Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
BUgAyPXboK.exe

Overview

General Information

Sample Name:BUgAyPXboK.exe
Analysis ID:694553
MD5:dde91b6947d2b726e5bb8f5852cecb76
SHA1:7d2467c4e65238599c5fd05641c628fb4252c7ca
SHA256:eae8d675873bd846302263fdca95db805b560d3406ec964f76b2d4123f78b59a
Tags:exeGandCrab
Infos:

Detection

Gandcrab
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Gandcrab
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Snort IDS alert for network traffic
Contains functionality to determine the online IP of the system
Found Tor onion address
Uses nslookup.exe to query domains
Machine Learning detection for sample
May check the online IP address of the machine
Machine Learning detection for dropped file
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
Too many similar processes found
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Queries information about the installed CPU (vendor, model number etc)
Drops PE files
Found evaded block containing many API calls
Contains functionality to enumerate device drivers
Checks for available system drives (often done to infect USB drives)
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • BUgAyPXboK.exe (PID: 868 cmdline: "C:\Users\user\Desktop\BUgAyPXboK.exe" MD5: DDE91B6947D2B726E5BB8F5852CECB76)
    • nslookup.exe (PID: 5424 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5500 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 1576 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5276 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5356 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5336 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5360 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5340 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4876 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 812 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5796 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6128 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5224 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5588 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5572 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6040 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2912 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1572 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4228 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5940 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2464 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 3244 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 3824 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5896 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2208 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4628 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2852 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 2608 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4628 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 2688 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4908 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1908 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 3096 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1964 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 644 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1676 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5964 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4772 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4064 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5928 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2360 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4856 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5728 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6052 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5940 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6088 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • ykbxzh.exe (PID: 5500 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe" MD5: EE7A320AB14366D36D44CDC33B5E8238)
  • ykbxzh.exe (PID: 4784 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe" MD5: EE7A320AB14366D36D44CDC33B5E8238)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
BUgAyPXboK.exeSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
  • 0xf716:$: DECRYPT.txt
  • 0xf784:$: DECRYPT.txt
BUgAyPXboK.exeJoeSecurity_GandcrabYara detected GandcrabJoe Security
    BUgAyPXboK.exeGandcrabGandcrab Payloadkevoreilly
    • 0xf70c:$string1: GDCB-DECRYPT.txt
    • 0xf77a:$string1: GDCB-DECRYPT.txt
    • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
    • 0xf716:$: DECRYPT.txt
    • 0xf784:$: DECRYPT.txt
    C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeJoeSecurity_GandcrabYara detected GandcrabJoe Security
      C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeGandcrabGandcrab Payloadkevoreilly
      • 0xf70c:$string1: GDCB-DECRYPT.txt
      • 0xf77a:$string1: GDCB-DECRYPT.txt
      • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
      SourceRuleDescriptionAuthorStrings
      0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
        00000019.00000002.306373977.000000000040E000.00000004.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
          00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
            00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
              0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
                Click to see the 6 entries
                SourceRuleDescriptionAuthorStrings
                0.0.BUgAyPXboK.exe.400000.0.unpackSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
                • 0xf716:$: DECRYPT.txt
                • 0xf784:$: DECRYPT.txt
                0.0.BUgAyPXboK.exe.400000.0.unpackJoeSecurity_GandcrabYara detected GandcrabJoe Security
                  0.0.BUgAyPXboK.exe.400000.0.unpackGandcrabGandcrab Payloadkevoreilly
                  • 0xf70c:$string1: GDCB-DECRYPT.txt
                  • 0xf77a:$string1: GDCB-DECRYPT.txt
                  • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
                  12.0.ykbxzh.exe.400000.0.unpackSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
                  • 0xf716:$: DECRYPT.txt
                  • 0xf784:$: DECRYPT.txt
                  12.0.ykbxzh.exe.400000.0.unpackJoeSecurity_GandcrabYara detected GandcrabJoe Security
                    Click to see the 13 entries
                    No Sigma rule has matched
                    Timestamp:192.168.2.68.8.8.859531532026737 08/31/22-23:45:39.973829
                    SID:2026737
                    Source Port:59531
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854507532829500 08/31/22-23:44:51.051028
                    SID:2829500
                    Source Port:54507
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856433532026737 08/31/22-23:45:05.669170
                    SID:2026737
                    Source Port:56433
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859724532026737 08/31/22-23:45:37.047109
                    SID:2026737
                    Source Port:59724
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859626532026737 08/31/22-23:45:09.130817
                    SID:2026737
                    Source Port:59626
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860383532829500 08/31/22-23:45:54.073595
                    SID:2829500
                    Source Port:60383
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856298532026737 08/31/22-23:44:46.383892
                    SID:2026737
                    Source Port:56298
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864965532829500 08/31/22-23:44:45.948752
                    SID:2829500
                    Source Port:64965
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862224532829500 08/31/22-23:44:36.753658
                    SID:2829500
                    Source Port:62224
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861613532829500 08/31/22-23:43:46.602572
                    SID:2829500
                    Source Port:61613
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856363532026737 08/31/22-23:44:42.471272
                    SID:2026737
                    Source Port:56363
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856507532829500 08/31/22-23:45:51.692352
                    SID:2829500
                    Source Port:56507
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852121532829500 08/31/22-23:45:13.843635
                    SID:2829500
                    Source Port:52121
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863867532829500 08/31/22-23:43:31.143411
                    SID:2829500
                    Source Port:63867
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854513532829498 08/31/22-23:44:53.235786
                    SID:2829498
                    Source Port:54513
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854757532026737 08/31/22-23:45:14.540780
                    SID:2026737
                    Source Port:54757
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850347532829500 08/31/22-23:44:00.906690
                    SID:2829500
                    Source Port:50347
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860134532829500 08/31/22-23:44:29.746960
                    SID:2829500
                    Source Port:60134
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861173532829498 08/31/22-23:45:03.206529
                    SID:2829498
                    Source Port:61173
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852486532026737 08/31/22-23:43:48.342534
                    SID:2026737
                    Source Port:52486
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864649532829498 08/31/22-23:44:48.847826
                    SID:2829498
                    Source Port:64649
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864798532026737 08/31/22-23:44:59.208494
                    SID:2026737
                    Source Port:64798
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863501532829498 08/31/22-23:45:53.807893
                    SID:2829498
                    Source Port:63501
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850968532829498 08/31/22-23:45:24.827189
                    SID:2829498
                    Source Port:50968
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862915532829498 08/31/22-23:43:29.888154
                    SID:2829498
                    Source Port:62915
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863438532026737 08/31/22-23:45:30.070764
                    SID:2026737
                    Source Port:63438
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852719532829498 08/31/22-23:44:35.284576
                    SID:2829498
                    Source Port:52719
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863675532026737 08/31/22-23:45:02.703986
                    SID:2026737
                    Source Port:63675
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854493532829500 08/31/22-23:45:28.756602
                    SID:2829500
                    Source Port:54493
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852729532026737 08/31/22-23:45:11.556204
                    SID:2026737
                    Source Port:52729
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860170532026737 08/31/22-23:45:19.218542
                    SID:2026737
                    Source Port:60170
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864409532829500 08/31/22-23:44:20.846616
                    SID:2829500
                    Source Port:64409
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850257532829500 08/31/22-23:44:58.802648
                    SID:2829500
                    Source Port:50257
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856551532026737 08/31/22-23:43:56.858808
                    SID:2026737
                    Source Port:56551
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852870532026737 08/31/22-23:44:15.600002
                    SID:2026737
                    Source Port:52870
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.858159532026737 08/31/22-23:44:44.437835
                    SID:2026737
                    Source Port:58159
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856429532829500 08/31/22-23:45:04.151432
                    SID:2829500
                    Source Port:56429
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859756532829500 08/31/22-23:44:14.164883
                    SID:2829500
                    Source Port:59756
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854881532829498 08/31/22-23:45:07.148628
                    SID:2829498
                    Source Port:54881
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860693532829498 08/31/22-23:44:32.915750
                    SID:2829498
                    Source Port:60693
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.865048532829500 08/31/22-23:44:07.531291
                    SID:2829500
                    Source Port:65048
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862523532026737 08/31/22-23:44:02.606977
                    SID:2026737
                    Source Port:62523
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857788532829498 08/31/22-23:44:45.461187
                    SID:2829498
                    Source Port:57788
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854202532829498 08/31/22-23:44:57.085032
                    SID:2829498
                    Source Port:54202
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859224532026737 08/31/22-23:44:39.557927
                    SID:2026737
                    Source Port:59224
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862949532829500 08/31/22-23:45:16.848920
                    SID:2829500
                    Source Port:62949
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864652532829498 08/31/22-23:44:48.958101
                    SID:2829498
                    Source Port:64652
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853271532829498 08/31/22-23:45:27.889217
                    SID:2829498
                    Source Port:53271
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852867532026737 08/31/22-23:44:15.534930
                    SID:2026737
                    Source Port:52867
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851776532829500 08/31/22-23:44:39.007949
                    SID:2829500
                    Source Port:51776
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857059532829498 08/31/22-23:45:18.303571
                    SID:2829498
                    Source Port:57059
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857981532026737 08/31/22-23:45:53.032065
                    SID:2026737
                    Source Port:57981
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862850532026737 08/31/22-23:44:23.403881
                    SID:2026737
                    Source Port:62850
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853947532829498 08/31/22-23:43:50.950634
                    SID:2829498
                    Source Port:53947
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857519532829500 08/31/22-23:44:26.384204
                    SID:2829500
                    Source Port:57519
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854313532829498 08/31/22-23:45:50.857498
                    SID:2829498
                    Source Port:54313
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856752532829500 08/31/22-23:44:33.536411
                    SID:2829500
                    Source Port:56752
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859885532829498 08/31/22-23:43:58.594444
                    SID:2829498
                    Source Port:59885
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860757532829500 08/31/22-23:45:46.254203
                    SID:2829500
                    Source Port:60757
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856549532026737 08/31/22-23:43:56.812959
                    SID:2026737
                    Source Port:56549
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851890532026737 08/31/22-23:44:51.640850
                    SID:2026737
                    Source Port:51890
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850256532829500 08/31/22-23:44:58.782280
                    SID:2829500
                    Source Port:50256
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855298532829500 08/31/22-23:45:37.693886
                    SID:2829500
                    Source Port:55298
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859969532829500 08/31/22-23:44:44.030720
                    SID:2829500
                    Source Port:59969
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855639532026737 08/31/22-23:45:55.456580
                    SID:2026737
                    Source Port:55639
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851689532829498 08/31/22-23:45:15.310184
                    SID:2829498
                    Source Port:51689
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863232532026737 08/31/22-23:43:32.344833
                    SID:2026737
                    Source Port:63232
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859757532829500 08/31/22-23:44:14.192618
                    SID:2829500
                    Source Port:59757
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857790532829498 08/31/22-23:44:45.500682
                    SID:2829498
                    Source Port:57790
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862963532829498 08/31/22-23:44:17.245311
                    SID:2829498
                    Source Port:62963
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860786532026737 08/31/22-23:45:45.011230
                    SID:2026737
                    Source Port:60786
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863256532829498 08/31/22-23:45:10.074723
                    SID:2829498
                    Source Port:63256
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856065532026737 08/31/22-23:45:29.057624
                    SID:2026737
                    Source Port:56065
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853050532829498 08/31/22-23:45:20.171719
                    SID:2829498
                    Source Port:53050
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856552532026737 08/31/22-23:43:56.877030
                    SID:2026737
                    Source Port:56552
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851626532829500 08/31/22-23:45:44.232922
                    SID:2829500
                    Source Port:51626
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859886532829498 08/31/22-23:43:58.614290
                    SID:2829498
                    Source Port:59886
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863266532026737 08/31/22-23:44:37.362093
                    SID:2026737
                    Source Port:63266
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853956532829498 08/31/22-23:45:45.816937
                    SID:2829498
                    Source Port:53956
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854301532829500 08/31/22-23:45:08.700152
                    SID:2829500
                    Source Port:54301
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862636532829498 08/31/22-23:45:12.181439
                    SID:2829498
                    Source Port:62636
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854101532026737 08/31/22-23:45:43.138088
                    SID:2026737
                    Source Port:54101
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849237532026737 08/31/22-23:44:09.133303
                    SID:2026737
                    Source Port:49237
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860011532026737 08/31/22-23:44:56.144537
                    SID:2026737
                    Source Port:60011
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856128532829498 08/31/22-23:44:10.647184
                    SID:2829498
                    Source Port:56128
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859627532026737 08/31/22-23:45:09.148937
                    SID:2026737
                    Source Port:59627
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849507532829500 08/31/22-23:45:22.271617
                    SID:2829500
                    Source Port:49507
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854312532829498 08/31/22-23:45:50.836877
                    SID:2829498
                    Source Port:54312
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849337532829498 08/31/22-23:44:43.512238
                    SID:2829498
                    Source Port:49337
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856297532026737 08/31/22-23:44:46.363903
                    SID:2026737
                    Source Port:56297
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857979532026737 08/31/22-23:45:52.995555
                    SID:2026737
                    Source Port:57979
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852394532829498 08/31/22-23:45:33.462720
                    SID:2829498
                    Source Port:52394
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861807532026737 08/31/22-23:45:26.638406
                    SID:2026737
                    Source Port:61807
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860692532829498 08/31/22-23:44:32.895962
                    SID:2829498
                    Source Port:60692
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857759532829498 08/31/22-23:44:41.121343
                    SID:2829498
                    Source Port:57759
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860789532026737 08/31/22-23:45:45.071628
                    SID:2026737
                    Source Port:60789
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857190532829500 08/31/22-23:45:34.277428
                    SID:2829500
                    Source Port:57190
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857982532026737 08/31/22-23:45:53.052190
                    SID:2026737
                    Source Port:57982
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864931532829498 08/31/22-23:45:31.895021
                    SID:2829498
                    Source Port:64931
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856125532829498 08/31/22-23:44:10.587852
                    SID:2829498
                    Source Port:56125
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863259532829498 08/31/22-23:45:10.134383
                    SID:2829498
                    Source Port:63259
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864651532829498 08/31/22-23:44:48.937934
                    SID:2829498
                    Source Port:64651
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854908532829500 08/31/22-23:43:40.017875
                    SID:2829500
                    Source Port:54908
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855959532829498 08/31/22-23:44:24.973756
                    SID:2829498
                    Source Port:55959
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856907532829498 08/31/22-23:45:34.930944
                    SID:2829498
                    Source Port:56907
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853959532829498 08/31/22-23:45:45.873966
                    SID:2829498
                    Source Port:53959
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861578532829498 08/31/22-23:45:43.955052
                    SID:2829498
                    Source Port:61578
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861094532829498 08/31/22-23:44:27.968897
                    SID:2829498
                    Source Port:61094
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857188532829500 08/31/22-23:45:34.238634
                    SID:2829500
                    Source Port:57188
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859794532026737 08/31/22-23:45:48.558569
                    SID:2026737
                    Source Port:59794
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851326532026737 08/31/22-23:44:27.434988
                    SID:2026737
                    Source Port:51326
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862040532829500 08/31/22-23:45:01.158698
                    SID:2829500
                    Source Port:62040
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864640532829500 08/31/22-23:45:18.759264
                    SID:2829500
                    Source Port:64640
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854203532829498 08/31/22-23:44:57.105081
                    SID:2829498
                    Source Port:54203
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851889532026737 08/31/22-23:44:51.620571
                    SID:2026737
                    Source Port:51889
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860010532026737 08/31/22-23:44:56.124573
                    SID:2026737
                    Source Port:60010
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863502532829498 08/31/22-23:45:53.826060
                    SID:2829498
                    Source Port:63502
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.858161532026737 08/31/22-23:44:44.475598
                    SID:2026737
                    Source Port:58161
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863437532026737 08/31/22-23:45:30.050806
                    SID:2026737
                    Source Port:63437
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864964532829500 08/31/22-23:44:45.929172
                    SID:2829500
                    Source Port:64964
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853198532829500 08/31/22-23:44:54.703855
                    SID:2829500
                    Source Port:53198
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864934532829498 08/31/22-23:45:31.953591
                    SID:2829498
                    Source Port:64934
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851532532026737 08/31/22-23:43:41.630051
                    SID:2026737
                    Source Port:51532
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864408532829500 08/31/22-23:44:20.826579
                    SID:2829500
                    Source Port:64408
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850540532026737 08/31/22-23:45:24.416776
                    SID:2026737
                    Source Port:50540
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856434532026737 08/31/22-23:45:05.689287
                    SID:2026737
                    Source Port:56434
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853595532829500 08/31/22-23:44:41.898667
                    SID:2829500
                    Source Port:53595
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854508532829500 08/31/22-23:44:51.075095
                    SID:2829500
                    Source Port:54508
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857098532829500 08/31/22-23:45:35.742268
                    SID:2829500
                    Source Port:57098
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854905532829500 08/31/22-23:43:39.956403
                    SID:2829500
                    Source Port:54905
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864799532026737 08/31/22-23:44:59.228975
                    SID:2026737
                    Source Port:64799
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861614532829500 08/31/22-23:43:46.625363
                    SID:2829500
                    Source Port:61614
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862223532829500 08/31/22-23:44:36.732224
                    SID:2829500
                    Source Port:62223
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850810532829500 08/31/22-23:45:42.795800
                    SID:2829500
                    Source Port:50810
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860758532829500 08/31/22-23:45:46.272226
                    SID:2829500
                    Source Port:60758
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864406532829500 08/31/22-23:44:20.786154
                    SID:2829500
                    Source Port:64406
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864932532829498 08/31/22-23:45:31.915004
                    SID:2829498
                    Source Port:64932
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863868532829500 08/31/22-23:43:31.170740
                    SID:2829500
                    Source Port:63868
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864966532829500 08/31/22-23:44:45.968566
                    SID:2829500
                    Source Port:64966
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862635532829498 08/31/22-23:45:12.157482
                    SID:2829498
                    Source Port:62635
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850970532829498 08/31/22-23:45:24.869816
                    SID:2829498
                    Source Port:50970
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860755532829500 08/31/22-23:45:46.217401
                    SID:2829500
                    Source Port:60755
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864642532829500 08/31/22-23:45:18.801787
                    SID:2829500
                    Source Port:64642
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863987532026737 08/31/22-23:45:33.034613
                    SID:2026737
                    Source Port:63987
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856091532829500 08/31/22-23:43:52.113643
                    SID:2829500
                    Source Port:56091
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854300532829500 08/31/22-23:45:08.678590
                    SID:2829500
                    Source Port:54300
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854907532829500 08/31/22-23:43:39.999758
                    SID:2829500
                    Source Port:54907
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861234532829498 08/31/22-23:44:38.522132
                    SID:2829498
                    Source Port:61234
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861172532829498 08/31/22-23:45:03.186618
                    SID:2829498
                    Source Port:61172
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862736532026737 08/31/22-23:44:30.983637
                    SID:2026737
                    Source Port:62736
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859723532026737 08/31/22-23:45:37.029063
                    SID:2026737
                    Source Port:59723
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855300532829500 08/31/22-23:45:37.734665
                    SID:2829500
                    Source Port:55300
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850255532829500 08/31/22-23:44:58.762397
                    SID:2829500
                    Source Port:50255
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849236532026737 08/31/22-23:44:09.112716
                    SID:2026737
                    Source Port:49236
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856908532829498 08/31/22-23:45:34.949400
                    SID:2829498
                    Source Port:56908
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860013532026737 08/31/22-23:44:56.185703
                    SID:2026737
                    Source Port:60013
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861808532026737 08/31/22-23:45:26.658197
                    SID:2026737
                    Source Port:61808
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851624532829500 08/31/22-23:45:44.191433
                    SID:2829500
                    Source Port:51624
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857518532829500 08/31/22-23:44:26.364052
                    SID:2829500
                    Source Port:57518
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856360532026737 08/31/22-23:44:42.410727
                    SID:2026737
                    Source Port:56360
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851535532026737 08/31/22-23:43:41.693076
                    SID:2026737
                    Source Port:51535
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852717532829498 08/31/22-23:44:35.238130
                    SID:2829498
                    Source Port:52717
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861231532829498 08/31/22-23:44:38.465975
                    SID:2829498
                    Source Port:61231
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862633532829498 08/31/22-23:45:12.116146
                    SID:2829498
                    Source Port:62633
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859532532026737 08/31/22-23:45:39.991955
                    SID:2026737
                    Source Port:59532
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859792532026737 08/31/22-23:45:48.517877
                    SID:2026737
                    Source Port:59792
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855637532026737 08/31/22-23:45:55.417422
                    SID:2026737
                    Source Port:55637
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849506532829500 08/31/22-23:45:22.251711
                    SID:2829500
                    Source Port:49506
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856773532026737 08/31/22-23:45:34.608670
                    SID:2026737
                    Source Port:56773
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851323532026737 08/31/22-23:44:27.377732
                    SID:2026737
                    Source Port:51323
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856126532829498 08/31/22-23:44:10.607141
                    SID:2829498
                    Source Port:56126
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861575532829498 08/31/22-23:45:43.896304
                    SID:2829498
                    Source Port:61575
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857096532829500 08/31/22-23:45:35.703871
                    SID:2829500
                    Source Port:57096
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860777532829498 08/31/22-23:45:40.857769
                    SID:2829498
                    Source Port:60777
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852868532026737 08/31/22-23:44:15.557965
                    SID:2026737
                    Source Port:52868
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861091532829498 08/31/22-23:44:27.912765
                    SID:2829498
                    Source Port:61091
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863233532026737 08/31/22-23:43:32.365334
                    SID:2026737
                    Source Port:63233
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861848532829498 08/31/22-23:45:29.448150
                    SID:2829498
                    Source Port:61848
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863674532026737 08/31/22-23:45:02.682245
                    SID:2026737
                    Source Port:63674
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.865049532829500 08/31/22-23:44:07.555130
                    SID:2829500
                    Source Port:65049
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853592532829500 08/31/22-23:44:41.838524
                    SID:2829500
                    Source Port:53592
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851595532829498 08/31/22-23:45:37.395999
                    SID:2829498
                    Source Port:51595
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852561532829498 08/31/22-23:43:44.313767
                    SID:2829498
                    Source Port:52561
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860386532829500 08/31/22-23:45:54.135455
                    SID:2829500
                    Source Port:60386
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854754532026737 08/31/22-23:45:14.478679
                    SID:2026737
                    Source Port:54754
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854299532829500 08/31/22-23:45:08.657968
                    SID:2829500
                    Source Port:54299
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856905532829498 08/31/22-23:45:34.890654
                    SID:2829498
                    Source Port:56905
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852728532026737 08/31/22-23:45:11.538182
                    SID:2026737
                    Source Port:52728
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852559532829498 08/31/22-23:43:44.275226
                    SID:2829498
                    Source Port:52559
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856571532829498 08/31/22-23:44:04.765178
                    SID:2829498
                    Source Port:56571
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856509532829500 08/31/22-23:45:51.736467
                    SID:2829500
                    Source Port:56509
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857691532829500 08/31/22-23:45:26.303054
                    SID:2829500
                    Source Port:57691
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861805532026737 08/31/22-23:45:26.598524
                    SID:2026737
                    Source Port:61805
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864800532026737 08/31/22-23:44:59.249276
                    SID:2026737
                    Source Port:64800
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854102532026737 08/31/22-23:45:43.158257
                    SID:2026737
                    Source Port:54102
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862541532829498 08/31/22-23:45:00.327889
                    SID:2829498
                    Source Port:62541
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860133532829500 08/31/22-23:44:29.726898
                    SID:2829500
                    Source Port:60133
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859339532026737 08/31/22-23:44:34.622255
                    SID:2026737
                    Source Port:59339
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860358532829500 08/31/22-23:45:11.129894
                    SID:2829500
                    Source Port:60358
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860171532026737 08/31/22-23:45:19.238395
                    SID:2026737
                    Source Port:60171
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852393532829498 08/31/22-23:45:33.441343
                    SID:2829498
                    Source Port:52393
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851891532026737 08/31/22-23:44:51.663811
                    SID:2026737
                    Source Port:51891
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856432532829500 08/31/22-23:45:04.211842
                    SID:2829500
                    Source Port:56432
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862038532829500 08/31/22-23:45:01.120775
                    SID:2829500
                    Source Port:62038
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863865532829500 08/31/22-23:43:31.097637
                    SID:2829500
                    Source Port:63865
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854334532026737 08/31/22-23:45:17.822080
                    SID:2026737
                    Source Port:54334
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854331532026737 08/31/22-23:45:17.760023
                    SID:2026737
                    Source Port:54331
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856753532829500 08/31/22-23:44:33.556718
                    SID:2829500
                    Source Port:56753
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854511532829498 08/31/22-23:44:53.195102
                    SID:2829498
                    Source Port:54511
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853051532829498 08/31/22-23:45:20.191618
                    SID:2829498
                    Source Port:53051
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862539532829498 08/31/22-23:45:00.266317
                    SID:2829498
                    Source Port:62539
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854492532829500 08/31/22-23:45:28.736488
                    SID:2829500
                    Source Port:54492
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856089532829500 08/31/22-23:43:52.075291
                    SID:2829500
                    Source Port:56089
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859968532829500 08/31/22-23:44:44.010316
                    SID:2829500
                    Source Port:59968
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859339532829500 08/31/22-23:45:29.745493
                    SID:2829500
                    Source Port:59339
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851777532829500 08/31/22-23:44:39.027584
                    SID:2829500
                    Source Port:51777
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856506532829500 08/31/22-23:45:51.673642
                    SID:2829500
                    Source Port:56506
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852483532026737 08/31/22-23:43:48.282565
                    SID:2026737
                    Source Port:52483
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853948532829498 08/31/22-23:43:50.969584
                    SID:2829498
                    Source Port:53948
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853195532829500 08/31/22-23:44:54.646933
                    SID:2829500
                    Source Port:53195
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862524532026737 08/31/22-23:44:02.627433
                    SID:2026737
                    Source Port:62524
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861611532829500 08/31/22-23:43:46.559519
                    SID:2829500
                    Source Port:61611
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857757532829498 08/31/22-23:44:41.083129
                    SID:2829498
                    Source Port:57757
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862961532829498 08/31/22-23:44:17.199822
                    SID:2829498
                    Source Port:62961
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.858160532026737 08/31/22-23:44:44.457604
                    SID:2026737
                    Source Port:58160
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.865046532829500 08/31/22-23:44:07.490248
                    SID:2829500
                    Source Port:65046
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851687532829498 08/31/22-23:45:15.269352
                    SID:2829498
                    Source Port:51687
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854491532829500 08/31/22-23:45:28.716622
                    SID:2829500
                    Source Port:54491
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853197532829500 08/31/22-23:44:54.685783
                    SID:2829500
                    Source Port:53197
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862947532829500 08/31/22-23:45:16.811046
                    SID:2829500
                    Source Port:62947
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853273532829498 08/31/22-23:45:27.934014
                    SID:2829498
                    Source Port:53273
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850808532829500 08/31/22-23:45:42.752242
                    SID:2829500
                    Source Port:50808
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856430532829500 08/31/22-23:45:04.173628
                    SID:2829500
                    Source Port:56430
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859227532026737 08/31/22-23:44:39.617895
                    SID:2026737
                    Source Port:59227
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851774532829500 08/31/22-23:44:38.969749
                    SID:2829500
                    Source Port:51774
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849335532829498 08/31/22-23:44:43.471732
                    SID:2829498
                    Source Port:49335
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859970532829500 08/31/22-23:44:44.048963
                    SID:2829500
                    Source Port:59970
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850811532829500 08/31/22-23:45:42.813839
                    SID:2829500
                    Source Port:50811
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853945532829498 08/31/22-23:43:50.908833
                    SID:2829498
                    Source Port:53945
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861577532829498 08/31/22-23:45:43.934540
                    SID:2829498
                    Source Port:61577
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859795532026737 08/31/22-23:45:48.583140
                    SID:2026737
                    Source Port:59795
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854906532829500 08/31/22-23:43:39.979642
                    SID:2829500
                    Source Port:54906
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860695532829498 08/31/22-23:44:32.965263
                    SID:2829498
                    Source Port:60695
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857520532829500 08/31/22-23:44:26.402095
                    SID:2829500
                    Source Port:57520
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864933532829498 08/31/22-23:45:31.933353
                    SID:2829498
                    Source Port:64933
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851325532026737 08/31/22-23:44:27.416197
                    SID:2026737
                    Source Port:51325
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854204532829498 08/31/22-23:44:57.124925
                    SID:2829498
                    Source Port:54204
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859337532829500 08/31/22-23:45:29.704403
                    SID:2829500
                    Source Port:59337
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853049532829498 08/31/22-23:45:20.151836
                    SID:2829498
                    Source Port:53049
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850538532026737 08/31/22-23:45:24.374820
                    SID:2026737
                    Source Port:50538
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857692532829500 08/31/22-23:45:26.323011
                    SID:2829500
                    Source Port:57692
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862853532026737 08/31/22-23:44:23.460622
                    SID:2026737
                    Source Port:62853
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864407532829500 08/31/22-23:44:20.806285
                    SID:2829500
                    Source Port:64407
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864650532829498 08/31/22-23:44:48.868078
                    SID:2829498
                    Source Port:64650
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857057532829498 08/31/22-23:45:18.264695
                    SID:2829498
                    Source Port:57057
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863672532026737 08/31/22-23:45:02.641322
                    SID:2026737
                    Source Port:63672
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856300532026737 08/31/22-23:44:46.422476
                    SID:2026737
                    Source Port:56300
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861175532829498 08/31/22-23:45:03.248644
                    SID:2829498
                    Source Port:61175
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863503532829498 08/31/22-23:45:53.846708
                    SID:2829498
                    Source Port:63503
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853958532829498 08/31/22-23:45:45.853434
                    SID:2829498
                    Source Port:53958
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864963532829500 08/31/22-23:44:45.907609
                    SID:2829500
                    Source Port:64963
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863436532026737 08/31/22-23:45:30.030649
                    SID:2026737
                    Source Port:63436
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862443532829500 08/31/22-23:45:32.738675
                    SID:2829500
                    Source Port:62443
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862041532829500 08/31/22-23:45:01.185034
                    SID:2829500
                    Source Port:62041
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855958532829498 08/31/22-23:44:24.955368
                    SID:2829498
                    Source Port:55958
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854315532829498 08/31/22-23:45:50.898635
                    SID:2829498
                    Source Port:54315
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856435532026737 08/31/22-23:45:05.709061
                    SID:2026737
                    Source Port:56435
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852484532026737 08/31/22-23:43:48.300604
                    SID:2026737
                    Source Port:52484
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855961532829498 08/31/22-23:44:25.014723
                    SID:2829498
                    Source Port:55961
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856775532026737 08/31/22-23:45:34.651620
                    SID:2026737
                    Source Port:56775
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849234532026737 08/31/22-23:44:09.071545
                    SID:2026737
                    Source Port:49234
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863258532829498 08/31/22-23:45:10.114400
                    SID:2829498
                    Source Port:63258
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860788532026737 08/31/22-23:45:45.053319
                    SID:2026737
                    Source Port:60788
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862226532829500 08/31/22-23:44:36.798472
                    SID:2829500
                    Source Port:62226
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859754532829500 08/31/22-23:44:14.128267
                    SID:2829500
                    Source Port:59754
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862913532829498 08/31/22-23:43:29.846372
                    SID:2829498
                    Source Port:62913
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854883532829498 08/31/22-23:45:07.190819
                    SID:2829498
                    Source Port:54883
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859967532829500 08/31/22-23:44:43.992635
                    SID:2829500
                    Source Port:59967
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854505532829500 08/31/22-23:44:51.004869
                    SID:2829500
                    Source Port:54505
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861835532829498 08/31/22-23:44:04.805216
                    SID:2829498
                    Source Port:61835
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859883532829498 08/31/22-23:43:58.553914
                    SID:2829498
                    Source Port:59883
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856754532829500 08/31/22-23:44:33.577050
                    SID:2829500
                    Source Port:56754
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862735532026737 08/31/22-23:44:30.963319
                    SID:2026737
                    Source Port:62735
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859534532026737 08/31/22-23:45:40.030175
                    SID:2026737
                    Source Port:59534
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859341532026737 08/31/22-23:44:34.662548
                    SID:2026737
                    Source Port:59341
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859338532026737 08/31/22-23:44:34.602119
                    SID:2026737
                    Source Port:59338
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864643532829500 08/31/22-23:45:18.822080
                    SID:2829500
                    Source Port:64643
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852730532026737 08/31/22-23:45:11.576227
                    SID:2026737
                    Source Port:52730
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851534532026737 08/31/22-23:43:41.673206
                    SID:2026737
                    Source Port:51534
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850345532829500 08/31/22-23:44:00.864997
                    SID:2829500
                    Source Port:50345
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851627532829500 08/31/22-23:45:44.253365
                    SID:2829500
                    Source Port:51627
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852727532026737 08/31/22-23:45:11.519431
                    SID:2026737
                    Source Port:52727
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862039532829500 08/31/22-23:45:01.138670
                    SID:2829500
                    Source Port:62039
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860169532026737 08/31/22-23:45:19.198459
                    SID:2026737
                    Source Port:60169
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860172532026737 08/31/22-23:45:19.258880
                    SID:2026737
                    Source Port:60172
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856066532026737 08/31/22-23:45:29.077449
                    SID:2026737
                    Source Port:56066
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862852532026737 08/31/22-23:44:23.440318
                    SID:2026737
                    Source Port:62852
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863267532026737 08/31/22-23:44:37.381873
                    SID:2026737
                    Source Port:63267
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855299532829500 08/31/22-23:45:37.714101
                    SID:2829500
                    Source Port:55299
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854205532829498 08/31/22-23:44:57.145411
                    SID:2829498
                    Source Port:54205
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863988532026737 08/31/22-23:45:33.054662
                    SID:2026737
                    Source Port:63988
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854333532026737 08/31/22-23:45:17.804037
                    SID:2026737
                    Source Port:54333
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860778532829498 08/31/22-23:45:40.877620
                    SID:2829498
                    Source Port:60778
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852123532829500 08/31/22-23:45:13.882213
                    SID:2829500
                    Source Port:52123
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850809532829500 08/31/22-23:45:42.775516
                    SID:2829500
                    Source Port:50809
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859226532026737 08/31/22-23:44:39.597797
                    SID:2026737
                    Source Port:59226
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862442532829500 08/31/22-23:45:32.718407
                    SID:2829500
                    Source Port:62442
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854332532026737 08/31/22-23:45:17.784189
                    SID:2026737
                    Source Port:54332
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861576532829498 08/31/22-23:45:43.916183
                    SID:2829498
                    Source Port:61576
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857056532829498 08/31/22-23:45:18.246350
                    SID:2829498
                    Source Port:57056
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861233532829498 08/31/22-23:44:38.502415
                    SID:2829498
                    Source Port:61233
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856361532026737 08/31/22-23:44:42.430522
                    SID:2026737
                    Source Port:56361
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862948532829500 08/31/22-23:45:16.831038
                    SID:2829500
                    Source Port:62948
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861834532829498 08/31/22-23:44:04.785165
                    SID:2829498
                    Source Port:61834
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853594532829500 08/31/22-23:44:41.878318
                    SID:2829500
                    Source Port:53594
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854884532829498 08/31/22-23:45:07.210988
                    SID:2829498
                    Source Port:54884
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862522532026737 08/31/22-23:44:02.586427
                    SID:2026737
                    Source Port:62522
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850539532026737 08/31/22-23:45:24.397103
                    SID:2026737
                    Source Port:50539
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851596532829498 08/31/22-23:45:37.416090
                    SID:2829498
                    Source Port:51596
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859340532026737 08/31/22-23:44:34.642153
                    SID:2026737
                    Source Port:59340
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851593532829498 08/31/22-23:45:37.355426
                    SID:2829498
                    Source Port:51593
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.865047532829500 08/31/22-23:44:07.510331
                    SID:2829500
                    Source Port:65047
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862543532829498 08/31/22-23:43:34.588739
                    SID:2829498
                    Source Port:62543
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860357532829500 08/31/22-23:45:11.111963
                    SID:2829500
                    Source Port:60357
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862540532829498 08/31/22-23:45:00.304908
                    SID:2829498
                    Source Port:62540
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853946532829498 08/31/22-23:43:50.926739
                    SID:2829498
                    Source Port:53946
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851775532829500 08/31/22-23:44:38.988155
                    SID:2829500
                    Source Port:51775
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849334532829498 08/31/22-23:44:43.443293
                    SID:2829498
                    Source Port:49334
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855636532026737 08/31/22-23:45:55.399161
                    SID:2026737
                    Source Port:55636
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860385532829500 08/31/22-23:45:54.115289
                    SID:2829500
                    Source Port:60385
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861847532829498 08/31/22-23:45:29.427867
                    SID:2829498
                    Source Port:61847
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857095532829500 08/31/22-23:45:35.685539
                    SID:2829500
                    Source Port:57095
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863673532026737 08/31/22-23:45:02.662218
                    SID:2026737
                    Source Port:63673
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859722532026737 08/31/22-23:45:37.008989
                    SID:2026737
                    Source Port:59722
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853272532829498 08/31/22-23:45:27.910057
                    SID:2829498
                    Source Port:53272
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856774532026737 08/31/22-23:45:34.633210
                    SID:2026737
                    Source Port:56774
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854755532026737 08/31/22-23:45:14.500005
                    SID:2026737
                    Source Port:54755
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861093532829498 08/31/22-23:44:27.948801
                    SID:2829498
                    Source Port:61093
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862912532829498 08/31/22-23:43:29.827972
                    SID:2829498
                    Source Port:62912
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863435532026737 08/31/22-23:45:30.010284
                    SID:2026737
                    Source Port:63435
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859340532829500 08/31/22-23:45:29.765614
                    SID:2829500
                    Source Port:59340
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856090532829500 08/31/22-23:43:52.093457
                    SID:2829500
                    Source Port:56090
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857191532829500 08/31/22-23:45:34.298140
                    SID:2829500
                    Source Port:57191
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862444532829500 08/31/22-23:45:32.758993
                    SID:2829500
                    Source Port:62444
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849508532829500 08/31/22-23:45:22.293889
                    SID:2829500
                    Source Port:49508
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849336532829498 08/31/22-23:44:43.492294
                    SID:2829498
                    Source Port:49336
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854512532829498 08/31/22-23:44:53.215474
                    SID:2829498
                    Source Port:54512
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861174532829498 08/31/22-23:45:03.230028
                    SID:2829498
                    Source Port:61174
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850348532829500 08/31/22-23:44:00.930724
                    SID:2829500
                    Source Port:50348
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856755532829500 08/31/22-23:44:33.597404
                    SID:2829500
                    Source Port:56755
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850969532829498 08/31/22-23:45:24.845855
                    SID:2829498
                    Source Port:50969
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856550532026737 08/31/22-23:43:56.837414
                    SID:2026737
                    Source Port:56550
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861836532829498 08/31/22-23:44:04.825892
                    SID:2829498
                    Source Port:61836
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860135532829500 08/31/22-23:44:29.765194
                    SID:2829500
                    Source Port:60135
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850537532026737 08/31/22-23:45:24.354748
                    SID:2026737
                    Source Port:50537
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857693532829500 08/31/22-23:45:26.343034
                    SID:2829500
                    Source Port:57693
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854100532026737 08/31/22-23:45:43.119824
                    SID:2026737
                    Source Port:54100
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859338532829500 08/31/22-23:45:29.724262
                    SID:2829500
                    Source Port:59338
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856431532829500 08/31/22-23:45:04.193694
                    SID:2829500
                    Source Port:56431
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853274532829498 08/31/22-23:45:27.954080
                    SID:2829498
                    Source Port:53274
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857756532829498 08/31/22-23:44:41.063437
                    SID:2829498
                    Source Port:57756
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852122532829500 08/31/22-23:45:13.864005
                    SID:2829500
                    Source Port:52122
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863990532026737 08/31/22-23:45:33.098684
                    SID:2026737
                    Source Port:63990
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860694532829498 08/31/22-23:44:32.941274
                    SID:2829498
                    Source Port:60694
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856508532829500 08/31/22-23:45:51.716328
                    SID:2829500
                    Source Port:56508
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862946532829500 08/31/22-23:45:16.791073
                    SID:2829500
                    Source Port:62946
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854490532829500 08/31/22-23:45:28.698486
                    SID:2829500
                    Source Port:54490
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856362532026737 08/31/22-23:44:42.450740
                    SID:2026737
                    Source Port:56362
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852485532026737 08/31/22-23:43:48.319052
                    SID:2026737
                    Source Port:52485
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862962532829498 08/31/22-23:44:17.220032
                    SID:2829498
                    Source Port:62962
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863231532026737 08/31/22-23:43:32.324505
                    SID:2026737
                    Source Port:63231
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853048532829498 08/31/22-23:45:20.133745
                    SID:2829498
                    Source Port:53048
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864801532026737 08/31/22-23:44:59.269048
                    SID:2026737
                    Source Port:64801
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854756532026737 08/31/22-23:45:14.520580
                    SID:2026737
                    Source Port:54756
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862525532026737 08/31/22-23:44:02.647686
                    SID:2026737
                    Source Port:62525
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851688532829498 08/31/22-23:45:15.290256
                    SID:2829498
                    Source Port:51688
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856906532829498 08/31/22-23:45:34.910660
                    SID:2829498
                    Source Port:56906
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852560532829498 08/31/22-23:43:44.295389
                    SID:2829498
                    Source Port:52560
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850346532829500 08/31/22-23:44:00.886556
                    SID:2829500
                    Source Port:50346
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863500532829498 08/31/22-23:45:53.787672
                    SID:2829498
                    Source Port:63500
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860776532829498 08/31/22-23:45:40.839433
                    SID:2829498
                    Source Port:60776
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860779532829498 08/31/22-23:45:40.897866
                    SID:2829498
                    Source Port:60779
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860384532829500 08/31/22-23:45:54.095085
                    SID:2829500
                    Source Port:60384
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861092532829498 08/31/22-23:44:27.930612
                    SID:2829498
                    Source Port:61092
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852869532026737 08/31/22-23:44:15.578775
                    SID:2026737
                    Source Port:52869
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856088532829500 08/31/22-23:43:52.054951
                    SID:2829500
                    Source Port:56088
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851324532026737 08/31/22-23:44:27.397683
                    SID:2026737
                    Source Port:51324
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854510532829498 08/31/22-23:44:53.176959
                    SID:2829498
                    Source Port:54510
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863866532829500 08/31/22-23:43:31.119406
                    SID:2829500
                    Source Port:63866
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852395532829498 08/31/22-23:45:33.483017
                    SID:2829498
                    Source Port:52395
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851892532026737 08/31/22-23:44:51.684138
                    SID:2026737
                    Source Port:51892
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860356532829500 08/31/22-23:45:11.093877
                    SID:2829500
                    Source Port:60356
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861612532829500 08/31/22-23:43:46.582342
                    SID:2829500
                    Source Port:61612
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862960532829498 08/31/22-23:44:17.126999
                    SID:2829498
                    Source Port:62960
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857758532829498 08/31/22-23:44:41.103311
                    SID:2829498
                    Source Port:57758
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852120532829500 08/31/22-23:45:13.823401
                    SID:2829500
                    Source Port:52120
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853196532829500 08/31/22-23:44:54.665572
                    SID:2829500
                    Source Port:53196
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853593532829500 08/31/22-23:44:41.858327
                    SID:2829500
                    Source Port:53593
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863234532026737 08/31/22-23:43:32.383826
                    SID:2026737
                    Source Port:63234
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861846532829498 08/31/22-23:45:29.407811
                    SID:2829498
                    Source Port:61846
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851686532829498 08/31/22-23:45:15.249386
                    SID:2829498
                    Source Port:51686
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859721532026737 08/31/22-23:45:36.989137
                    SID:2026737
                    Source Port:59721
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863989532026737 08/31/22-23:45:33.076660
                    SID:2026737
                    Source Port:63989
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861232532829498 08/31/22-23:44:38.484716
                    SID:2829498
                    Source Port:61232
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860787532026737 08/31/22-23:45:45.033484
                    SID:2026737
                    Source Port:60787
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860012532026737 08/31/22-23:44:56.166001
                    SID:2026737
                    Source Port:60012
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854099532026737 08/31/22-23:45:43.099769
                    SID:2026737
                    Source Port:54099
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852558532829498 08/31/22-23:43:44.255164
                    SID:2829498
                    Source Port:52558
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862851532026737 08/31/22-23:44:23.422050
                    SID:2026737
                    Source Port:62851
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852718532829498 08/31/22-23:44:35.264599
                    SID:2829498
                    Source Port:52718
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857690532829500 08/31/22-23:45:26.285005
                    SID:2829500
                    Source Port:57690
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855638532026737 08/31/22-23:45:55.435640
                    SID:2026737
                    Source Port:55638
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859225532026737 08/31/22-23:44:39.577699
                    SID:2026737
                    Source Port:59225
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854298532829500 08/31/22-23:45:08.637369
                    SID:2829500
                    Source Port:54298
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849505532829500 08/31/22-23:45:22.198497
                    SID:2829500
                    Source Port:49505
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860132532829500 08/31/22-23:44:29.658619
                    SID:2829500
                    Source Port:60132
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862441532829500 08/31/22-23:45:32.697893
                    SID:2829500
                    Source Port:62441
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.853957532829498 08/31/22-23:45:45.835304
                    SID:2829498
                    Source Port:53957
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852720532829498 08/31/22-23:44:35.302792
                    SID:2829498
                    Source Port:52720
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863257532829498 08/31/22-23:45:10.094581
                    SID:2829498
                    Source Port:63257
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859628532026737 08/31/22-23:45:09.167178
                    SID:2026737
                    Source Port:59628
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.852392532829498 08/31/22-23:45:33.421298
                    SID:2829498
                    Source Port:52392
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860756532829500 08/31/22-23:45:46.235846
                    SID:2829500
                    Source Port:60756
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862542532829498 08/31/22-23:45:00.351749
                    SID:2829498
                    Source Port:62542
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862734532026737 08/31/22-23:44:30.902951
                    SID:2026737
                    Source Port:62734
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.860359532829500 08/31/22-23:45:11.147941
                    SID:2829500
                    Source Port:60359
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861806532026737 08/31/22-23:45:26.618513
                    SID:2026737
                    Source Port:61806
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856127532829498 08/31/22-23:44:10.627241
                    SID:2829498
                    Source Port:56127
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.861849532829498 08/31/22-23:45:29.468833
                    SID:2829498
                    Source Port:61849
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851533532026737 08/31/22-23:43:41.652498
                    SID:2026737
                    Source Port:51533
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857791532829498 08/31/22-23:44:45.522004
                    SID:2829498
                    Source Port:57791
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851594532829498 08/31/22-23:45:37.375783
                    SID:2829498
                    Source Port:51594
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.851625532829500 08/31/22-23:45:44.209571
                    SID:2829500
                    Source Port:51625
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862225532829500 08/31/22-23:44:36.774015
                    SID:2829500
                    Source Port:62225
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850254532829500 08/31/22-23:44:58.744615
                    SID:2829500
                    Source Port:50254
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859884532829498 08/31/22-23:43:58.574440
                    SID:2829498
                    Source Port:59884
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856067532026737 08/31/22-23:45:29.097446
                    SID:2026737
                    Source Port:56067
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863265532026737 08/31/22-23:44:37.342111
                    SID:2026737
                    Source Port:63265
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862914532829498 08/31/22-23:43:29.867951
                    SID:2829498
                    Source Port:62914
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857980532026737 08/31/22-23:45:53.013848
                    SID:2026737
                    Source Port:57980
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857189532829500 08/31/22-23:45:34.259006
                    SID:2829500
                    Source Port:57189
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859793532026737 08/31/22-23:45:48.538109
                    SID:2026737
                    Source Port:59793
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.858162532026737 08/31/22-23:44:44.497801
                    SID:2026737
                    Source Port:58162
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856064532026737 08/31/22-23:45:29.037586
                    SID:2026737
                    Source Port:56064
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859625532026737 08/31/22-23:45:09.112131
                    SID:2026737
                    Source Port:59625
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856772532026737 08/31/22-23:45:34.590480
                    SID:2026737
                    Source Port:56772
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857789532829498 08/31/22-23:44:45.480446
                    SID:2829498
                    Source Port:57789
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857097532829500 08/31/22-23:45:35.724078
                    SID:2829500
                    Source Port:57097
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859533532026737 08/31/22-23:45:40.011858
                    SID:2026737
                    Source Port:59533
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.864641532829500 08/31/22-23:45:18.781389
                    SID:2829500
                    Source Port:64641
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.850971532829498 08/31/22-23:45:24.890116
                    SID:2829498
                    Source Port:50971
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854882532829498 08/31/22-23:45:07.166788
                    SID:2829498
                    Source Port:54882
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854506532829500 08/31/22-23:44:51.025085
                    SID:2829500
                    Source Port:54506
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862634532829498 08/31/22-23:45:12.136668
                    SID:2829498
                    Source Port:62634
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857058532829498 08/31/22-23:45:18.283248
                    SID:2829498
                    Source Port:57058
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.859755532829500 08/31/22-23:44:14.146726
                    SID:2829500
                    Source Port:59755
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.863268532026737 08/31/22-23:44:37.399636
                    SID:2026737
                    Source Port:63268
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856299532026737 08/31/22-23:44:46.401563
                    SID:2026737
                    Source Port:56299
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.857517532829500 08/31/22-23:44:26.339554
                    SID:2829500
                    Source Port:57517
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855297532829500 08/31/22-23:45:37.673787
                    SID:2829500
                    Source Port:55297
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.862737532026737 08/31/22-23:44:31.038440
                    SID:2026737
                    Source Port:62737
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.856436532026737 08/31/22-23:45:05.726984
                    SID:2026737
                    Source Port:56436
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.854314532829498 08/31/22-23:45:50.878483
                    SID:2829498
                    Source Port:54314
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.849235532026737 08/31/22-23:44:09.091938
                    SID:2026737
                    Source Port:49235
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.68.8.8.855960532829498 08/31/22-23:44:24.995544
                    SID:2829498
                    Source Port:55960
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: BUgAyPXboK.exeVirustotal: Detection: 88%Perma Link
                    Source: BUgAyPXboK.exeMetadefender: Detection: 85%Perma Link
                    Source: BUgAyPXboK.exeReversingLabs: Detection: 100%
                    Source: BUgAyPXboK.exeAvira: detected
                    Source: http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144deAvira URL Cloud: Label: malware
                    Source: http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144deAvira URL Cloud: Label: phishing
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeAvira: detection malicious, Label: TR/Crypt.XPACK.Gen3
                    Source: BUgAyPXboK.exeJoe Sandbox ML: detected
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeJoe Sandbox ML: detected
                    Source: 12.0.ykbxzh.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 25.0.ykbxzh.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 25.2.ykbxzh.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 12.2.ykbxzh.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 0.0.BUgAyPXboK.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 0.2.BUgAyPXboK.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00405750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00405D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004048A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00407DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00405540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004048A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00405540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00405750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00405D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00407DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004048A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00405540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00405750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00405D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00407DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: BUgAyPXboK.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: BUgAyPXboK.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: z:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: x:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: v:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: t:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: r:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: p:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: n:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: l:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: j:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: h:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: f:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: b:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: y:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: w:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: u:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: s:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: q:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: o:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: m:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: k:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: i:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: g:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: e:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile opened: a:
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,

                    Networking

                    barindex
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62912 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62913 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62914 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62915 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:63865 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:63866 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:63867 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:63868 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63231 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63232 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63233 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63234 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62540 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62541 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62542 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62543 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54905 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54906 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54907 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54908 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51532 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51533 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51534 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51535 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52558 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52559 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52560 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52561 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:61611 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:61612 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:61613 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:61614 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52483 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52484 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52485 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52486 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53945 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53946 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53947 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53948 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56088 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56089 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56090 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56091 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56549 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56550 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56551 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56552 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:59883 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:59884 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:59885 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:59886 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50345 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50346 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50347 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50348 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62522 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62523 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62524 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62525 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56571 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61834 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61835 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61836 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:65046 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:65047 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:65048 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:65049 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:49234 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:49235 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:49236 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:49237 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56125 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56126 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56127 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56128 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59754 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59755 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59756 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59757 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52867 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52868 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52869 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52870 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62960 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62961 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62962 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62963 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64406 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64407 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64408 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64409 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62850 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62851 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62852 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62853 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:55958 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:55959 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:55960 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:55961 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57517 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57518 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57519 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57520 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51323 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51324 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51325 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51326 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61091 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61092 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61093 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61094 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60132 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60133 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60134 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60135 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62734 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62735 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62736 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:62737 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60692 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60693 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60694 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60695 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56752 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56753 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56754 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56755 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59338 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59339 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59340 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59341 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52717 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52718 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52719 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52720 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62223 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62224 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62225 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62226 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63265 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63266 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63267 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63268 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61231 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61232 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61233 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61234 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51774 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51775 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51776 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51777 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59224 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59225 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59226 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59227 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57756 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57757 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57758 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57759 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53592 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53593 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53594 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53595 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56360 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56361 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56362 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56363 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:49334 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:49335 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:49336 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:49337 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59967 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59968 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59969 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59970 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:58159 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:58160 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:58161 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:58162 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57788 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57789 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57790 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57791 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64963 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64964 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64965 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64966 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56297 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56298 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56299 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56300 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64649 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64650 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64651 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64652 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54505 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54506 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54507 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54508 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51889 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51890 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51891 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:51892 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54510 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54511 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54512 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54513 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53195 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53196 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53197 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:53198 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60010 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60011 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60012 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60013 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54202 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54203 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54204 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54205 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50254 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50255 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50256 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50257 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:64798 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:64799 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:64800 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:64801 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62539 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62038 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62039 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62040 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62041 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63672 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63673 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63674 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63675 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61172 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61173 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61174 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61175 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56429 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56430 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56431 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56432 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56433 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56434 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56435 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56436 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54881 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54882 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54883 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54884 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54298 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54299 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54300 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54301 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59625 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59626 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59627 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59628 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63256 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63257 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63258 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63259 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60356 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60357 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60358 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60359 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52727 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52728 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52729 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:52730 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62633 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62634 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62635 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:62636 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:52120 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:52121 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:52122 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:52123 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54754 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54755 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54756 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54757 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51686 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51687 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51688 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51689 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62946 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62947 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62948 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62949 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54331 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54332 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54333 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54334 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57056 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57057 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57058 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:57059 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64640 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64641 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64642 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:64643 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60169 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60170 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60171 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60172 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53048 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53049 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53050 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53051 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:49505 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:49506 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:49507 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:49508 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:50537 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:50538 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:50539 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:50540 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:50968 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:50969 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:50970 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:50971 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57690 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57691 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57692 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57693 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:61805 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:61806 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:61807 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:61808 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53271 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53272 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53273 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53274 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54490 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54491 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54492 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:54493 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56064 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56065 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56066 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56067 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61846 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61847 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61848 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61849 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59337 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59338 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59339 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:59340 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63435 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63436 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63437 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63438 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64931 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64932 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64933 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:64934 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62441 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62442 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62443 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:62444 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63987 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63988 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63989 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:63990 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52392 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52393 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52394 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:52395 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57188 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57189 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57190 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57191 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56772 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56773 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56774 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:56775 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56905 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56906 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56907 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:56908 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57095 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57096 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57097 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:57098 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59721 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59722 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59723 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59724 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51593 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51594 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51595 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:51596 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:55297 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:55298 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:55299 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:55300 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59531 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59532 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59533 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59534 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60776 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60777 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60778 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:60779 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50808 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50809 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50810 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:50811 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54099 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54100 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54101 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:54102 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61575 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61576 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61577 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:61578 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51624 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51625 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51626 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:51627 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60786 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60787 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60788 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:60789 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53956 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53957 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53958 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:53959 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60755 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60756 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60757 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60758 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59792 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59793 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59794 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:59795 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54312 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54313 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54314 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:54315 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56506 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56507 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56508 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:56509 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:57979 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:57980 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:57981 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:57982 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63500 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63501 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63502 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.6:63503 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60383 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60384 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60385 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.6:60386 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:55636 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:55637 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:55638 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.6:55639 -> 8.8.8.8:53
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: BUgAyPXboK.exe, 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: BUgAyPXboK.exe, 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: ykbxzh.exe, 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: ykbxzh.exe, 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: BUgAyPXboK.exeString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: BUgAyPXboK.exeString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: BUgAyPXboK.exeString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: BUgAyPXboK.exeString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: BUgAyPXboK.exeString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: BUgAyPXboK.exeString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: ykbxzh.exe.0.drString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: ykbxzh.exe.0.drString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: ykbxzh.exe.0.drString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: ykbxzh.exe.0.drString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: ykbxzh.exe.0.drString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: ykbxzh.exe.0.drString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: BUgAyPXboK.exe, ykbxzh.exe.0.drString found in binary or memory: https://www.torproject.org/
                    Source: unknownDNS traffic detected: queries for: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00407A00 lstrcatW,InternetCloseHandle,InternetConnectW,VirtualAlloc,wsprintfW,HttpOpenRequestW,HttpAddRequestHeadersW,HttpSendRequestW,InternetReadFile,InternetReadFile,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,VirtualFree,

                    Spam, unwanted Advertisements and Ransom Demands

                    barindex
                    Source: Yara matchFile source: BUgAyPXboK.exe, type: SAMPLE
                    Source: Yara matchFile source: 0.0.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 12.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 12.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 25.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 25.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000002.306373977.000000000040E000.00000004.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000C.00000002.292144226.000000000040E000.00000004.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: BUgAyPXboK.exe PID: 868, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: ykbxzh.exe PID: 5500, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: ykbxzh.exe PID: 4784, type: MEMORYSTR
                    Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, type: DROPPED
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: nslookup.exeProcess created: 44

                    System Summary

                    barindex
                    Source: BUgAyPXboK.exe, type: SAMPLEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 0.0.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 12.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 12.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 25.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 25.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 0.2.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, type: DROPPEDMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: BUgAyPXboK.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: BUgAyPXboK.exe, type: SAMPLEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: BUgAyPXboK.exe, type: SAMPLEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 0.0.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 0.0.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 12.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 12.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 12.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 12.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 25.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 25.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 25.0.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 25.2.ykbxzh.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 0.2.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 0.2.BUgAyPXboK.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, type: DROPPEDMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, type: DROPPEDMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00402000
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00407EE0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00402000
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_00407EE0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00402000
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_00407EE0
                    Source: BUgAyPXboK.exeVirustotal: Detection: 88%
                    Source: BUgAyPXboK.exeMetadefender: Detection: 85%
                    Source: BUgAyPXboK.exeReversingLabs: Detection: 100%
                    Source: BUgAyPXboK.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
                    Source: unknownProcess created: C:\Users\user\Desktop\BUgAyPXboK.exe "C:\Users\user\Desktop\BUgAyPXboK.exe"
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe "C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe"
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe "C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe"
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeJump to behavior
                    Source: classification engineClassification label: mal100.rans.troj.evad.winEXE@166/2@742/1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00406D90 VirtualAlloc,VirtualAlloc,GetUserNameW,VirtualAlloc,GetComputerNameW,wsprintfW,VirtualAlloc,wsprintfW,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,VirtualFree,VirtualAlloc,VirtualAlloc,wsprintfW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrcmpiW,wsprintfW,wsprintfW,VirtualFree,VirtualAlloc,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,wsprintfW,GetNativeSystemInfo,VirtualAlloc,wsprintfW,VirtualAlloc,VirtualAlloc,GetWindowsDirectoryW,GetVolumeInformationW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrlenW,wsprintfW,lstrcatW,lstrcatW,GetModuleHandleW,GetProcAddress,lstrlenW,VirtualFree,lstrcatW,VirtualAlloc,GetDriveTypeW,lstrcatW,lstrcatW,lstrcatW,GetDiskFreeSpaceW,lstrlenW,wsprintfW,wsprintfW,lstrlenW,lstrlenW,wsprintfW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00404640 CreateToolhelp32Snapshot,VirtualAlloc,Process32FirstW,CloseHandle,lstrcmpiW,OpenProcess,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,Process32NextW,VirtualFree,FindCloseChangeNotification,
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5336:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:812:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2688:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5340:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6040:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5896:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4772:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1676:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5500:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6128:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5276:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5588:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5928:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2608:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1908:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6088:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4628:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4856:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1572:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1964:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3244:120:WilError_01
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeMutant created: \Sessions\1\BaseNamedObjects\Global\pc_group=WORKGROUP&ransom_id=ff6866ce6d7bede6
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6052:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5940:120:WilError_01
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: Window RecorderWindow detected: More than 3 window changes detected
                    Source: BUgAyPXboK.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeJump to dropped file
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce cmskpbujpybJump to behavior
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce cmskpbujpybJump to behavior
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce cmskpbujpybJump to behavior
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce cmskpbujpybJump to behavior
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exe TID: 4652Thread sleep count: 116 > 30
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exe TID: 4652Thread sleep time: -1160000s >= -30000s
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeEvaded block: after key decision
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeEvaded block: after key decision
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: EnumDeviceDrivers,K32EnumDeviceDrivers,VirtualAlloc,K32EnumDeviceDrivers,K32GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: EnumDeviceDrivers,EnumDeviceDrivers,VirtualAlloc,EnumDeviceDrivers,GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: EnumDeviceDrivers,EnumDeviceDrivers,VirtualAlloc,EnumDeviceDrivers,GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 12_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeCode function: 25_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeSystem information queried: ModuleInformation
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00403A60 AllocateAndInitializeSid,GetModuleHandleA,GetProcAddress,FreeSid,
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00408BC0 cpuid
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
                    Source: C:\Users\user\Desktop\BUgAyPXboK.exeCode function: 0_2_00406D90 VirtualAlloc,VirtualAlloc,GetUserNameW,VirtualAlloc,GetComputerNameW,wsprintfW,VirtualAlloc,wsprintfW,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,VirtualFree,VirtualAlloc,VirtualAlloc,wsprintfW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrcmpiW,wsprintfW,wsprintfW,VirtualFree,VirtualAlloc,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,wsprintfW,GetNativeSystemInfo,VirtualAlloc,wsprintfW,VirtualAlloc,VirtualAlloc,GetWindowsDirectoryW,GetVolumeInformationW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrlenW,wsprintfW,lstrcatW,lstrcatW,GetModuleHandleW,GetProcAddress,lstrlenW,VirtualFree,lstrcatW,VirtualAlloc,GetDriveTypeW,lstrcatW,lstrcatW,lstrcatW,GetDiskFreeSpaceW,lstrlenW,wsprintfW,wsprintfW,lstrlenW,lstrlenW,wsprintfW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,VirtualFree,
                    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                    1
                    Replication Through Removable Media
                    2
                    Native API
                    1
                    Registry Run Keys / Startup Folder
                    11
                    Process Injection
                    1
                    Masquerading
                    OS Credential Dumping1
                    Security Software Discovery
                    1
                    Replication Through Removable Media
                    11
                    Archive Collected Data
                    Exfiltration Over Other Network Medium2
                    Encrypted Channel
                    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
                    Data Encrypted for Impact
                    Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                    Registry Run Keys / Startup Folder
                    1
                    Virtualization/Sandbox Evasion
                    LSASS Memory1
                    Virtualization/Sandbox Evasion
                    Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
                    Ingress Tool Transfer
                    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)11
                    Process Injection
                    Security Account Manager1
                    Process Discovery
                    SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
                    Non-Application Layer Protocol
                    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
                    Software Packing
                    NTDS11
                    Peripheral Device Discovery
                    Distributed Component Object ModelInput CaptureScheduled Transfer1
                    Application Layer Protocol
                    SIM Card SwapCarrier Billing Fraud
                    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
                    Account Discovery
                    SSHKeyloggingData Transfer Size Limits1
                    Proxy
                    Manipulate Device CommunicationManipulate App Store Rankings or Ratings
                    Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain Credentials1
                    System Owner/User Discovery
                    VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                    External Remote ServicesScheduled TaskStartup ItemsStartup ItemsCompile After DeliveryDCSync1
                    Remote System Discovery
                    Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                    Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem2
                    System Network Configuration Discovery
                    Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                    Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Masquerading/etc/passwd and /etc/shadow1
                    System Network Connections Discovery
                    Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
                    Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)Invalid Code SignatureNetwork Sniffing1
                    File and Directory Discovery
                    Taint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
                    Compromise Software Dependencies and Development ToolsWindows Command ShellCronCronRight-to-Left OverrideInput Capture44
                    System Information Discovery
                    Replication Through Removable MediaRemote Data StagingExfiltration Over Physical MediumMail ProtocolsService Stop
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet
                    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 694553 Sample: BUgAyPXboK.exe Startdate: 31/08/2022 Architecture: WINDOWS Score: 100 57 nomoreransom.bit 2->57 59 gandcrab.bit 2->59 61 3 other IPs or domains 2->61 65 Snort IDS alert for network traffic 2->65 67 Malicious sample detected (through community Yara rule) 2->67 69 Antivirus detection for URL or domain 2->69 71 5 other signatures 2->71 8 BUgAyPXboK.exe 1 28 2->8         started        13 ykbxzh.exe 2->13         started        15 ykbxzh.exe 2->15         started        signatures3 process4 dnsIp5 63 ipv4bot.whatismyipaddress.com 8->63 40 C:\Users\user\AppData\Roaming\...\ykbxzh.exe, PE32 8->40 dropped 73 Contains functionality to determine the online IP of the system 8->73 75 May check the online IP address of the machine 8->75 77 Uses nslookup.exe to query domains 8->77 17 nslookup.exe 1 8->17         started        20 nslookup.exe 1 8->20         started        22 nslookup.exe 1 8->22         started        24 20 other processes 8->24 79 Antivirus detection for dropped file 13->79 81 Machine Learning detection for dropped file 13->81 file6 signatures7 process8 dnsIp9 42 dns1.soprodns.ru 17->42 45 nomoreransom.bit 17->45 47 8.8.8.8.in-addr.arpa 17->47 26 conhost.exe 17->26         started        51 3 other IPs or domains 20->51 28 conhost.exe 20->28         started        53 3 other IPs or domains 22->53 30 conhost.exe 22->30         started        49 nomoreransom.bit 24->49 55 60 other IPs or domains 24->55 32 conhost.exe 24->32         started        34 conhost.exe 24->34         started        36 conhost.exe 24->36         started        38 17 other processes 24->38 signatures10 83 May check the online IP address of the machine 42->83 process11

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    BUgAyPXboK.exe89%VirustotalBrowse
                    BUgAyPXboK.exe86%MetadefenderBrowse
                    BUgAyPXboK.exe100%ReversingLabsWin32.Ransomware.GandCrab
                    BUgAyPXboK.exe100%AviraTR/Crypt.XPACK.Gen3
                    BUgAyPXboK.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLink
                    C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe100%AviraTR/Crypt.XPACK.Gen3
                    C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLinkDownload
                    12.0.ykbxzh.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    25.0.ykbxzh.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    25.2.ykbxzh.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    12.2.ykbxzh.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    0.0.BUgAyPXboK.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    0.2.BUgAyPXboK.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    SourceDetectionScannerLabelLink
                    emsisoft.bit0%VirustotalBrowse
                    nomoreransom.bit1%VirustotalBrowse
                    gandcrab.bit2%VirustotalBrowse
                    SourceDetectionScannerLabelLink
                    http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de100%Avira URL Cloudmalware
                    http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de100%Avira URL Cloudphishing
                    http://gdcbghvjyqy7jclk.onion/e644d32fec6144de0%Avira URL Cloudsafe
                    NameIPActiveMaliciousAntivirus DetectionReputation
                    emsisoft.bit
                    unknown
                    unknowntrueunknown
                    ipv4bot.whatismyipaddress.com
                    unknown
                    unknownfalse
                      high
                      nomoreransom.bit
                      unknown
                      unknowntrueunknown
                      gandcrab.bit
                      unknown
                      unknowntrueunknown
                      dns1.soprodns.ru
                      unknown
                      unknowntrue
                        unknown
                        8.8.8.8.in-addr.arpa
                        unknown
                        unknownfalse
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          https://www.torproject.org/BUgAyPXboK.exe, ykbxzh.exe.0.drfalse
                            high
                            http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144deBUgAyPXboK.exe, ykbxzh.exe.0.drfalse
                              high
                              http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144deBUgAyPXboK.exe, ykbxzh.exe.0.drfalse
                                high
                                http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144deBUgAyPXboK.exe, ykbxzh.exe.0.drtrue
                                • Avira URL Cloud: malware
                                unknown
                                http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144deBUgAyPXboK.exe, ykbxzh.exe.0.drtrue
                                • Avira URL Cloud: phishing
                                unknown
                                http://gdcbghvjyqy7jclk.onion/e644d32fec6144deBUgAyPXboK.exe, ykbxzh.exe.0.drtrue
                                • Avira URL Cloud: safe
                                unknown
                                http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144deBUgAyPXboK.exe, ykbxzh.exe.0.drfalse
                                  high
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  IP
                                  192.168.2.1
                                  Joe Sandbox Version:35.0.0 Citrine
                                  Analysis ID:694553
                                  Start date and time:2022-08-31 23:42:21 +02:00
                                  Joe Sandbox Product:CloudBasic
                                  Overall analysis duration:0h 7m 50s
                                  Hypervisor based Inspection enabled:false
                                  Report type:light
                                  Sample file name:BUgAyPXboK.exe
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                  Number of analysed new started processes analysed:63
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • HDC enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Detection:MAL
                                  Classification:mal100.rans.troj.evad.winEXE@166/2@742/1
                                  EGA Information:
                                  • Successful, ratio: 100%
                                  HDC Information:
                                  • Successful, ratio: 100% (good quality ratio 96.9%)
                                  • Quality average: 84.5%
                                  • Quality standard deviation: 23.2%
                                  HCA Information:
                                  • Successful, ratio: 99%
                                  • Number of executed functions: 0
                                  • Number of non-executed functions: 0
                                  Cookbook Comments:
                                  • Found application associated with file extension: .exe
                                  • Adjust boot time
                                  • Enable AMSI
                                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, svchost.exe
                                  • Excluded IPs from analysis (whitelisted): 20.82.154.241, 20.82.228.9
                                  • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, client.wns.windows.com, rp-consumer-prod-displaycatalog-geomap.trafficmanager.net, fs.microsoft.com, eudb.ris.api.iris.microsoft.com, neus2c-displaycatalog.frontdoor.bigcatalog.commerce.microsoft.com, ctldl.windowsupdate.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com, displaycatalog-rp.md.mp.microsoft.com.akadns.net, neus1c-displaycatalog.frontdoor.bigcatalog.commerce.microsoft.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size exceeded maximum capacity and may have missing behavior information.
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  TimeTypeDescription
                                  23:43:25AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce cmskpbujpyb "C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe"
                                  23:43:29API Interceptor116x Sleep call for process: BUgAyPXboK.exe modified
                                  23:43:35AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\RunOnce cmskpbujpyb "C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe"
                                  No context
                                  No context
                                  No context
                                  No context
                                  No context
                                  Process:C:\Users\user\Desktop\BUgAyPXboK.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2221
                                  Entropy (8bit):0.0
                                  Encrypted:false
                                  SSDEEP:3::
                                  MD5:8882037A0674A329B5AB8C870E58C422
                                  SHA1:FA2B896CE7908548EB54F6897A57DFCC9A333A49
                                  SHA-256:BF58499BF43BEC8D41F04779DAC5618A081455A657667C157DE019657224FEAD
                                  SHA-512:AAE711E67CAB35A320C533B2B939B1C171F9219B4813292F7CE0A64AF785679DDC23DBD61A3D31876558FA19C4E88D3DF845242C2210C226FB5D9D3DAECE6891
                                  Malicious:false
                                  Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Users\user\Desktop\BUgAyPXboK.exe
                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):75264
                                  Entropy (8bit):4.804310863125555
                                  Encrypted:false
                                  SSDEEP:1536:4gSeGDjtQhnwmmB0yjMqqUM2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:4MSjOnrmBbMqqMmr3IdE8we0Avu5r++N
                                  MD5:EE7A320AB14366D36D44CDC33B5E8238
                                  SHA1:744108B34CC6279D6FC78268EB8BA151BC3090AE
                                  SHA-256:B8333C93702F808152B0FA0F18A0CDC72E8F85B1BCC765F2AB1710A7F983B855
                                  SHA-512:E3F63DE252BBDD5A023789DD9DE9204B4996EAEC55422BF140E92EB6A0C0D5C93CF7977A52FC7FA7B971EF131BE423E20016EC6895E699C1EEE83CA4B88279D9
                                  Malicious:true
                                  Yara Hits:
                                  • Rule: SUSP_RANSOMWARE_Indicator_Jul20, Description: Detects ransomware indicator, Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, Author: Florian Roth
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, Author: Joe Security
                                  • Rule: Gandcrab, Description: Gandcrab Payload, Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, Author: kevoreilly
                                  Antivirus:
                                  • Antivirus: Avira, Detection: 100%
                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                  Preview:MZ......................@...............................................!..L.!This .u....m cannot be run in DOS mode....$.......AU@..4...4...4..Ce...4..Ce...4...f...4...4...4...L...4...4/.4...f...4...f...4...f...4..Rich.4..................PE..L...].vZ.............................J............@..........................`............@.................................p........@.......................P.......................................................................................text............................... ..`.rdata..............................@....data........ ......................@....CRT.........0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................................
                                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Entropy (8bit):4.804404197820735
                                  TrID:
                                  • Win32 Executable (generic) a (10002005/4) 99.96%
                                  • Generic Win/DOS Executable (2004/3) 0.02%
                                  • DOS Executable Generic (2002/1) 0.02%
                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                  File name:BUgAyPXboK.exe
                                  File size:75264
                                  MD5:dde91b6947d2b726e5bb8f5852cecb76
                                  SHA1:7d2467c4e65238599c5fd05641c628fb4252c7ca
                                  SHA256:eae8d675873bd846302263fdca95db805b560d3406ec964f76b2d4123f78b59a
                                  SHA512:d7c5a4ae4e4a641d0ec8c821ef6356d17b35fd52999b95c0b1b882587a7fb536407012203468644577ea6daeda913d1603d2c59034555ec1bce43973592704e8
                                  SSDEEP:1536:kgSeGDjtQhnwmmB0yjMqqUM2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:kMSjOnrmBbMqqMmr3IdE8we0Avu5r++N
                                  TLSH:A67318053AE18133FAF2F9B265B869E1587B7E545B287ADF00E8043E19275E25D30B4F
                                  File Content Preview:MZ......................@...............................................!..L.!This ...X.1m cannot be run in DOS mode....$.......AU@..4...4...4..Ce...4..Ce...4...f...4...4...4...L...4...4/..4...f...4...f...4...f...4..Rich.4..................PE..L...].vZ...
                                  Icon Hash:00828e8e8686b000
                                  Entrypoint:0x404af0
                                  Entrypoint Section:.text
                                  Digitally signed:false
                                  Imagebase:0x400000
                                  Subsystem:windows gui
                                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                  DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                  Time Stamp:0x5A76065D [Sat Feb 3 18:58:37 2018 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:5
                                  OS Version Minor:1
                                  File Version Major:5
                                  File Version Minor:1
                                  Subsystem Version Major:5
                                  Subsystem Version Minor:1
                                  Import Hash:40306b615af659fc1f93cfb121cc38d9
                                  Instruction
                                  push ebp
                                  mov ebp, esp
                                  call 00007F8528A3986Dh
                                  push 00000000h
                                  call dword ptr [00409168h]
                                  pop ebp
                                  ret
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  push ebp
                                  mov ebp, esp
                                  sub esp, 5Ch
                                  push esi
                                  push 00000044h
                                  lea eax, dword ptr [ebp-58h]
                                  xorps xmm0, xmm0
                                  push 00000000h
                                  push eax
                                  mov esi, ecx
                                  movdqu dqword ptr [ebp-10h], xmm0
                                  call 00007F8528A3DAC7h
                                  mov eax, dword ptr [00412B0Ch]
                                  add esp, 0Ch
                                  mov dword ptr [ebp-18h], eax
                                  mov dword ptr [ebp-1Ch], eax
                                  mov eax, dword ptr [00412B08h]
                                  or dword ptr [ebp-2Ch], 00000101h
                                  mov dword ptr [ebp-20h], eax
                                  xor eax, eax
                                  mov word ptr [ebp-28h], ax
                                  lea eax, dword ptr [ebp-10h]
                                  push eax
                                  lea eax, dword ptr [ebp-58h]
                                  mov dword ptr [ebp-58h], 00000044h
                                  push eax
                                  push 00000000h
                                  push 00000000h
                                  push 00000000h
                                  push 00000001h
                                  push 00000000h
                                  push 00000000h
                                  push esi
                                  push 00000000h
                                  call dword ptr [00409164h]
                                  test eax, eax
                                  jne 00007F8528A39ACDh
                                  call dword ptr [00409064h]
                                  pop esi
                                  mov esp, ebp
                                  pop ebp
                                  ret
                                  push dword ptr [ebp-10h]
                                  mov esi, dword ptr [0040910Ch]
                                  call esi
                                  push dword ptr [ebp-0Ch]
                                  call esi
                                  pop esi
                                  mov esp, ebp
                                  pop ebp
                                  ret
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  int3
                                  push ebp
                                  mov ebp, esp
                                  sub esp, 10h
                                  movq xmm0, qword ptr [0040FF2Ch]
                                  mov al, byte ptr [0040FF34h]
                                  push ebx
                                  mov ebx, dword ptr [ebp+08h]
                                  Programming Language:
                                  • [ C ] VS2013 build 21005
                                  • [IMP] VS2008 SP1 build 30729
                                  • [RES] VS2013 build 21005
                                  • [LNK] VS2013 build 21005
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x109700xb4.rdata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x140000x1e0.rsrc
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x150000xab0.reloc
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  .text0x10000x80000x8000False0.439727783203125data5.762192122939682IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                  .rdata0x90000x90000x8600False0.26437150186567165data3.71703192533741IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .data0x120000x10000xc00False0.2613932291666667data3.15531156836296IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .CRT0x130000x10000x200False0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .rsrc0x140000x10000x200False0.52734375data4.710061382693063IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .reloc0x150000x10000xc00False0.008138020833333334data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                  NameRVASizeTypeLanguageCountry
                                  RT_MANIFEST0x140600x17dXML 1.0 document textEnglishUnited States
                                  DLLImport
                                  KERNEL32.dllSetFilePointer, GetFileAttributesW, ReadFile, GetLastError, MoveFileW, lstrcpyW, SetFileAttributesW, CreateMutexW, GetDriveTypeW, VerSetConditionMask, WaitForSingleObject, GetTickCount, InitializeCriticalSection, OpenProcess, GetSystemDirectoryW, TerminateThread, Sleep, TerminateProcess, VerifyVersionInfoW, WaitForMultipleObjects, DeleteCriticalSection, ExpandEnvironmentStringsW, lstrlenW, SetHandleInformation, lstrcatA, MultiByteToWideChar, CreatePipe, lstrcmpiA, Process32NextW, CreateToolhelp32Snapshot, LeaveCriticalSection, EnterCriticalSection, FindFirstFileW, lstrcmpW, FindClose, FindNextFileW, GetNativeSystemInfo, GetComputerNameW, GetDiskFreeSpaceW, GetWindowsDirectoryW, GetVolumeInformationW, LoadLibraryA, lstrcmpiW, VirtualFree, CreateThread, CloseHandle, lstrcatW, CreateFileMappingW, ExitThread, CreateFileW, GetModuleFileNameW, WriteFile, GetModuleHandleW, UnmapViewOfFile, MapViewOfFile, GetFileSize, GetEnvironmentVariableW, lstrcpyA, GetModuleHandleA, VirtualAlloc, Process32FirstW, GetTempPathW, GetProcAddress, GetProcessHeap, HeapFree, HeapAlloc, lstrlenA, CreateProcessW, ExitProcess, IsProcessorFeaturePresent
                                  USER32.dllwsprintfW, TranslateMessage, RegisterClassExW, LoadIconW, SetWindowLongW, EndPaint, BeginPaint, LoadCursorW, GetMessageW, ShowWindow, CreateWindowExW, SendMessageW, DispatchMessageW, DefWindowProcW, UpdateWindow, GetForegroundWindow, DestroyWindow
                                  GDI32.dllTextOutW
                                  ADVAPI32.dllCryptExportKey, AllocateAndInitializeSid, RegSetValueExW, RegCreateKeyExW, RegCloseKey, CryptAcquireContextW, CryptGetKeyParam, CryptReleaseContext, CryptImportKey, CryptEncrypt, CryptGenKey, CryptDestroyKey, GetUserNameW, RegQueryValueExW, RegOpenKeyExW, FreeSid
                                  SHELL32.dllSHGetSpecialFolderPathW, ShellExecuteExW, ShellExecuteW
                                  CRYPT32.dllCryptStringToBinaryA, CryptBinaryToStringA
                                  WININET.dllInternetCloseHandle, HttpAddRequestHeadersW, HttpSendRequestW, InternetConnectW, HttpOpenRequestW, InternetOpenW, InternetReadFile
                                  PSAPI.DLLEnumDeviceDrivers, GetDeviceDriverBaseNameW
                                  Language of compilation systemCountry where language is spokenMap
                                  EnglishUnited States
                                  TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                  192.168.2.68.8.8.859531532026737 08/31/22-23:45:39.973829UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5953153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854507532829500 08/31/22-23:44:51.051028UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35450753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856433532026737 08/31/22-23:45:05.669170UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5643353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859724532026737 08/31/22-23:45:37.047109UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5972453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859626532026737 08/31/22-23:45:09.130817UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5962653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860383532829500 08/31/22-23:45:54.073595UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36038353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856298532026737 08/31/22-23:44:46.383892UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5629853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864965532829500 08/31/22-23:44:45.948752UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36496553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862224532829500 08/31/22-23:44:36.753658UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36222453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861613532829500 08/31/22-23:43:46.602572UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36161353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856363532026737 08/31/22-23:44:42.471272UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5636353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856507532829500 08/31/22-23:45:51.692352UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35650753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852121532829500 08/31/22-23:45:13.843635UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35212153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863867532829500 08/31/22-23:43:31.143411UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36386753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854513532829498 08/31/22-23:44:53.235786UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15451353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854757532026737 08/31/22-23:45:14.540780UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5475753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850347532829500 08/31/22-23:44:00.906690UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35034753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860134532829500 08/31/22-23:44:29.746960UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36013453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861173532829498 08/31/22-23:45:03.206529UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16117353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852486532026737 08/31/22-23:43:48.342534UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5248653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864649532829498 08/31/22-23:44:48.847826UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16464953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864798532026737 08/31/22-23:44:59.208494UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6479853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863501532829498 08/31/22-23:45:53.807893UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16350153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850968532829498 08/31/22-23:45:24.827189UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15096853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862915532829498 08/31/22-23:43:29.888154UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16291553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863438532026737 08/31/22-23:45:30.070764UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6343853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852719532829498 08/31/22-23:44:35.284576UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15271953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863675532026737 08/31/22-23:45:02.703986UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6367553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854493532829500 08/31/22-23:45:28.756602UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35449353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852729532026737 08/31/22-23:45:11.556204UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5272953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860170532026737 08/31/22-23:45:19.218542UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6017053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864409532829500 08/31/22-23:44:20.846616UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36440953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850257532829500 08/31/22-23:44:58.802648UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35025753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856551532026737 08/31/22-23:43:56.858808UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5655153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852870532026737 08/31/22-23:44:15.600002UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5287053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.858159532026737 08/31/22-23:44:44.437835UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5815953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856429532829500 08/31/22-23:45:04.151432UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35642953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859756532829500 08/31/22-23:44:14.164883UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35975653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854881532829498 08/31/22-23:45:07.148628UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15488153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860693532829498 08/31/22-23:44:32.915750UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16069353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.865048532829500 08/31/22-23:44:07.531291UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36504853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862523532026737 08/31/22-23:44:02.606977UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6252353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857788532829498 08/31/22-23:44:45.461187UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15778853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854202532829498 08/31/22-23:44:57.085032UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15420253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859224532026737 08/31/22-23:44:39.557927UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5922453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862949532829500 08/31/22-23:45:16.848920UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36294953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864652532829498 08/31/22-23:44:48.958101UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16465253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853271532829498 08/31/22-23:45:27.889217UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852867532026737 08/31/22-23:44:15.534930UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5286753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851776532829500 08/31/22-23:44:39.007949UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35177653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857059532829498 08/31/22-23:45:18.303571UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15705953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857981532026737 08/31/22-23:45:53.032065UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5798153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862850532026737 08/31/22-23:44:23.403881UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6285053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853947532829498 08/31/22-23:43:50.950634UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15394753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857519532829500 08/31/22-23:44:26.384204UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35751953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854313532829498 08/31/22-23:45:50.857498UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15431353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856752532829500 08/31/22-23:44:33.536411UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35675253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859885532829498 08/31/22-23:43:58.594444UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15988553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860757532829500 08/31/22-23:45:46.254203UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36075753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856549532026737 08/31/22-23:43:56.812959UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5654953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851890532026737 08/31/22-23:44:51.640850UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850256532829500 08/31/22-23:44:58.782280UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35025653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855298532829500 08/31/22-23:45:37.693886UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35529853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859969532829500 08/31/22-23:44:44.030720UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35996953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855639532026737 08/31/22-23:45:55.456580UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5563953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851689532829498 08/31/22-23:45:15.310184UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15168953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863232532026737 08/31/22-23:43:32.344833UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6323253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859757532829500 08/31/22-23:44:14.192618UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35975753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857790532829498 08/31/22-23:44:45.500682UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15779053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862963532829498 08/31/22-23:44:17.245311UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16296353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860786532026737 08/31/22-23:45:45.011230UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6078653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863256532829498 08/31/22-23:45:10.074723UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16325653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856065532026737 08/31/22-23:45:29.057624UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5606553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853050532829498 08/31/22-23:45:20.171719UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15305053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856552532026737 08/31/22-23:43:56.877030UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5655253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851626532829500 08/31/22-23:45:44.232922UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35162653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859886532829498 08/31/22-23:43:58.614290UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15988653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863266532026737 08/31/22-23:44:37.362093UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6326653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853956532829498 08/31/22-23:45:45.816937UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15395653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854301532829500 08/31/22-23:45:08.700152UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35430153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862636532829498 08/31/22-23:45:12.181439UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16263653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854101532026737 08/31/22-23:45:43.138088UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5410153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849237532026737 08/31/22-23:44:09.133303UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4923753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860011532026737 08/31/22-23:44:56.144537UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6001153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856128532829498 08/31/22-23:44:10.647184UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15612853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859627532026737 08/31/22-23:45:09.148937UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5962753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849507532829500 08/31/22-23:45:22.271617UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34950753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854312532829498 08/31/22-23:45:50.836877UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15431253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849337532829498 08/31/22-23:44:43.512238UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14933753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856297532026737 08/31/22-23:44:46.363903UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5629753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857979532026737 08/31/22-23:45:52.995555UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5797953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852394532829498 08/31/22-23:45:33.462720UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15239453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861807532026737 08/31/22-23:45:26.638406UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6180753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860692532829498 08/31/22-23:44:32.895962UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16069253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857759532829498 08/31/22-23:44:41.121343UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15775953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860789532026737 08/31/22-23:45:45.071628UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6078953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857190532829500 08/31/22-23:45:34.277428UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35719053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857982532026737 08/31/22-23:45:53.052190UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5798253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864931532829498 08/31/22-23:45:31.895021UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16493153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856125532829498 08/31/22-23:44:10.587852UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15612553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863259532829498 08/31/22-23:45:10.134383UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16325953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864651532829498 08/31/22-23:44:48.937934UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16465153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854908532829500 08/31/22-23:43:40.017875UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35490853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855959532829498 08/31/22-23:44:24.973756UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15595953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856907532829498 08/31/22-23:45:34.930944UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15690753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853959532829498 08/31/22-23:45:45.873966UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15395953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861578532829498 08/31/22-23:45:43.955052UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16157853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861094532829498 08/31/22-23:44:27.968897UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16109453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857188532829500 08/31/22-23:45:34.238634UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35718853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859794532026737 08/31/22-23:45:48.558569UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5979453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851326532026737 08/31/22-23:44:27.434988UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5132653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862040532829500 08/31/22-23:45:01.158698UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36204053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864640532829500 08/31/22-23:45:18.759264UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36464053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854203532829498 08/31/22-23:44:57.105081UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15420353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851889532026737 08/31/22-23:44:51.620571UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5188953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860010532026737 08/31/22-23:44:56.124573UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6001053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863502532829498 08/31/22-23:45:53.826060UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16350253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.858161532026737 08/31/22-23:44:44.475598UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5816153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863437532026737 08/31/22-23:45:30.050806UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6343753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864964532829500 08/31/22-23:44:45.929172UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36496453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853198532829500 08/31/22-23:44:54.703855UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35319853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864934532829498 08/31/22-23:45:31.953591UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16493453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851532532026737 08/31/22-23:43:41.630051UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5153253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864408532829500 08/31/22-23:44:20.826579UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36440853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850540532026737 08/31/22-23:45:24.416776UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5054053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856434532026737 08/31/22-23:45:05.689287UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5643453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853595532829500 08/31/22-23:44:41.898667UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35359553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854508532829500 08/31/22-23:44:51.075095UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35450853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857098532829500 08/31/22-23:45:35.742268UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35709853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854905532829500 08/31/22-23:43:39.956403UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35490553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864799532026737 08/31/22-23:44:59.228975UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6479953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861614532829500 08/31/22-23:43:46.625363UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36161453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862223532829500 08/31/22-23:44:36.732224UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36222353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850810532829500 08/31/22-23:45:42.795800UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35081053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860758532829500 08/31/22-23:45:46.272226UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36075853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864406532829500 08/31/22-23:44:20.786154UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36440653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864932532829498 08/31/22-23:45:31.915004UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16493253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863868532829500 08/31/22-23:43:31.170740UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36386853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864966532829500 08/31/22-23:44:45.968566UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36496653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862635532829498 08/31/22-23:45:12.157482UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16263553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850970532829498 08/31/22-23:45:24.869816UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15097053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860755532829500 08/31/22-23:45:46.217401UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36075553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864642532829500 08/31/22-23:45:18.801787UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36464253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863987532026737 08/31/22-23:45:33.034613UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6398753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856091532829500 08/31/22-23:43:52.113643UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35609153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854300532829500 08/31/22-23:45:08.678590UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35430053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854907532829500 08/31/22-23:43:39.999758UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35490753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861234532829498 08/31/22-23:44:38.522132UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16123453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861172532829498 08/31/22-23:45:03.186618UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16117253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862736532026737 08/31/22-23:44:30.983637UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6273653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859723532026737 08/31/22-23:45:37.029063UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5972353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855300532829500 08/31/22-23:45:37.734665UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35530053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850255532829500 08/31/22-23:44:58.762397UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35025553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849236532026737 08/31/22-23:44:09.112716UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4923653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856908532829498 08/31/22-23:45:34.949400UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15690853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860013532026737 08/31/22-23:44:56.185703UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6001353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861808532026737 08/31/22-23:45:26.658197UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6180853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851624532829500 08/31/22-23:45:44.191433UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35162453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857518532829500 08/31/22-23:44:26.364052UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35751853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856360532026737 08/31/22-23:44:42.410727UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5636053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851535532026737 08/31/22-23:43:41.693076UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5153553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852717532829498 08/31/22-23:44:35.238130UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15271753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861231532829498 08/31/22-23:44:38.465975UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16123153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862633532829498 08/31/22-23:45:12.116146UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16263353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859532532026737 08/31/22-23:45:39.991955UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5953253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859792532026737 08/31/22-23:45:48.517877UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5979253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855637532026737 08/31/22-23:45:55.417422UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5563753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849506532829500 08/31/22-23:45:22.251711UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34950653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856773532026737 08/31/22-23:45:34.608670UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5677353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851323532026737 08/31/22-23:44:27.377732UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5132353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856126532829498 08/31/22-23:44:10.607141UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15612653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861575532829498 08/31/22-23:45:43.896304UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16157553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857096532829500 08/31/22-23:45:35.703871UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35709653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860777532829498 08/31/22-23:45:40.857769UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852868532026737 08/31/22-23:44:15.557965UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5286853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861091532829498 08/31/22-23:44:27.912765UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16109153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863233532026737 08/31/22-23:43:32.365334UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6323353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861848532829498 08/31/22-23:45:29.448150UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16184853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863674532026737 08/31/22-23:45:02.682245UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6367453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.865049532829500 08/31/22-23:44:07.555130UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36504953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853592532829500 08/31/22-23:44:41.838524UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35359253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851595532829498 08/31/22-23:45:37.395999UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15159553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852561532829498 08/31/22-23:43:44.313767UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15256153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860386532829500 08/31/22-23:45:54.135455UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36038653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854754532026737 08/31/22-23:45:14.478679UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5475453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854299532829500 08/31/22-23:45:08.657968UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35429953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856905532829498 08/31/22-23:45:34.890654UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15690553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852728532026737 08/31/22-23:45:11.538182UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5272853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852559532829498 08/31/22-23:43:44.275226UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15255953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856571532829498 08/31/22-23:44:04.765178UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15657153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856509532829500 08/31/22-23:45:51.736467UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35650953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857691532829500 08/31/22-23:45:26.303054UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35769153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861805532026737 08/31/22-23:45:26.598524UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6180553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864800532026737 08/31/22-23:44:59.249276UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6480053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854102532026737 08/31/22-23:45:43.158257UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5410253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862541532829498 08/31/22-23:45:00.327889UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16254153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860133532829500 08/31/22-23:44:29.726898UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36013353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859339532026737 08/31/22-23:44:34.622255UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5933953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860358532829500 08/31/22-23:45:11.129894UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36035853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860171532026737 08/31/22-23:45:19.238395UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6017153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852393532829498 08/31/22-23:45:33.441343UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15239353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851891532026737 08/31/22-23:44:51.663811UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856432532829500 08/31/22-23:45:04.211842UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35643253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862038532829500 08/31/22-23:45:01.120775UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36203853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863865532829500 08/31/22-23:43:31.097637UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36386553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854334532026737 08/31/22-23:45:17.822080UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5433453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854331532026737 08/31/22-23:45:17.760023UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5433153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856753532829500 08/31/22-23:44:33.556718UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35675353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854511532829498 08/31/22-23:44:53.195102UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15451153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853051532829498 08/31/22-23:45:20.191618UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15305153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862539532829498 08/31/22-23:45:00.266317UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16253953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854492532829500 08/31/22-23:45:28.736488UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35449253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856089532829500 08/31/22-23:43:52.075291UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35608953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859968532829500 08/31/22-23:44:44.010316UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35996853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859339532829500 08/31/22-23:45:29.745493UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35933953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851777532829500 08/31/22-23:44:39.027584UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35177753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856506532829500 08/31/22-23:45:51.673642UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35650653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852483532026737 08/31/22-23:43:48.282565UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5248353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853948532829498 08/31/22-23:43:50.969584UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15394853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853195532829500 08/31/22-23:44:54.646933UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35319553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862524532026737 08/31/22-23:44:02.627433UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6252453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861611532829500 08/31/22-23:43:46.559519UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36161153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857757532829498 08/31/22-23:44:41.083129UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15775753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862961532829498 08/31/22-23:44:17.199822UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16296153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.858160532026737 08/31/22-23:44:44.457604UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5816053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.865046532829500 08/31/22-23:44:07.490248UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36504653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851687532829498 08/31/22-23:45:15.269352UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15168753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854491532829500 08/31/22-23:45:28.716622UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35449153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853197532829500 08/31/22-23:44:54.685783UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35319753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862947532829500 08/31/22-23:45:16.811046UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36294753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853273532829498 08/31/22-23:45:27.934014UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850808532829500 08/31/22-23:45:42.752242UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35080853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856430532829500 08/31/22-23:45:04.173628UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35643053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859227532026737 08/31/22-23:44:39.617895UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5922753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851774532829500 08/31/22-23:44:38.969749UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35177453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849335532829498 08/31/22-23:44:43.471732UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14933553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859970532829500 08/31/22-23:44:44.048963UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35997053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850811532829500 08/31/22-23:45:42.813839UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35081153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853945532829498 08/31/22-23:43:50.908833UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15394553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861577532829498 08/31/22-23:45:43.934540UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16157753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859795532026737 08/31/22-23:45:48.583140UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5979553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854906532829500 08/31/22-23:43:39.979642UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35490653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860695532829498 08/31/22-23:44:32.965263UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16069553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857520532829500 08/31/22-23:44:26.402095UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35752053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864933532829498 08/31/22-23:45:31.933353UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16493353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851325532026737 08/31/22-23:44:27.416197UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5132553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854204532829498 08/31/22-23:44:57.124925UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15420453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859337532829500 08/31/22-23:45:29.704403UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35933753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853049532829498 08/31/22-23:45:20.151836UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15304953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850538532026737 08/31/22-23:45:24.374820UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5053853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857692532829500 08/31/22-23:45:26.323011UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35769253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862853532026737 08/31/22-23:44:23.460622UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6285353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864407532829500 08/31/22-23:44:20.806285UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36440753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864650532829498 08/31/22-23:44:48.868078UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16465053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857057532829498 08/31/22-23:45:18.264695UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15705753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863672532026737 08/31/22-23:45:02.641322UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6367253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856300532026737 08/31/22-23:44:46.422476UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5630053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861175532829498 08/31/22-23:45:03.248644UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16117553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863503532829498 08/31/22-23:45:53.846708UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16350353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853958532829498 08/31/22-23:45:45.853434UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15395853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864963532829500 08/31/22-23:44:45.907609UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36496353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863436532026737 08/31/22-23:45:30.030649UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6343653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862443532829500 08/31/22-23:45:32.738675UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36244353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862041532829500 08/31/22-23:45:01.185034UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36204153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855958532829498 08/31/22-23:44:24.955368UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15595853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854315532829498 08/31/22-23:45:50.898635UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15431553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856435532026737 08/31/22-23:45:05.709061UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5643553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852484532026737 08/31/22-23:43:48.300604UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5248453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855961532829498 08/31/22-23:44:25.014723UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15596153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856775532026737 08/31/22-23:45:34.651620UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5677553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849234532026737 08/31/22-23:44:09.071545UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4923453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863258532829498 08/31/22-23:45:10.114400UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16325853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860788532026737 08/31/22-23:45:45.053319UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6078853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862226532829500 08/31/22-23:44:36.798472UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36222653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859754532829500 08/31/22-23:44:14.128267UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35975453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862913532829498 08/31/22-23:43:29.846372UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16291353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854883532829498 08/31/22-23:45:07.190819UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15488353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859967532829500 08/31/22-23:44:43.992635UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35996753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854505532829500 08/31/22-23:44:51.004869UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35450553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861835532829498 08/31/22-23:44:04.805216UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16183553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859883532829498 08/31/22-23:43:58.553914UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15988353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856754532829500 08/31/22-23:44:33.577050UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35675453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862735532026737 08/31/22-23:44:30.963319UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6273553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859534532026737 08/31/22-23:45:40.030175UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5953453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859341532026737 08/31/22-23:44:34.662548UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5934153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859338532026737 08/31/22-23:44:34.602119UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5933853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864643532829500 08/31/22-23:45:18.822080UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36464353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852730532026737 08/31/22-23:45:11.576227UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5273053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851534532026737 08/31/22-23:43:41.673206UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5153453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850345532829500 08/31/22-23:44:00.864997UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35034553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851627532829500 08/31/22-23:45:44.253365UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35162753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852727532026737 08/31/22-23:45:11.519431UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5272753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862039532829500 08/31/22-23:45:01.138670UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36203953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860169532026737 08/31/22-23:45:19.198459UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6016953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860172532026737 08/31/22-23:45:19.258880UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6017253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856066532026737 08/31/22-23:45:29.077449UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5606653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862852532026737 08/31/22-23:44:23.440318UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6285253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863267532026737 08/31/22-23:44:37.381873UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6326753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855299532829500 08/31/22-23:45:37.714101UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35529953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854205532829498 08/31/22-23:44:57.145411UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15420553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863988532026737 08/31/22-23:45:33.054662UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6398853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854333532026737 08/31/22-23:45:17.804037UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5433353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860778532829498 08/31/22-23:45:40.877620UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852123532829500 08/31/22-23:45:13.882213UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35212353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850809532829500 08/31/22-23:45:42.775516UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35080953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859226532026737 08/31/22-23:44:39.597797UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5922653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862442532829500 08/31/22-23:45:32.718407UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36244253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854332532026737 08/31/22-23:45:17.784189UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5433253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861576532829498 08/31/22-23:45:43.916183UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16157653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857056532829498 08/31/22-23:45:18.246350UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15705653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861233532829498 08/31/22-23:44:38.502415UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16123353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856361532026737 08/31/22-23:44:42.430522UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5636153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862948532829500 08/31/22-23:45:16.831038UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36294853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861834532829498 08/31/22-23:44:04.785165UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16183453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853594532829500 08/31/22-23:44:41.878318UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35359453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854884532829498 08/31/22-23:45:07.210988UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15488453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862522532026737 08/31/22-23:44:02.586427UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6252253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850539532026737 08/31/22-23:45:24.397103UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5053953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851596532829498 08/31/22-23:45:37.416090UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15159653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859340532026737 08/31/22-23:44:34.642153UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5934053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851593532829498 08/31/22-23:45:37.355426UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15159353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.865047532829500 08/31/22-23:44:07.510331UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36504753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862543532829498 08/31/22-23:43:34.588739UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16254353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860357532829500 08/31/22-23:45:11.111963UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36035753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862540532829498 08/31/22-23:45:00.304908UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16254053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853946532829498 08/31/22-23:43:50.926739UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15394653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851775532829500 08/31/22-23:44:38.988155UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35177553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849334532829498 08/31/22-23:44:43.443293UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14933453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855636532026737 08/31/22-23:45:55.399161UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5563653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860385532829500 08/31/22-23:45:54.115289UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36038553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861847532829498 08/31/22-23:45:29.427867UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16184753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857095532829500 08/31/22-23:45:35.685539UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35709553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863673532026737 08/31/22-23:45:02.662218UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6367353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859722532026737 08/31/22-23:45:37.008989UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5972253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853272532829498 08/31/22-23:45:27.910057UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856774532026737 08/31/22-23:45:34.633210UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5677453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854755532026737 08/31/22-23:45:14.500005UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5475553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861093532829498 08/31/22-23:44:27.948801UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16109353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862912532829498 08/31/22-23:43:29.827972UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16291253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863435532026737 08/31/22-23:45:30.010284UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6343553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859340532829500 08/31/22-23:45:29.765614UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35934053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856090532829500 08/31/22-23:43:52.093457UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35609053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857191532829500 08/31/22-23:45:34.298140UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35719153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862444532829500 08/31/22-23:45:32.758993UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36244453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849508532829500 08/31/22-23:45:22.293889UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34950853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849336532829498 08/31/22-23:44:43.492294UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14933653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854512532829498 08/31/22-23:44:53.215474UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15451253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861174532829498 08/31/22-23:45:03.230028UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16117453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850348532829500 08/31/22-23:44:00.930724UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35034853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856755532829500 08/31/22-23:44:33.597404UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35675553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850969532829498 08/31/22-23:45:24.845855UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15096953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856550532026737 08/31/22-23:43:56.837414UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5655053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861836532829498 08/31/22-23:44:04.825892UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16183653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860135532829500 08/31/22-23:44:29.765194UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36013553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850537532026737 08/31/22-23:45:24.354748UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5053753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857693532829500 08/31/22-23:45:26.343034UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35769353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854100532026737 08/31/22-23:45:43.119824UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5410053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859338532829500 08/31/22-23:45:29.724262UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35933853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856431532829500 08/31/22-23:45:04.193694UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35643153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853274532829498 08/31/22-23:45:27.954080UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857756532829498 08/31/22-23:44:41.063437UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15775653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852122532829500 08/31/22-23:45:13.864005UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35212253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863990532026737 08/31/22-23:45:33.098684UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6399053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860694532829498 08/31/22-23:44:32.941274UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16069453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856508532829500 08/31/22-23:45:51.716328UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35650853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862946532829500 08/31/22-23:45:16.791073UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36294653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854490532829500 08/31/22-23:45:28.698486UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35449053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856362532026737 08/31/22-23:44:42.450740UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5636253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852485532026737 08/31/22-23:43:48.319052UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5248553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862962532829498 08/31/22-23:44:17.220032UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16296253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863231532026737 08/31/22-23:43:32.324505UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6323153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853048532829498 08/31/22-23:45:20.133745UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15304853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864801532026737 08/31/22-23:44:59.269048UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6480153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854756532026737 08/31/22-23:45:14.520580UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5475653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862525532026737 08/31/22-23:44:02.647686UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6252553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851688532829498 08/31/22-23:45:15.290256UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15168853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856906532829498 08/31/22-23:45:34.910660UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15690653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852560532829498 08/31/22-23:43:44.295389UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15256053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850346532829500 08/31/22-23:44:00.886556UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35034653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863500532829498 08/31/22-23:45:53.787672UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16350053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860776532829498 08/31/22-23:45:40.839433UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860779532829498 08/31/22-23:45:40.897866UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860384532829500 08/31/22-23:45:54.095085UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36038453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861092532829498 08/31/22-23:44:27.930612UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16109253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852869532026737 08/31/22-23:44:15.578775UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5286953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856088532829500 08/31/22-23:43:52.054951UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35608853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851324532026737 08/31/22-23:44:27.397683UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5132453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854510532829498 08/31/22-23:44:53.176959UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15451053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863866532829500 08/31/22-23:43:31.119406UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36386653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852395532829498 08/31/22-23:45:33.483017UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15239553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851892532026737 08/31/22-23:44:51.684138UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860356532829500 08/31/22-23:45:11.093877UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36035653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861612532829500 08/31/22-23:43:46.582342UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36161253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862960532829498 08/31/22-23:44:17.126999UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16296053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857758532829498 08/31/22-23:44:41.103311UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15775853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852120532829500 08/31/22-23:45:13.823401UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35212053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853196532829500 08/31/22-23:44:54.665572UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35319653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853593532829500 08/31/22-23:44:41.858327UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35359353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863234532026737 08/31/22-23:43:32.383826UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6323453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861846532829498 08/31/22-23:45:29.407811UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16184653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851686532829498 08/31/22-23:45:15.249386UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15168653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859721532026737 08/31/22-23:45:36.989137UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5972153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863989532026737 08/31/22-23:45:33.076660UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6398953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861232532829498 08/31/22-23:44:38.484716UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16123253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860787532026737 08/31/22-23:45:45.033484UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6078753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860012532026737 08/31/22-23:44:56.166001UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6001253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854099532026737 08/31/22-23:45:43.099769UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5409953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852558532829498 08/31/22-23:43:44.255164UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15255853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862851532026737 08/31/22-23:44:23.422050UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6285153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852718532829498 08/31/22-23:44:35.264599UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15271853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857690532829500 08/31/22-23:45:26.285005UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35769053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855638532026737 08/31/22-23:45:55.435640UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5563853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859225532026737 08/31/22-23:44:39.577699UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5922553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854298532829500 08/31/22-23:45:08.637369UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35429853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849505532829500 08/31/22-23:45:22.198497UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34950553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860132532829500 08/31/22-23:44:29.658619UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36013253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862441532829500 08/31/22-23:45:32.697893UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36244153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.853957532829498 08/31/22-23:45:45.835304UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15395753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852720532829498 08/31/22-23:44:35.302792UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15272053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863257532829498 08/31/22-23:45:10.094581UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16325753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859628532026737 08/31/22-23:45:09.167178UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5962853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.852392532829498 08/31/22-23:45:33.421298UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15239253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860756532829500 08/31/22-23:45:46.235846UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36075653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862542532829498 08/31/22-23:45:00.351749UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16254253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862734532026737 08/31/22-23:44:30.902951UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6273453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.860359532829500 08/31/22-23:45:11.147941UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36035953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861806532026737 08/31/22-23:45:26.618513UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6180653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856127532829498 08/31/22-23:44:10.627241UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15612753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.861849532829498 08/31/22-23:45:29.468833UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16184953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851533532026737 08/31/22-23:43:41.652498UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5153353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857791532829498 08/31/22-23:44:45.522004UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15779153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851594532829498 08/31/22-23:45:37.375783UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15159453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.851625532829500 08/31/22-23:45:44.209571UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35162553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862225532829500 08/31/22-23:44:36.774015UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36222553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850254532829500 08/31/22-23:44:58.744615UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35025453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859884532829498 08/31/22-23:43:58.574440UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15988453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856067532026737 08/31/22-23:45:29.097446UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5606753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863265532026737 08/31/22-23:44:37.342111UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6326553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862914532829498 08/31/22-23:43:29.867951UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16291453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857980532026737 08/31/22-23:45:53.013848UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5798053192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857189532829500 08/31/22-23:45:34.259006UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35718953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859793532026737 08/31/22-23:45:48.538109UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5979353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.858162532026737 08/31/22-23:44:44.497801UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5816253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856064532026737 08/31/22-23:45:29.037586UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5606453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859625532026737 08/31/22-23:45:09.112131UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5962553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856772532026737 08/31/22-23:45:34.590480UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5677253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857789532829498 08/31/22-23:44:45.480446UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15778953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857097532829500 08/31/22-23:45:35.724078UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35709753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859533532026737 08/31/22-23:45:40.011858UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5953353192.168.2.68.8.8.8
                                  192.168.2.68.8.8.864641532829500 08/31/22-23:45:18.781389UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36464153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.850971532829498 08/31/22-23:45:24.890116UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15097153192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854882532829498 08/31/22-23:45:07.166788UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15488253192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854506532829500 08/31/22-23:44:51.025085UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35450653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862634532829498 08/31/22-23:45:12.136668UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16263453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857058532829498 08/31/22-23:45:18.283248UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15705853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.859755532829500 08/31/22-23:44:14.146726UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35975553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.863268532026737 08/31/22-23:44:37.399636UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6326853192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856299532026737 08/31/22-23:44:46.401563UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5629953192.168.2.68.8.8.8
                                  192.168.2.68.8.8.857517532829500 08/31/22-23:44:26.339554UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35751753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855297532829500 08/31/22-23:45:37.673787UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35529753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.862737532026737 08/31/22-23:44:31.038440UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6273753192.168.2.68.8.8.8
                                  192.168.2.68.8.8.856436532026737 08/31/22-23:45:05.726984UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5643653192.168.2.68.8.8.8
                                  192.168.2.68.8.8.854314532829498 08/31/22-23:45:50.878483UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15431453192.168.2.68.8.8.8
                                  192.168.2.68.8.8.849235532026737 08/31/22-23:44:09.091938UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4923553192.168.2.68.8.8.8
                                  192.168.2.68.8.8.855960532829498 08/31/22-23:44:24.995544UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15596053192.168.2.68.8.8.8
                                  TimestampSource PortDest PortSource IPDest IP
                                  Aug 31, 2022 23:43:28.189418077 CEST6519853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:28.208646059 CEST53651988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:29.258124113 CEST6291053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:29.787338972 CEST53629108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:29.807944059 CEST6291153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:29.826931000 CEST53629118.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:29.827971935 CEST6291253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:29.845730066 CEST53629128.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:29.846371889 CEST6291353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:29.865859032 CEST53629138.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:29.867950916 CEST6291453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:29.887485027 CEST53629148.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:29.888154030 CEST6291553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:29.907727003 CEST53629158.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:31.034406900 CEST6386353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:31.062170982 CEST53638638.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:31.077511072 CEST6386453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:31.096620083 CEST53638648.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:31.097636938 CEST6386553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:31.118815899 CEST53638658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:31.119405985 CEST6386653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:31.139120102 CEST53638668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:31.143410921 CEST6386753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:31.163194895 CEST53638678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:31.170739889 CEST6386853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:31.188503981 CEST53638688.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:32.248059988 CEST6322953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:32.284269094 CEST53632298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:32.306555986 CEST6323053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:32.323657990 CEST53632308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:32.324505091 CEST6323153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:32.344270945 CEST53632318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:32.344832897 CEST6323253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:32.364722967 CEST53632328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:32.365334034 CEST6323353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:32.383225918 CEST53632338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:32.383826017 CEST6323453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:32.403651953 CEST53632348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:34.200436115 CEST6253853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:34.281522036 CEST53625388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:34.401488066 CEST6253953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:34.420568943 CEST53625398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:34.487617016 CEST6254053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:34.507476091 CEST53625408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:34.508060932 CEST6254153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:34.527868986 CEST53625418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:34.528575897 CEST6254253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:34.548209906 CEST53625428.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:34.588738918 CEST6254353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:34.608354092 CEST53625438.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:38.385130882 CEST5490353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:39.376049042 CEST5490353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:39.915618896 CEST53549038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:39.936307907 CEST5490453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:39.955585957 CEST53549048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:39.956403017 CEST5490553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:39.976094961 CEST53549058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:39.979641914 CEST5490653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:39.999306917 CEST53549068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:39.999758005 CEST5490753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:40.017430067 CEST53549078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:40.017874956 CEST5490853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:40.037492037 CEST53549088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:41.553627014 CEST5153053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:41.581630945 CEST53515308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:41.610330105 CEST5153153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:41.629317045 CEST53515318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:41.630050898 CEST5153253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:41.647600889 CEST53515328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:41.652498007 CEST5153353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:41.672156096 CEST53515338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:41.673206091 CEST5153453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:41.692521095 CEST53515348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:41.693075895 CEST5153553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:41.712446928 CEST53515358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:42.090478897 CEST53549038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:43.030864954 CEST5612253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.065428972 CEST5612253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.188271999 CEST53561228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:44.235419989 CEST5255753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.254477024 CEST53525578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:44.255163908 CEST5255853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.274674892 CEST53525588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:44.275226116 CEST5255953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.294872999 CEST53525598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:44.295388937 CEST5256053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.312819958 CEST53525608.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:44.313766956 CEST5256153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:44.331306934 CEST53525618.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:44.684417009 CEST53561228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:45.478450060 CEST6160953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.473700047 CEST6160953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.499958038 CEST53616098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:46.510267019 CEST53616098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:46.532617092 CEST6161053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.551563978 CEST53616108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:46.559519053 CEST6161153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.579423904 CEST53616118.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:46.582341909 CEST6161253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.602025032 CEST53616128.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:46.602571964 CEST6161353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.622019053 CEST53616138.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:46.625363111 CEST6161453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:46.644733906 CEST53616148.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:47.643717051 CEST5248153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:48.172422886 CEST53524818.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:48.262540102 CEST5248253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:48.281683922 CEST53524828.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:48.282565117 CEST5248353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:48.299957037 CEST53524838.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:48.300604105 CEST5248453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:48.318428040 CEST53524848.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:48.319051981 CEST5248553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:48.336926937 CEST53524858.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:48.342534065 CEST5248653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:48.362144947 CEST53524868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:49.251065969 CEST5394353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.267714977 CEST5394353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.869615078 CEST53539438.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:50.879436016 CEST53539438.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:50.891069889 CEST5394453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.908133030 CEST53539448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:50.908833027 CEST5394553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.926266909 CEST53539458.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:50.926738977 CEST5394653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.948179960 CEST53539468.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:50.950634003 CEST5394753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.969118118 CEST53539478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:50.969583988 CEST5394853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:50.989043951 CEST53539488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:51.967856884 CEST5608653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:51.996550083 CEST53560868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:52.034921885 CEST5608753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:52.054335117 CEST53560878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:52.054950953 CEST5608853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:52.074793100 CEST53560888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:52.075290918 CEST5608953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:52.092959881 CEST53560898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:52.093456984 CEST5609053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:52.113110065 CEST53560908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:52.113642931 CEST5609153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:52.131578922 CEST53560918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:55.712802887 CEST5654753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.705502987 CEST5654753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.771748066 CEST53565478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:56.792910099 CEST5654853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.812232018 CEST53565488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:56.812958956 CEST5654953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.832400084 CEST53565498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:56.837414026 CEST5655053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.856908083 CEST53565508.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:56.858808041 CEST5655153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.876498938 CEST53565518.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:56.877029896 CEST5655253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:56.897021055 CEST53565528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:57.493695974 CEST53565478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:58.408860922 CEST5988153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:58.437196016 CEST53598818.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:58.533785105 CEST5988253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:58.552953005 CEST53598828.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:58.553914070 CEST5988353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:58.573885918 CEST53598838.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:58.574440002 CEST5988453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:58.593951941 CEST53598848.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:58.594444036 CEST5988553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:58.613837957 CEST53598858.8.8.8192.168.2.6
                                  Aug 31, 2022 23:43:58.614289999 CEST5988653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:43:58.632070065 CEST53598868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:00.717885971 CEST5034353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:00.746181965 CEST53503438.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:00.844788074 CEST5034453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:00.862198114 CEST53503448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:00.864996910 CEST5034553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:00.885832071 CEST53503458.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:00.886555910 CEST5034653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:00.906203032 CEST53503468.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:00.906689882 CEST5034753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:00.926271915 CEST53503478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:00.930723906 CEST5034853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:00.950309992 CEST53503488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:02.461639881 CEST6252053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:02.498614073 CEST53625208.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:02.566622972 CEST6252153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:02.585666895 CEST53625218.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:02.586426973 CEST6252253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:02.606394053 CEST53625228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:02.606976986 CEST6252353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:02.626574039 CEST53625238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:02.627433062 CEST6252453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:02.647193909 CEST53625248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:02.647686005 CEST6252553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:02.667031050 CEST53625258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:04.089490891 CEST5562953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:04.712783098 CEST53556298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:04.744563103 CEST5657053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:04.763520956 CEST53565708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:04.765177965 CEST5657153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:04.784681082 CEST53565718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:04.785165071 CEST6183453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:04.804680109 CEST53618348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:04.805216074 CEST6183553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:04.822841883 CEST53618358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:04.825891972 CEST6183653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:04.843600988 CEST53618368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:06.382621050 CEST6504453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.378031969 CEST6504453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.404920101 CEST53650448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:07.470320940 CEST6504553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.489322901 CEST53650458.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:07.490247965 CEST6504653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.509794950 CEST53650468.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:07.510330915 CEST6504753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.529654026 CEST53650478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:07.531291008 CEST6504853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.550762892 CEST53650488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:07.555130005 CEST6504953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:07.574573040 CEST53650498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:07.958069086 CEST53650448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:08.953820944 CEST4923253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:09.030044079 CEST53492328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:09.053752899 CEST4923353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:09.070871115 CEST53492338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:09.071544886 CEST4923453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:09.089035034 CEST53492348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:09.091938019 CEST4923553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:09.112163067 CEST53492358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:09.112715960 CEST4923653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:09.132690907 CEST53492368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:09.133302927 CEST4923753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:09.151197910 CEST53492378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:10.494071960 CEST5612353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:10.521003008 CEST53561238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:10.565339088 CEST5612453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:10.584431887 CEST53561248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:10.587852001 CEST5612553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:10.605585098 CEST53561258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:10.607141018 CEST5612653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:10.625139952 CEST53561268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:10.627240896 CEST5612753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:10.645028114 CEST53561278.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:10.647183895 CEST5612853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:10.664766073 CEST53561288.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:13.952435970 CEST5975253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:14.085079908 CEST53597528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:14.108444929 CEST5975353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:14.127676010 CEST53597538.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:14.128267050 CEST5975453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:14.146212101 CEST53597548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:14.146725893 CEST5975553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:14.164454937 CEST53597558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:14.164882898 CEST5975653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:14.184348106 CEST53597568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:14.192617893 CEST5975753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:14.210242033 CEST53597578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:15.463445902 CEST5286553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:15.491667032 CEST53528658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:15.515043020 CEST5286653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:15.534033060 CEST53528668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:15.534929991 CEST5286753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:15.554707050 CEST53528678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:15.557965040 CEST5286853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:15.578181982 CEST53528688.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:15.578774929 CEST5286953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:15.598711014 CEST53528698.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:15.600002050 CEST5287053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:15.619543076 CEST53528708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:17.033523083 CEST6295853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:17.061666965 CEST53629588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:17.107180119 CEST6295953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:17.126076937 CEST53629598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:17.126998901 CEST6296053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:17.199198961 CEST53629608.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:17.199821949 CEST6296153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:17.219321012 CEST53629618.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:17.220031977 CEST6296253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:17.244647026 CEST53629628.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:17.245311022 CEST6296353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:17.262830019 CEST53629638.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:18.446585894 CEST6440453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:19.514300108 CEST6440453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.504131079 CEST6440453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.621330023 CEST53644048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:20.672352076 CEST53644048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:20.766475916 CEST6440553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.785567999 CEST53644058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:20.786154032 CEST6440653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.805774927 CEST53644068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:20.806284904 CEST6440753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.825907946 CEST53644078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:20.826579094 CEST6440853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.846116066 CEST53644088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:20.846616030 CEST6440953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:20.866101980 CEST53644098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:21.033593893 CEST53644048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:22.105437040 CEST6284853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.099241972 CEST6284853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.367536068 CEST53628488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:23.377346992 CEST6284953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.396424055 CEST53628498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:23.403881073 CEST6285053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.421693087 CEST53628508.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:23.422049999 CEST6285153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.439786911 CEST53628518.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:23.440318108 CEST6285253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.459907055 CEST53628528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:23.460622072 CEST6285353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:23.480061054 CEST53628538.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:23.853235960 CEST5595653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:24.138417959 CEST53628488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:24.848371029 CEST5595653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:24.916491032 CEST53559568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:24.935620070 CEST5595753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:24.954788923 CEST53559578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:24.955368042 CEST5595853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:24.966316938 CEST53559568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:24.972978115 CEST53559588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:24.973756075 CEST5595953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:24.993294001 CEST53559598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:24.995543957 CEST5596053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:25.013444901 CEST53559608.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:25.014723063 CEST5596153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:25.034226894 CEST53559618.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.281732082 CEST5751553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:26.310862064 CEST53575158.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.319732904 CEST5751653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:26.338895082 CEST53575168.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.339554071 CEST5751753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:26.359158993 CEST53575178.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.364052057 CEST5751853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:26.383789062 CEST53575188.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.384203911 CEST5751953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:26.401676893 CEST53575198.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.402095079 CEST5752053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:26.420916080 CEST53575208.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:26.826797962 CEST5132153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.353720903 CEST53513218.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.360004902 CEST5132253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.377182007 CEST53513228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.377732038 CEST5132353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.397227049 CEST53513238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.397682905 CEST5132453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.415566921 CEST53513248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.416197062 CEST5132553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.433887959 CEST53513258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.434988022 CEST5132653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.454647064 CEST53513268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.849769115 CEST6108953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.878129959 CEST53610898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.893129110 CEST6109053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.912081957 CEST53610908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.912765026 CEST6109153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.930186987 CEST53610918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.930612087 CEST6109253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.948191881 CEST53610928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.948801041 CEST6109353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.966533899 CEST53610938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:27.968897104 CEST6109453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:27.989063978 CEST53610948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:28.560740948 CEST6013053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.556891918 CEST6013053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.633094072 CEST53601308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:29.640669107 CEST6013153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.658077955 CEST53601318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:29.658618927 CEST6013253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.678369999 CEST53601328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:29.726897955 CEST6013353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.746664047 CEST53601338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:29.746959925 CEST6013453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.764878988 CEST53601348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:29.765193939 CEST6013553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:29.784965992 CEST53601358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:30.184921026 CEST53601308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:30.807333946 CEST6273253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:30.873771906 CEST53627328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:30.880889893 CEST6273353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:30.898199081 CEST53627338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:30.902951002 CEST6273453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:30.923027992 CEST53627348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:30.963319063 CEST6273553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:30.983294010 CEST53627358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:30.983637094 CEST6273653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:31.003328085 CEST53627368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:31.038439989 CEST6273753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:31.058240891 CEST53627378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:32.254594088 CEST6069053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:32.867783070 CEST53606908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:32.873814106 CEST6069153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:32.892914057 CEST53606918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:32.895962000 CEST6069253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:32.913737059 CEST53606928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:32.915750027 CEST6069353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:32.935492039 CEST53606938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:32.941273928 CEST6069453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:32.960941076 CEST53606948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:32.965262890 CEST6069553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:32.982760906 CEST53606958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.473517895 CEST5675053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:33.501940966 CEST53567508.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.516571045 CEST5675153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:33.535860062 CEST53567518.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.536411047 CEST5675253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:33.556155920 CEST53567528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.556718111 CEST5675353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:33.576621056 CEST53567538.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.577049971 CEST5675453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:33.596858978 CEST53567548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.597404003 CEST5675553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:33.617141962 CEST53567558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:33.999166965 CEST5933653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:34.576379061 CEST53593368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:34.582575083 CEST5933753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:34.601655960 CEST53593378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:34.602118969 CEST5933853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:34.621896982 CEST53593388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:34.622255087 CEST5933953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:34.641765118 CEST53593398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:34.642153025 CEST5934053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:34.662103891 CEST53593408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:34.662548065 CEST5934153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:34.682557106 CEST53593418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.045813084 CEST5271553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:35.214416027 CEST53527158.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.220551968 CEST5271653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:35.237657070 CEST53527168.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.238130093 CEST5271753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:35.257749081 CEST53527178.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.264599085 CEST5271853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:35.284265041 CEST53527188.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.284575939 CEST5271953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:35.302470922 CEST53527198.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.302792072 CEST5272053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:35.322506905 CEST53527208.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:35.671628952 CEST6222153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.677879095 CEST6222153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.706327915 CEST53622218.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:36.712397099 CEST6222253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.731586933 CEST53622228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:36.732223988 CEST6222353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.750371933 CEST53622238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:36.753658056 CEST6222453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.773665905 CEST53622248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:36.774014950 CEST6222553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.791744947 CEST53622258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:36.798471928 CEST6222653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:36.816457033 CEST53622268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:36.939074039 CEST53622218.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.285651922 CEST6326353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:37.313386917 CEST53632638.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.320348978 CEST6326453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:37.337385893 CEST53632648.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.342111111 CEST6326553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:37.361768007 CEST53632658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.362092972 CEST6326653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:37.381539106 CEST53632668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.381872892 CEST6326753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:37.399224997 CEST53632678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.399636030 CEST6326853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:37.419363976 CEST53632688.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:37.907648087 CEST5999853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.436364889 CEST53599988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.446387053 CEST6123053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.465503931 CEST53612308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.465975046 CEST6123153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.484422922 CEST53612318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.484715939 CEST6123253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.502108097 CEST53612328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.502414942 CEST6123353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.521826982 CEST53612338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.522131920 CEST6123453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.539650917 CEST53612348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.911334991 CEST5177253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.938251019 CEST53517728.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.952085018 CEST5177353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.969208002 CEST53517738.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.969748974 CEST5177453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:38.987540007 CEST53517748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:38.988154888 CEST5177553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.007621050 CEST53517758.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.007949114 CEST5177653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.027304888 CEST53517768.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.027584076 CEST5177753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.047132015 CEST53517778.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.449382067 CEST5922253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.475492001 CEST53592228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.537282944 CEST5922353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.556307077 CEST53592238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.557926893 CEST5922453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.577370882 CEST53592248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.577698946 CEST5922553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.597099066 CEST53592258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.597796917 CEST5922653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.615369081 CEST53592268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:39.617894888 CEST5922753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:39.635468960 CEST53592278.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:40.011394024 CEST5281653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.008980036 CEST5281653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.036927938 CEST53528168.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.046010017 CEST5775553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.062947989 CEST53577558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.063436985 CEST5775653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.082788944 CEST53577568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.083128929 CEST5775753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.102920055 CEST53577578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.103311062 CEST5775853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.121021986 CEST53577588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.121342897 CEST5775953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.141063929 CEST53577598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.169985056 CEST53528168.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.694123030 CEST5359053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.811177969 CEST53535908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.820821047 CEST5359153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.837889910 CEST53535918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.838524103 CEST5359253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.857992887 CEST53535928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.858326912 CEST5359353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.877934933 CEST53535938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.878318071 CEST5359453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.898178101 CEST53535948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:41.898667097 CEST5359553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:41.918279886 CEST53535958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.354094982 CEST5635853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:42.382412910 CEST53563588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.390948057 CEST5635953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:42.410130024 CEST53563598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.410727024 CEST5636053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:42.430150986 CEST53563608.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.430521965 CEST5636153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:42.450306892 CEST53563618.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.450740099 CEST5636253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:42.470879078 CEST53563628.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.471271992 CEST5636353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:42.491142035 CEST53563638.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:42.883522987 CEST4933253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.413260937 CEST53493328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.423599005 CEST4933353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.442663908 CEST53493338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.443293095 CEST4933453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.460849047 CEST53493348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.471731901 CEST4933553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.491415024 CEST53493358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.492294073 CEST4933653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.511894941 CEST53493368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.512238026 CEST4933753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.531490088 CEST53493378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.926251888 CEST5996553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.961663008 CEST53599658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.974957943 CEST5996653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:43.991935968 CEST53599668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:43.992635012 CEST5996753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.009932995 CEST53599678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.010315895 CEST5996853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.030059099 CEST53599688.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.030719995 CEST5996953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.048516035 CEST53599698.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.048963070 CEST5997053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.068895102 CEST53599708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.382122040 CEST5815753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.411514997 CEST53581578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.418190002 CEST5815853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.437238932 CEST53581588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.437834978 CEST5815953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.457220078 CEST53581598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.457603931 CEST5816053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.475223064 CEST53581608.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.475598097 CEST5816153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.493381023 CEST53581618.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.497801065 CEST5816253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:44.517654896 CEST53581628.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:44.906749010 CEST5778653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.435556889 CEST53577868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.442172050 CEST5778753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.460696936 CEST53577878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.461186886 CEST5778853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.478576899 CEST53577888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.480446100 CEST5778953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.500251055 CEST53577898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.500682116 CEST5779053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.520853996 CEST53577908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.522003889 CEST5779153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.539642096 CEST53577918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.854546070 CEST6496153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.881977081 CEST53649618.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.887908936 CEST6496253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.907064915 CEST53649628.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.907608986 CEST6496353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.927283049 CEST53649638.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.929172039 CEST6496453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.948478937 CEST53649648.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.948751926 CEST6496553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.968255043 CEST53649658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:45.968565941 CEST6496653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:45.988017082 CEST53649668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.311108112 CEST5629553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:46.337909937 CEST53562958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.344320059 CEST5629653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:46.363435984 CEST53562968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.363903046 CEST5629753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:46.383466005 CEST53562978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.383892059 CEST5629853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:46.401216030 CEST53562988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.401562929 CEST5629953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:46.421830893 CEST53562998.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.422476053 CEST5630053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:46.442011118 CEST53563008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:46.748087883 CEST6464753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:47.783533096 CEST6464753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.821460009 CEST53646478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:48.823721886 CEST6464753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.830035925 CEST6464853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.847312927 CEST53646488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:48.847826004 CEST6464953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.867320061 CEST53646498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:48.868077993 CEST6465053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.885781050 CEST53646508.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:48.910540104 CEST53646478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:48.937933922 CEST6465153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.957782030 CEST53646518.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:48.958101034 CEST6465253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:48.977746010 CEST53646528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:49.891845942 CEST53646478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:50.444237947 CEST5450353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:50.972193956 CEST53545038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:50.985032082 CEST5450453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.004219055 CEST53545048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.004868984 CEST5450553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.024416924 CEST53545058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.025084972 CEST5450653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.044862986 CEST53545068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.051028013 CEST5450753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.070853949 CEST53545078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.075094938 CEST5450853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.093216896 CEST53545088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.553877115 CEST5188753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.589247942 CEST53518878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.600792885 CEST5188853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.620028019 CEST53518888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.620570898 CEST5188953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.640378952 CEST53518898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.640850067 CEST5189053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.660531044 CEST53518908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.663810968 CEST5189153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.683698893 CEST53518918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:51.684138060 CEST5189253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:51.703880072 CEST53518928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:52.075218916 CEST5304153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.086749077 CEST5304153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.151417971 CEST53530418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:53.159248114 CEST5450953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.176506996 CEST53545098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:53.176959038 CEST5451053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.194789886 CEST53545108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:53.195101976 CEST5451153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.215109110 CEST53545118.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:53.215473890 CEST5451253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.235271931 CEST53545128.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:53.235785961 CEST5451353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.255618095 CEST53545138.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:53.561455011 CEST5319353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:53.625669956 CEST53530418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.554263115 CEST5319353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:54.619091034 CEST53531938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.627124071 CEST5319453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:54.646353960 CEST53531948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.646933079 CEST5319553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:54.664908886 CEST53531958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.665571928 CEST5319653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:54.685338974 CEST53531968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.685782909 CEST5319753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:54.703402996 CEST53531978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.703855038 CEST5319853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:54.721267939 CEST53531988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:54.741657972 CEST53531938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:55.064367056 CEST6000853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.075655937 CEST6000853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.097080946 CEST53600088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:56.104077101 CEST6000953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.124034882 CEST53600098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:56.124572992 CEST6001053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.144139051 CEST53600108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:56.144536972 CEST6001153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.165666103 CEST53600118.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:56.166001081 CEST6001253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.185373068 CEST53600128.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:56.185703039 CEST6001353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:56.206304073 CEST53600138.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:56.519510984 CEST5420053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.057044029 CEST53542008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:57.065381050 CEST5420153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.084417105 CEST53542018.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:57.085031986 CEST5420253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.104636908 CEST53542028.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:57.105081081 CEST5420353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.124588966 CEST53542038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:57.124924898 CEST5420453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.144799948 CEST53542048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:57.145411015 CEST5420553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.165554047 CEST53542058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:57.468453884 CEST5025253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:57.657109976 CEST53600088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.460675001 CEST5025253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:58.709364891 CEST53502528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.724746943 CEST5025353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:58.744060993 CEST53502538.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.744615078 CEST5025453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:58.762052059 CEST53502548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.762397051 CEST5025553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:58.775975943 CEST53502528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.781868935 CEST53502558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.782279968 CEST5025653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:58.802098036 CEST53502568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:58.802648067 CEST5025753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:58.822364092 CEST53502578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.148394108 CEST6479653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:59.175309896 CEST53647968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.188793898 CEST6479753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:59.208067894 CEST53647978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.208493948 CEST6479853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:59.228351116 CEST53647988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.228975058 CEST6479953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:59.248884916 CEST53647998.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.249275923 CEST6480053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:59.268644094 CEST53648008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.269047976 CEST6480153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:44:59.286719084 CEST53648018.8.8.8192.168.2.6
                                  Aug 31, 2022 23:44:59.632479906 CEST6253753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:00.215579033 CEST53625378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:00.236723900 CEST6253853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:00.255872011 CEST53625388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:00.266316891 CEST6253953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:00.286022902 CEST53625398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:00.304908037 CEST6254053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:00.325176001 CEST53625408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:00.327888966 CEST6254153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:00.348517895 CEST53625418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:00.351748943 CEST6254253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:00.371310949 CEST53625428.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.047051907 CEST6203653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:01.091835022 CEST53620368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.100621939 CEST6203753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:01.120204926 CEST53620378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.120774984 CEST6203853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:01.138207912 CEST53620388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.138669968 CEST6203953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:01.158245087 CEST53620398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.158698082 CEST6204053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:01.178411007 CEST53620408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.185034037 CEST6204153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:01.204669952 CEST53620418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:01.537235975 CEST6367053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.539155960 CEST6367053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.615139008 CEST53636708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:02.621450901 CEST6367153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.640677929 CEST53636718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:02.641321898 CEST6367253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.661689997 CEST53636728.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:02.662218094 CEST6367353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.681889057 CEST53636738.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:02.682245016 CEST6367453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.703619003 CEST53636748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:02.703985929 CEST6367553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:02.723409891 CEST53636758.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.045041084 CEST6117053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:03.106302977 CEST53636708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.158047915 CEST53611708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.167327881 CEST6117153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:03.184478045 CEST53611718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.186618090 CEST6117253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:03.206196070 CEST53611728.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.206528902 CEST6117353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:03.228708982 CEST53611738.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.230027914 CEST6117453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:03.248331070 CEST53611748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.248644114 CEST6117553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:03.268287897 CEST53611758.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:03.595216990 CEST5642753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:04.125479937 CEST53564278.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:04.131422997 CEST5642853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:04.150804043 CEST53564288.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:04.151432037 CEST5642953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:04.172810078 CEST53564298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:04.173628092 CEST5643053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:04.193243027 CEST53564308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:04.193694115 CEST5643153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:04.211317062 CEST53564318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:04.211842060 CEST5643253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:04.231714964 CEST53564328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:04.562575102 CEST5643153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.570563078 CEST5643153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.642608881 CEST53564318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:05.649463892 CEST5643253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.668690920 CEST53564328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:05.669169903 CEST5643353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.679235935 CEST53564318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:05.688968897 CEST53564338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:05.689286947 CEST5643453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.708745956 CEST53564348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:05.709060907 CEST5643553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.726625919 CEST53564358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:05.726984024 CEST5643653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:05.746467113 CEST53564368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:06.085989952 CEST4946553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.102210999 CEST4946553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.123591900 CEST53494658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:07.130872011 CEST5488053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.147948027 CEST53548808.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:07.148627996 CEST5488153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.166426897 CEST53548818.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:07.166788101 CEST5488253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.184499979 CEST53548828.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:07.190819025 CEST5488353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.210597992 CEST53548838.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:07.210988045 CEST5488453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.230631113 CEST53548848.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:07.536108971 CEST5429653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:07.638503075 CEST53494658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.542176008 CEST5429653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:08.604301929 CEST53542968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.609941006 CEST53542968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.617167950 CEST5429753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:08.636708975 CEST53542978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.637368917 CEST5429853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:08.657493114 CEST53542988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.657968044 CEST5429953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:08.678095102 CEST53542998.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.678590059 CEST5430053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:08.699327946 CEST53543008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:08.700151920 CEST5430153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:08.720056057 CEST53543018.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.050138950 CEST5962353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:09.086039066 CEST53596238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.094361067 CEST5962453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:09.111648083 CEST53596248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.112131119 CEST5962553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:09.129959106 CEST53596258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.130816936 CEST5962653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:09.148557901 CEST53596268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.148936987 CEST5962753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:09.166651011 CEST53596278.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.167177916 CEST5962853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:09.184634924 CEST53596288.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:09.521197081 CEST6325453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:10.048824072 CEST53632548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:10.054795027 CEST6325553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:10.074271917 CEST53632558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:10.074723005 CEST6325653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:10.094129086 CEST53632568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:10.094580889 CEST6325753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:10.114101887 CEST53632578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:10.114399910 CEST6325853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:10.134094954 CEST53632588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:10.134382963 CEST6325953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:10.153976917 CEST53632598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:10.448133945 CEST6035453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.069394112 CEST53603548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.075881004 CEST6035553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.093446970 CEST53603558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.093877077 CEST6035653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.111608028 CEST53603568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.111963034 CEST6035753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.129561901 CEST53603578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.129894018 CEST6035853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.147553921 CEST53603588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.147941113 CEST6035953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.167288065 CEST53603598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.464940071 CEST5272553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.493338108 CEST53527258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.501610994 CEST5272653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.518835068 CEST53527268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.519431114 CEST5272753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.537653923 CEST53527278.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.538182020 CEST5272853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.555847883 CEST53527288.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.556204081 CEST5272953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.575905085 CEST53527298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:11.576226950 CEST5273053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:11.596256971 CEST53527308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.058248043 CEST6263153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:12.086657047 CEST53626318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.096239090 CEST6263253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:12.115483999 CEST53626328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.116146088 CEST6263353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:12.133847952 CEST53626338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.136667967 CEST6263453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:12.156578064 CEST53626348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.157481909 CEST6263553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:12.177124977 CEST53626358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.181438923 CEST6263653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:12.199208975 CEST53626368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:12.617562056 CEST5211853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.603507042 CEST5211853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.795871973 CEST53521188.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:13.803756952 CEST5211953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.822742939 CEST53521198.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:13.823400974 CEST5212053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.843261957 CEST53521208.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:13.843635082 CEST5212153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.863305092 CEST53521218.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:13.864005089 CEST5212253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.881822109 CEST53521228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:13.882213116 CEST5212353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:13.899844885 CEST53521238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.276071072 CEST53521188.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.292866945 CEST5475253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:14.455116987 CEST53547528.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.460872889 CEST5475353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:14.478157043 CEST53547538.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.478678942 CEST5475453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:14.498713970 CEST53547548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.500005007 CEST5475553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:14.520136118 CEST53547558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.520580053 CEST5475653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:14.540436983 CEST53547568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:14.540780067 CEST5475753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:14.560705900 CEST53547578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.136995077 CEST5168453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:15.212640047 CEST53516848.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.226294041 CEST5168553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:15.245517015 CEST53516858.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.249386072 CEST5168653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:15.268943071 CEST53516868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.269351959 CEST5168753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:15.289814949 CEST53516878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.290256023 CEST5168853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:15.309674978 CEST53516888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.310184002 CEST5168953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:15.330753088 CEST53516898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:15.733643055 CEST6294453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.727732897 CEST6294453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.762197018 CEST53629448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:16.773322105 CEST6294553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.790291071 CEST53629458.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:16.791073084 CEST6294653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.810615063 CEST53629468.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:16.811045885 CEST6294753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.830655098 CEST53629478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:16.831037998 CEST6294853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.848545074 CEST53629488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:16.848920107 CEST6294953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:16.868464947 CEST53629498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:17.195213079 CEST5432953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:17.734127045 CEST53543298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:17.740503073 CEST5433053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:17.759524107 CEST53543308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:17.760023117 CEST5433153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:17.779627085 CEST53543318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:17.784188986 CEST5433253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:17.803694963 CEST53543328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:17.804037094 CEST5433353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:17.821728945 CEST53543338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:17.822079897 CEST5433453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:17.841531038 CEST53543348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.176704884 CEST5705453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.213179111 CEST53570548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.228538990 CEST5705553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.245822906 CEST53570558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.246350050 CEST5705653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.264169931 CEST53570568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.264694929 CEST5705753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.282655001 CEST53570578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.283247948 CEST5705853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.303041935 CEST53570588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.303570986 CEST5705953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.323292971 CEST53570598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.617186069 CEST6463853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.727078915 CEST53646388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.739464045 CEST6463953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.758493900 CEST53646398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.759263992 CEST6464053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.779901028 CEST53646408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.781388998 CEST6464153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.801358938 CEST53646418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.801786900 CEST6464253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.821578026 CEST53646428.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:18.822079897 CEST6464353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:18.839883089 CEST53646438.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.141751051 CEST6016753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:19.169836044 CEST53601678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.178591967 CEST6016853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:19.197752953 CEST53601688.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.198458910 CEST6016953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:19.218126059 CEST53601698.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.218542099 CEST6017053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:19.237973928 CEST53601708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.238394976 CEST6017153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:19.258479118 CEST53601718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.258879900 CEST6017253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:19.278409958 CEST53601728.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:19.579224110 CEST5304653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.108885050 CEST53530468.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:20.116256952 CEST5304753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.133389950 CEST53530478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:20.133744955 CEST5304853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.151463985 CEST53530488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:20.151835918 CEST5304953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.171344042 CEST53530498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:20.171719074 CEST5305053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.191129923 CEST53530508.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:20.191617966 CEST5305153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.211190939 CEST53530518.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:20.554970026 CEST4950353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:20.750307083 CEST53629448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:21.924539089 CEST4950353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:22.173013926 CEST53495038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:22.180754900 CEST4950453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:22.197968006 CEST53495048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:22.198497057 CEST4950553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:22.217995882 CEST53495058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:22.251710892 CEST4950653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:22.271331072 CEST53495068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:22.271616936 CEST4950753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:22.290329933 CEST53495078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:22.293889046 CEST4950853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:22.313796043 CEST53495088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:23.552133083 CEST53495038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:23.801573038 CEST5053553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.331062078 CEST53505358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.337188959 CEST5053653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.354151011 CEST53505368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.354748011 CEST5053753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.374262094 CEST53505378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.374819994 CEST5053853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.394306898 CEST53505388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.397103071 CEST5053953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.416450024 CEST53505398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.416775942 CEST5054053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.435049057 CEST53505408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.724124908 CEST5096653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.800530910 CEST53509668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.807276964 CEST5096753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.826673985 CEST53509678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.827188969 CEST5096853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.844790936 CEST53509688.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.845854998 CEST5096953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.866312027 CEST53509698.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.869816065 CEST5097053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.889637947 CEST53509708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:24.890115976 CEST5097153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:24.909706116 CEST53509718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:25.236032009 CEST5768853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.229635000 CEST5768853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.257894039 CEST53576888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.267116070 CEST53576888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.267462015 CEST5768953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.284495115 CEST53576898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.285005093 CEST5769053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.302685022 CEST53576908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.303054094 CEST5769153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.322731018 CEST53576918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.323010921 CEST5769253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.342674017 CEST53576928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.343034029 CEST5769353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.362843990 CEST53576938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.532789946 CEST6180353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.570079088 CEST53618038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.580955029 CEST6180453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.598028898 CEST53618048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.598524094 CEST6180553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.618112087 CEST53618058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.618513107 CEST6180653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.638072968 CEST53618068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.638406038 CEST6180753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.657855034 CEST53618078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.658196926 CEST6180853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:26.677685976 CEST53618088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:26.844290018 CEST5326953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.838044882 CEST5326953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.864686966 CEST53532698.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:27.871409893 CEST5327053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.888834953 CEST53532708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:27.889216900 CEST5327153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.909015894 CEST53532718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:27.910057068 CEST5327253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.929562092 CEST53532728.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:27.934014082 CEST5327353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.953717947 CEST53532738.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:27.954080105 CEST5327453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:27.971896887 CEST53532748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.130558968 CEST5448853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:28.669117928 CEST53544888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.680681944 CEST5448953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:28.697978020 CEST53544898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.698486090 CEST5449053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:28.716156006 CEST53544908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.716622114 CEST5449153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:28.735982895 CEST53544918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.736488104 CEST5449253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:28.756066084 CEST53544928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.756602049 CEST5449353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:28.776252031 CEST53544938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:28.935791016 CEST5606253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.011524916 CEST53560628.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.017611980 CEST5606353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.037141085 CEST53560638.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.037585974 CEST5606453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.057269096 CEST53560648.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.057624102 CEST5606553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.077163935 CEST53560658.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.077449083 CEST5606653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.097136974 CEST53560668.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.097445965 CEST5606753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.117222071 CEST53560678.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.270234108 CEST6184453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.381879091 CEST53618448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.387746096 CEST6184553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.407457113 CEST53618458.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.407810926 CEST6184653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.427575111 CEST53618468.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.427866936 CEST6184753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.447861910 CEST53618478.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.448149920 CEST6184853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.468513966 CEST53618488.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.468832970 CEST6184953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.488358974 CEST53618498.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.606527090 CEST53532698.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.649353981 CEST5933553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.678388119 CEST53593358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.684885025 CEST5933653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.704013109 CEST53593368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.704402924 CEST5933753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.723932981 CEST53593378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.724261999 CEST5933853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.745117903 CEST53593388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.745492935 CEST5933953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.765243053 CEST53593398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.765614033 CEST5934053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.785756111 CEST53593408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.950278044 CEST6343353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:29.978842020 CEST53634338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:29.985933065 CEST6343453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:30.005171061 CEST53634348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:30.010283947 CEST6343553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:30.029825926 CEST53634358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:30.030648947 CEST6343653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:30.050517082 CEST53634368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:30.050806046 CEST6343753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:30.070476055 CEST53634378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:30.070764065 CEST6343853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:30.090724945 CEST53634388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:30.252954006 CEST6492953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.244724035 CEST6492953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.870630980 CEST53649298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:31.870671988 CEST53649298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:31.877437115 CEST6493053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.894535065 CEST53649308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:31.895020962 CEST6493153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.914591074 CEST53649318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:31.915004015 CEST6493253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.932943106 CEST53649328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:31.933352947 CEST6493353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.953244925 CEST53649338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:31.953591108 CEST6493453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:31.973292112 CEST53649348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.136538029 CEST6243953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:32.671992064 CEST53624398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.678122044 CEST6244053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:32.697273970 CEST53624408.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.697892904 CEST6244153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:32.717818022 CEST53624418.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.718406916 CEST6244253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:32.738121986 CEST53624428.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.738675117 CEST6244353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:32.758621931 CEST53624438.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.758992910 CEST6244453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:32.776418924 CEST53624448.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:32.933954954 CEST6398553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.008081913 CEST53639858.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.016643047 CEST6398653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.033670902 CEST53639868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.034612894 CEST6398753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.052232027 CEST53639878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.054661989 CEST6398853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.074173927 CEST53639888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.076659918 CEST6398953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.096429110 CEST53639898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.098684072 CEST6399053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.116456032 CEST53639908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.277739048 CEST5239053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.391014099 CEST53523908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.401248932 CEST5239153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.420255899 CEST53523918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.421298027 CEST5239253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.440869093 CEST53523928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.441343069 CEST5239353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.461447954 CEST53523938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.462719917 CEST5239453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.482673883 CEST53523948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.483016968 CEST5239553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:33.502680063 CEST53523958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:33.675072908 CEST5718653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.205842018 CEST53571868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.218529940 CEST5718753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.237862110 CEST53571878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.238634109 CEST5718853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.258346081 CEST53571888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.259006023 CEST5718953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.276730061 CEST53571898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.277427912 CEST5719053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.297285080 CEST53571908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.298140049 CEST5719153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.317642927 CEST53571918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.490065098 CEST5677053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.563857079 CEST53567708.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.570928097 CEST5677153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.590023994 CEST53567718.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.590480089 CEST5677253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.608253002 CEST53567728.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.608669996 CEST5677353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.632611990 CEST53567738.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.633209944 CEST5677453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.650960922 CEST53567748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.651619911 CEST5677553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.671530008 CEST53567758.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.833235979 CEST5690353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.861598015 CEST53569038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.870647907 CEST5690453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.889672041 CEST53569048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.890654087 CEST5690553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.910166979 CEST53569058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.910660028 CEST5690653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.930305958 CEST53569068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.930943966 CEST5690753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.948801041 CEST53569078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:34.949399948 CEST5690853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:34.966978073 CEST53569088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.123905897 CEST5709353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:35.659677029 CEST53570938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.667711973 CEST5709453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:35.684854031 CEST53570948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.685539007 CEST5709553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:35.703336000 CEST53570958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.703871012 CEST5709653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:35.723376036 CEST53570968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.724077940 CEST5709753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:35.741929054 CEST53570978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.742268085 CEST5709853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:35.761758089 CEST53570988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:35.936270952 CEST5971953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:36.933383942 CEST5971953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:36.962335110 CEST53597198.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:36.971575022 CEST5972053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:36.988629103 CEST53597208.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:36.989136934 CEST5972153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.008464098 CEST53597218.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.008989096 CEST5972253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.028367996 CEST53597228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.029062986 CEST5972353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.046492100 CEST53597238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.047108889 CEST5972453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.068111897 CEST53597248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.239649057 CEST5159153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.328402042 CEST53515918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.335338116 CEST5159253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.354845047 CEST53515928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.355426073 CEST5159353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.375205994 CEST53515938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.375782967 CEST5159453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.395513058 CEST53515948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.395998955 CEST5159553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.415610075 CEST53515958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.416090012 CEST5159653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.435617924 CEST53515968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.596064091 CEST5529553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.646131992 CEST53552958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.655630112 CEST5529653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.672806025 CEST53552968.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.673787117 CEST5529753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.693382025 CEST53552978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.693886042 CEST5529853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.713413000 CEST53552988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.714101076 CEST5529953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.733810902 CEST53552998.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.734664917 CEST5530053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:37.752490044 CEST53553008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:37.905271053 CEST5952953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:38.917013884 CEST5952953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:39.287280083 CEST53597198.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:39.917289019 CEST5952953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:39.946167946 CEST53595298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:39.954221964 CEST5953053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:39.973323107 CEST53595308.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:39.973829031 CEST5953153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:39.991565943 CEST53595318.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:39.991955042 CEST5953253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.011499882 CEST53595328.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.011857986 CEST5953353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.029787064 CEST53595338.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.030174971 CEST5953453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.050113916 CEST53595348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.095642090 CEST53595298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.110693932 CEST53595298.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.202665091 CEST6077453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.811549902 CEST53607748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.819202900 CEST6077553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.838596106 CEST53607758.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.839432955 CEST6077653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.857355118 CEST53607768.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.857769012 CEST6077753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.877202034 CEST53607778.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.877619982 CEST6077853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.897402048 CEST53607788.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:40.897866011 CEST6077953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:40.919195890 CEST53607798.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:41.100511074 CEST5080653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.090756893 CEST5080653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.722179890 CEST53508068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:42.733959913 CEST5080753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.751497984 CEST53508078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:42.752242088 CEST5080853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.772325993 CEST53508088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:42.775516033 CEST5080953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.795279980 CEST53508098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:42.795799971 CEST5081053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.813390017 CEST53508108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:42.813838959 CEST5081153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:42.831677914 CEST53508118.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.005398989 CEST5409753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.071841955 CEST53540978.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.079855919 CEST5409853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.099137068 CEST53540988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.099769115 CEST5409953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.119312048 CEST53540998.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.119823933 CEST5410053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.137548923 CEST53541008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.138087988 CEST5410153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.157763004 CEST53541018.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.158257008 CEST5410253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.177860975 CEST53541028.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.341131926 CEST6157353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.868730068 CEST53615738.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.876570940 CEST6157453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.895756960 CEST53615748.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.896303892 CEST6157553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.915795088 CEST53615758.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.916182995 CEST6157653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.933940887 CEST53615768.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.934540033 CEST6157753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.954459906 CEST53615778.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:43.955051899 CEST6157853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:43.972961903 CEST53615788.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.135931969 CEST5162253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.162213087 CEST53516228.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.172229052 CEST5162353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.189434052 CEST53516238.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.191432953 CEST5162453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.209141016 CEST53516248.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.209570885 CEST5162553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.229032993 CEST53516258.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.232922077 CEST5162653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.252708912 CEST53516268.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.253365040 CEST5162753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.273025990 CEST53516278.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.436881065 CEST6078453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:44.985682964 CEST53607848.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:44.993525982 CEST6078553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.010627031 CEST53607858.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.011229992 CEST6078653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.030633926 CEST53607868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.033483982 CEST6078753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.052932024 CEST53607878.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.053318977 CEST6078853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.071058035 CEST53607888.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.071628094 CEST6078953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.091566086 CEST53607898.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.253845930 CEST5395453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.790606022 CEST53539548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.799216986 CEST5395553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.816375017 CEST53539558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.816936970 CEST5395653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.834777117 CEST53539568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.835304022 CEST5395753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.852967024 CEST53539578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.853434086 CEST5395853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.873301029 CEST53539588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:45.873965979 CEST5395953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:45.891820908 CEST53539598.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.065907955 CEST6075353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:46.191735983 CEST53607538.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.199429035 CEST6075453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:46.216659069 CEST53607548.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.217401028 CEST6075553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:46.235269070 CEST53607558.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.235846043 CEST6075653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:46.253509998 CEST53607568.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.254203081 CEST6075753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:46.271697998 CEST53607578.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.272226095 CEST6075853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:46.291834116 CEST53607588.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:46.460216999 CEST5979053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:47.109087944 CEST53508068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:47.458210945 CEST5979053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.461271048 CEST5979053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.489577055 CEST53597908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.497889042 CEST5979153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.517317057 CEST53597918.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.517877102 CEST5979253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.537610054 CEST53597928.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.538109064 CEST5979353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.544222116 CEST53597908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.557970047 CEST53597938.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.558568954 CEST5979453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.578443050 CEST53597948.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.583139896 CEST5979553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:48.602873087 CEST53597958.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:48.776711941 CEST5431053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:49.040975094 CEST53597908.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:49.768608093 CEST5431053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.784080982 CEST5431053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.809185982 CEST53543108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:50.816631079 CEST5431153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.836035967 CEST53543118.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:50.836877108 CEST5431253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.856573105 CEST53543128.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:50.857497931 CEST5431353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.878010035 CEST53543138.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:50.878483057 CEST5431453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.898149967 CEST53543148.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:50.898634911 CEST5431553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:50.916162014 CEST53543158.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.079763889 CEST5650453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:51.168813944 CEST53543108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.647681952 CEST53565048.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.655795097 CEST5650553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:51.672899008 CEST53565058.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.673641920 CEST5650653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:51.691550970 CEST53565068.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.692352057 CEST5650753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:51.711776018 CEST53565078.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.716327906 CEST5650853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:51.736037970 CEST53565088.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.736466885 CEST5650953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:51.756360054 CEST53565098.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:51.931433916 CEST5797753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:52.403012991 CEST53543108.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:52.940356970 CEST5797753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:52.968674898 CEST53579778.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:52.975866079 CEST5797853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:52.995096922 CEST53579788.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:52.995554924 CEST5797953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.013417959 CEST53579798.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.013848066 CEST5798053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.031677008 CEST53579808.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.032064915 CEST5798153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.051702976 CEST53579818.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.052190065 CEST5798253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.073030949 CEST53579828.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.227962971 CEST6349853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.510509014 CEST53579778.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.758115053 CEST53634988.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.764256954 CEST6349953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.783446074 CEST53634998.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.787672043 CEST6350053192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.807456970 CEST53635008.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.807893038 CEST6350153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.825607061 CEST53635018.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.826060057 CEST6350253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.846086025 CEST53635028.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:53.846708059 CEST6350353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:53.866564035 CEST53635038.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.023427963 CEST6038153192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:54.049860954 CEST53603818.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.055927992 CEST6038253192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:54.073111057 CEST53603828.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.073595047 CEST6038353192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:54.093367100 CEST53603838.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.095084906 CEST6038453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:54.114746094 CEST53603848.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.115288973 CEST6038553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:54.135003090 CEST53603858.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.135454893 CEST6038653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:54.154999018 CEST53603868.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:54.320693016 CEST5563453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.331852913 CEST5563453192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.368313074 CEST53556348.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:55.379616976 CEST5563553192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.398617029 CEST53556358.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:55.399161100 CEST5563653192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.417046070 CEST53556368.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:55.417422056 CEST5563753192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.435185909 CEST53556378.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:55.435640097 CEST5563853192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.456170082 CEST53556388.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:55.456579924 CEST5563953192.168.2.68.8.8.8
                                  Aug 31, 2022 23:45:55.476073980 CEST53556398.8.8.8192.168.2.6
                                  Aug 31, 2022 23:45:55.889926910 CEST53556348.8.8.8192.168.2.6
                                  TimestampSource IPDest IPChecksumCodeType
                                  Aug 31, 2022 23:43:42.090585947 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:43:44.684494972 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:43:46.512868881 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:43:50.879545927 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:43:57.495480061 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:07.958151102 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:20.672470093 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:24.138535023 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:30.185129881 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:36.939229965 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:41.170113087 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:48.910731077 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:49.892015934 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:53.625788927 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:54.741772890 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:57.657238007 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:44:58.776050091 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:03.106554985 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:05.679322004 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:07.638600111 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:14.276295900 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:20.750515938 CEST192.168.2.68.8.8.8cff6(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:23.552331924 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:26.267215014 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:29.606621981 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:39.290972948 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:40.110896111 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:47.109262943 CEST192.168.2.68.8.8.8cff6(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:48.544336081 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:51.169941902 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:52.403152943 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:53.510659933 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  Aug 31, 2022 23:45:55.890140057 CEST192.168.2.68.8.8.8d033(Port unreachable)Destination Unreachable
                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                  Aug 31, 2022 23:43:28.189418077 CEST192.168.2.68.8.8.80xa574Standard query (0)ipv4bot.whatismyipaddress.comA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.258124113 CEST192.168.2.68.8.8.80x157aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.807944059 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:29.827971935 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.846371889 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:29.867950916 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.888154030 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:31.034406900 CEST192.168.2.68.8.8.80xe7f5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:31.077511072 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:31.097636938 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:31.119405985 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:31.143410921 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:31.170739889 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:32.248059988 CEST192.168.2.68.8.8.80xb58eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:32.306555986 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:32.324505091 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:32.344832897 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:32.365334034 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:32.383826017 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:34.200436115 CEST192.168.2.68.8.8.80x5447Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:34.401488066 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:34.487617016 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:34.508060932 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:34.528575897 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:34.588738918 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:38.385130882 CEST192.168.2.68.8.8.80xd552Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:39.376049042 CEST192.168.2.68.8.8.80xd552Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:39.936307907 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:39.956403017 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:39.979641914 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:39.999758005 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:40.017874956 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:41.553627014 CEST192.168.2.68.8.8.80xd289Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:41.610330105 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:41.630050898 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:41.652498007 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:41.673206091 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:41.693075895 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:43.030864954 CEST192.168.2.68.8.8.80x36a0Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.065428972 CEST192.168.2.68.8.8.80x36a0Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.235419989 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:44.255163908 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.275226116 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:44.295388937 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.313766956 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:45.478450060 CEST192.168.2.68.8.8.80x6e9cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.473700047 CEST192.168.2.68.8.8.80x6e9cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.532617092 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:46.559519053 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.582341909 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:46.602571964 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.625363111 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:47.643717051 CEST192.168.2.68.8.8.80x1fdeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:48.262540102 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:48.282565117 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:48.300604105 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:48.319051981 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:48.342534065 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:49.251065969 CEST192.168.2.68.8.8.80xdc6dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.267714977 CEST192.168.2.68.8.8.80xdc6dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.891069889 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:50.908833027 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.926738977 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:50.950634003 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.969583988 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:51.967856884 CEST192.168.2.68.8.8.80xa66cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:52.034921885 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:52.054950953 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:52.075290918 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:52.093456984 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:52.113642931 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:55.712802887 CEST192.168.2.68.8.8.80xe578Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.705502987 CEST192.168.2.68.8.8.80xe578Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.792910099 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:56.812958956 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.837414026 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:56.858808041 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.877029896 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:58.408860922 CEST192.168.2.68.8.8.80x15adStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.533785105 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:58.553914070 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.574440002 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:43:58.594444036 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.614289999 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:00.717885971 CEST192.168.2.68.8.8.80x76a5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:00.844788074 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:00.864996910 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:00.886555910 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:00.906689882 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:00.930723906 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:02.461639881 CEST192.168.2.68.8.8.80xe899Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:02.566622972 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:02.586426973 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:02.606976986 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:02.627433062 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:02.647686005 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:04.089490891 CEST192.168.2.68.8.8.80x2315Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:04.744563103 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:04.765177965 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:04.785165071 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:04.805216074 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:04.825891972 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:06.382621050 CEST192.168.2.68.8.8.80xdaabStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.378031969 CEST192.168.2.68.8.8.80xdaabStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.470320940 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:07.490247965 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.510330915 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:07.531291008 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.555130005 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:08.953820944 CEST192.168.2.68.8.8.80xa02dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.053752899 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:09.071544886 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.091938019 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:09.112715960 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.133302927 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:10.494071960 CEST192.168.2.68.8.8.80x26baStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:10.565339088 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:10.587852001 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:10.607141018 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:10.627240896 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:10.647183895 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:13.952435970 CEST192.168.2.68.8.8.80xf735Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:14.108444929 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:14.128267050 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:14.146725893 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:14.164882898 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:14.192617893 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:15.463445902 CEST192.168.2.68.8.8.80xc22bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:15.515043020 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:15.534929991 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:15.557965040 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:15.578774929 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:15.600002050 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:17.033523083 CEST192.168.2.68.8.8.80x1614Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:17.107180119 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:17.126998901 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:17.199821949 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:17.220031977 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:17.245311022 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:18.446585894 CEST192.168.2.68.8.8.80xb64bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:19.514300108 CEST192.168.2.68.8.8.80xb64bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.504131079 CEST192.168.2.68.8.8.80xb64bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.766475916 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:20.786154032 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.806284904 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:20.826579094 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.846616030 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:22.105437040 CEST192.168.2.68.8.8.80x5585Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.099241972 CEST192.168.2.68.8.8.80x5585Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.377346992 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:23.403881073 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.422049999 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:23.440318108 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.460622072 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:23.853235960 CEST192.168.2.68.8.8.80x870eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.848371029 CEST192.168.2.68.8.8.80x870eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.935620070 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:24.955368042 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.973756075 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:24.995543957 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:25.014723063 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:26.281732082 CEST192.168.2.68.8.8.80x5b60Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:26.319732904 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:26.339554071 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:26.364052057 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:26.384203911 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:26.402095079 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:26.826797962 CEST192.168.2.68.8.8.80x894Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.360004902 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:27.377732038 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.397682905 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:27.416197062 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.434988022 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:27.849769115 CEST192.168.2.68.8.8.80xc33Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.893129110 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:27.912765026 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.930612087 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:27.948801041 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.968897104 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:28.560740948 CEST192.168.2.68.8.8.80x59cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.556891918 CEST192.168.2.68.8.8.80x59cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.640669107 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:29.658618927 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.726897955 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:29.746959925 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.765193939 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:30.807333946 CEST192.168.2.68.8.8.80x8a16Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:30.880889893 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:30.902951002 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:30.963319063 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:30.983637094 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:31.038439989 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:32.254594088 CEST192.168.2.68.8.8.80x6ca1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:32.873814106 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:32.895962000 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:32.915750027 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:32.941273928 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:32.965262890 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:33.473517895 CEST192.168.2.68.8.8.80x6372Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:33.516571045 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:33.536411047 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:33.556718111 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:33.577049971 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:33.597404003 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:33.999166965 CEST192.168.2.68.8.8.80x5b1cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:34.582575083 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:34.602118969 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:34.622255087 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:34.642153025 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:34.662548065 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:35.045813084 CEST192.168.2.68.8.8.80xdd95Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:35.220551968 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:35.238130093 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:35.264599085 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:35.284575939 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:35.302792072 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:35.671628952 CEST192.168.2.68.8.8.80xee4aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.677879095 CEST192.168.2.68.8.8.80xee4aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.712397099 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:36.732223988 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.753658056 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:36.774014950 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.798471928 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:37.285651922 CEST192.168.2.68.8.8.80xd110Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.320348978 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:37.342111111 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.362092972 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:37.381872892 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.399636030 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:37.907648087 CEST192.168.2.68.8.8.80x177dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.446387053 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:38.465975046 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.484715939 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:38.502414942 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.522131920 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:38.911334991 CEST192.168.2.68.8.8.80x6c8cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.952085018 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:38.969748974 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.988154888 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:39.007949114 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.027584076 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:39.449382067 CEST192.168.2.68.8.8.80x6aa3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.537282944 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:39.557926893 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.577698946 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:39.597796917 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.617894888 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:40.011394024 CEST192.168.2.68.8.8.80xea7dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.008980036 CEST192.168.2.68.8.8.80xea7dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.046010017 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:41.063436985 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.083128929 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:41.103311062 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.121342897 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:41.694123030 CEST192.168.2.68.8.8.80xab1aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.820821047 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:41.838524103 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.858326912 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:41.878318071 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.898667097 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:42.354094982 CEST192.168.2.68.8.8.80xacc3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:42.390948057 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:42.410727024 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:42.430521965 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:42.450740099 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:42.471271992 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:42.883522987 CEST192.168.2.68.8.8.80x56d3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.423599005 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:43.443293095 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.471731901 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:43.492294073 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.512238026 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:43.926251888 CEST192.168.2.68.8.8.80x5cfcStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.974957943 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:43.992635012 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.010315895 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:44.030719995 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.048963070 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:44.382122040 CEST192.168.2.68.8.8.80x6ce9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.418190002 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:44.437834978 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.457603931 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:44.475598097 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.497801065 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:44.906749010 CEST192.168.2.68.8.8.80x3503Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.442172050 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:45.461186886 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.480446100 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:45.500682116 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.522003889 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:45.854546070 CEST192.168.2.68.8.8.80xbc22Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.887908936 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:45.907608986 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.929172039 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:45.948751926 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.968565941 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:46.311108112 CEST192.168.2.68.8.8.80x7051Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:46.344320059 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:46.363903046 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:46.383892059 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:46.401562929 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:46.422476053 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:46.748087883 CEST192.168.2.68.8.8.80xaa50Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:47.783533096 CEST192.168.2.68.8.8.80xaa50Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.823721886 CEST192.168.2.68.8.8.80xaa50Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.830035925 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:48.847826004 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.868077993 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:48.937933922 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.958101034 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:50.444237947 CEST192.168.2.68.8.8.80xf6e1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:50.985032082 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:51.004868984 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.025084972 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:51.051028013 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.075094938 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:51.553877115 CEST192.168.2.68.8.8.80x893bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.600792885 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:51.620570898 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.640850067 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:51.663810968 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.684138060 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:52.075218916 CEST192.168.2.68.8.8.80x1223Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.086749077 CEST192.168.2.68.8.8.80x1223Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.159248114 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:53.176959038 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.195101976 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:53.215473890 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.235785961 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:53.561455011 CEST192.168.2.68.8.8.80x812dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.554263115 CEST192.168.2.68.8.8.80x812dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.627124071 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:54.646933079 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.665571928 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:54.685782909 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.703855038 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:55.064367056 CEST192.168.2.68.8.8.80x3588Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.075655937 CEST192.168.2.68.8.8.80x3588Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.104077101 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:56.124572992 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.144536972 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:56.166001081 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.185703039 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:56.519510984 CEST192.168.2.68.8.8.80x745fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:57.065381050 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:57.085031986 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:57.105081081 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:57.124924898 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:57.145411015 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:57.468453884 CEST192.168.2.68.8.8.80x1e86Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.460675001 CEST192.168.2.68.8.8.80x1e86Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.724746943 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:58.744615078 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.762397051 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:58.782279968 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.802648067 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:59.148394108 CEST192.168.2.68.8.8.80x598eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:59.188793898 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:59.208493948 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:59.228975058 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:59.249275923 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:59.269047976 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:44:59.632479906 CEST192.168.2.68.8.8.80x1a73Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:00.236723900 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:00.266316891 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:00.304908037 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:00.327888966 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:00.351748943 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:01.047051907 CEST192.168.2.68.8.8.80x98c5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:01.100621939 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:01.120774984 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:01.138669968 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:01.158698082 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:01.185034037 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:01.537235975 CEST192.168.2.68.8.8.80x6670Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.539155960 CEST192.168.2.68.8.8.80x6670Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.621450901 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:02.641321898 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.662218094 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:02.682245016 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.703985929 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:03.045041084 CEST192.168.2.68.8.8.80x7330Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.167327881 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:03.186618090 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.206528902 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:03.230027914 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.248644114 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:03.595216990 CEST192.168.2.68.8.8.80xc2b1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:04.131422997 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:04.151432037 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:04.173628092 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:04.193694115 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:04.211842060 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:04.562575102 CEST192.168.2.68.8.8.80x2d1bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.570563078 CEST192.168.2.68.8.8.80x2d1bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.649463892 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:05.669169903 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.689286947 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:05.709060907 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.726984024 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:06.085989952 CEST192.168.2.68.8.8.80xbeceStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.102210999 CEST192.168.2.68.8.8.80xbeceStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.130872011 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:07.148627996 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.166788101 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:07.190819025 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.210988045 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:07.536108971 CEST192.168.2.68.8.8.80x5212Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.542176008 CEST192.168.2.68.8.8.80x5212Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.617167950 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:08.637368917 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.657968044 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:08.678590059 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.700151920 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:09.050138950 CEST192.168.2.68.8.8.80xb3f3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:09.094361067 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:09.112131119 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:09.130816936 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:09.148936987 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:09.167177916 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:09.521197081 CEST192.168.2.68.8.8.80x439fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:10.054795027 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:10.074723005 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:10.094580889 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:10.114399910 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:10.134382963 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:10.448133945 CEST192.168.2.68.8.8.80xccc6Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.075881004 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:11.093877077 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.111963034 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:11.129894018 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.147941113 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:11.464940071 CEST192.168.2.68.8.8.80xef39Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.501610994 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:11.519431114 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.538182020 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:11.556204081 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.576226950 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:12.058248043 CEST192.168.2.68.8.8.80x92a8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:12.096239090 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:12.116146088 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:12.136667967 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:12.157481909 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:12.181438923 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:12.617562056 CEST192.168.2.68.8.8.80x46d2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.603507042 CEST192.168.2.68.8.8.80x46d2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.803756952 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:13.823400974 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.843635082 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:13.864005089 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.882213116 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:14.292866945 CEST192.168.2.68.8.8.80xf01aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.460872889 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:14.478678942 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.500005007 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:14.520580053 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.540780067 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:15.136995077 CEST192.168.2.68.8.8.80x7c76Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:15.226294041 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:15.249386072 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:15.269351959 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:15.290256023 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:15.310184002 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:15.733643055 CEST192.168.2.68.8.8.80x26ffStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.727732897 CEST192.168.2.68.8.8.80x26ffStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.773322105 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:16.791073084 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.811045885 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:16.831037998 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.848920107 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:17.195213079 CEST192.168.2.68.8.8.80x32faStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:17.740503073 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:17.760023117 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:17.784188986 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:17.804037094 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:17.822079897 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:18.176704884 CEST192.168.2.68.8.8.80x43f4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.228538990 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:18.246350050 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.264694929 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:18.283247948 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.303570986 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:18.617186069 CEST192.168.2.68.8.8.80xf9a1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.739464045 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:18.759263992 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.781388998 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:18.801786900 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.822079897 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:19.141751051 CEST192.168.2.68.8.8.80x53fcStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:19.178591967 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:19.198458910 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:19.218542099 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:19.238394976 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:19.258879900 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:19.579224110 CEST192.168.2.68.8.8.80x901cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:20.116256952 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:20.133744955 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:20.151835918 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:20.171719074 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:20.191617966 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:20.554970026 CEST192.168.2.68.8.8.80x6652Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:21.924539089 CEST192.168.2.68.8.8.80x6652Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.180754900 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:22.198497057 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.251710892 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:22.271616936 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.293889046 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:23.801573038 CEST192.168.2.68.8.8.80x6b1aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.337188959 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:24.354748011 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.374819994 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:24.397103071 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.416775942 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:24.724124908 CEST192.168.2.68.8.8.80x46dbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.807276964 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:24.827188969 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.845854998 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:24.869816065 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.890115976 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:25.236032009 CEST192.168.2.68.8.8.80x4aeaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.229635000 CEST192.168.2.68.8.8.80x4aeaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.267462015 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:26.285005093 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.303054094 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:26.323010921 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.343034029 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:26.532789946 CEST192.168.2.68.8.8.80xd8c1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.580955029 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:26.598524094 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.618513107 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:26.638406038 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.658196926 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:26.844290018 CEST192.168.2.68.8.8.80xa842Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.838044882 CEST192.168.2.68.8.8.80xa842Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.871409893 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:27.889216900 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.910057068 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:27.934014082 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.954080105 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:28.130558968 CEST192.168.2.68.8.8.80x8693Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:28.680681944 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:28.698486090 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:28.716622114 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:28.736488104 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:28.756602049 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:28.935791016 CEST192.168.2.68.8.8.80xd7ddStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.017611980 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:29.037585974 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.057624102 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:29.077449083 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.097445965 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:29.270234108 CEST192.168.2.68.8.8.80x9a3aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.387746096 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:29.407810926 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.427866936 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:29.448149920 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.468832970 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:29.649353981 CEST192.168.2.68.8.8.80x4aabStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.684885025 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:29.704402924 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.724261999 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:29.745492935 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.765614033 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:29.950278044 CEST192.168.2.68.8.8.80xd438Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.985933065 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:30.010283947 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:30.030648947 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:30.050806046 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:30.070764065 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:30.252954006 CEST192.168.2.68.8.8.80x3828Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.244724035 CEST192.168.2.68.8.8.80x3828Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.877437115 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:31.895020962 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.915004015 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:31.933352947 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.953591108 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:32.136538029 CEST192.168.2.68.8.8.80x12ddStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:32.678122044 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:32.697892904 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:32.718406916 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:32.738675117 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:32.758992910 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:32.933954954 CEST192.168.2.68.8.8.80xb965Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.016643047 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:33.034612894 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.054661989 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:33.076659918 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.098684072 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:33.277739048 CEST192.168.2.68.8.8.80x4fe0Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.401248932 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:33.421298027 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.441343069 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:33.462719917 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.483016968 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:33.675072908 CEST192.168.2.68.8.8.80xfbe4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.218529940 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:34.238634109 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.259006023 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:34.277427912 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.298140049 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:34.490065098 CEST192.168.2.68.8.8.80x2aa3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.570928097 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:34.590480089 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.608669996 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:34.633209944 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.651619911 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:34.833235979 CEST192.168.2.68.8.8.80xbbb4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.870647907 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:34.890654087 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.910660028 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:34.930943966 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.949399948 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:35.123905897 CEST192.168.2.68.8.8.80xc45cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:35.667711973 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:35.685539007 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:35.703871012 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:35.724077940 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:35.742268085 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:35.936270952 CEST192.168.2.68.8.8.80xb850Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:36.933383942 CEST192.168.2.68.8.8.80xb850Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:36.971575022 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:36.989136934 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.008989096 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:37.029062986 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.047108889 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:37.239649057 CEST192.168.2.68.8.8.80x86e7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.335338116 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:37.355426073 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.375782967 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:37.395998955 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.416090012 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:37.596064091 CEST192.168.2.68.8.8.80x6b88Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.655630112 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:37.673787117 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.693886042 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:37.714101076 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.734664917 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:37.905271053 CEST192.168.2.68.8.8.80xc3ebStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:38.917013884 CEST192.168.2.68.8.8.80xc3ebStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:39.917289019 CEST192.168.2.68.8.8.80xc3ebStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:39.954221964 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:39.973829031 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:39.991955042 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:40.011857986 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.030174971 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:40.202665091 CEST192.168.2.68.8.8.80x85fcStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.819202900 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:40.839432955 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.857769012 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:40.877619982 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.897866011 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:41.100511074 CEST192.168.2.68.8.8.80xeb3aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.090756893 CEST192.168.2.68.8.8.80xeb3aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.733959913 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:42.752242088 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.775516033 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:42.795799971 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.813838959 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:43.005398989 CEST192.168.2.68.8.8.80x79a2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.079855919 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:43.099769115 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.119823933 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:43.138087988 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.158257008 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:43.341131926 CEST192.168.2.68.8.8.80x3d7aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.876570940 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:43.896303892 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.916182995 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:43.934540033 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.955051899 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:44.135931969 CEST192.168.2.68.8.8.80x89daStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.172229052 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:44.191432953 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.209570885 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:44.232922077 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.253365040 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:44.436881065 CEST192.168.2.68.8.8.80x4715Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.993525982 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:45.011229992 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.033483982 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:45.053318977 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.071628094 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:45.253845930 CEST192.168.2.68.8.8.80xb4f5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.799216986 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:45.816936970 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.835304022 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:45.853434086 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.873965979 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:46.065907955 CEST192.168.2.68.8.8.80x356aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:46.199429035 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:46.217401028 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:46.235846043 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:46.254203081 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:46.272226095 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:46.460216999 CEST192.168.2.68.8.8.80xd84dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:47.458210945 CEST192.168.2.68.8.8.80xd84dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.461271048 CEST192.168.2.68.8.8.80xd84dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.497889042 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:48.517877102 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.538109064 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:48.558568954 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.583139896 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:48.776711941 CEST192.168.2.68.8.8.80xf4f9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:49.768608093 CEST192.168.2.68.8.8.80xf4f9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.784080982 CEST192.168.2.68.8.8.80xf4f9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.816631079 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:50.836877108 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.857497931 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:50.878483057 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.898634911 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:51.079763889 CEST192.168.2.68.8.8.80x889Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.655795097 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:51.673641920 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.692352057 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:51.716327906 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.736466885 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:51.931433916 CEST192.168.2.68.8.8.80xa6c5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:52.940356970 CEST192.168.2.68.8.8.80xa6c5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:52.975866079 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:52.995554924 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.013848066 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:53.032064915 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.052190065 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:53.227962971 CEST192.168.2.68.8.8.80x9daeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.764256954 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:53.787672043 CEST192.168.2.68.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.807893038 CEST192.168.2.68.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:53.826060057 CEST192.168.2.68.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.846708059 CEST192.168.2.68.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:54.023427963 CEST192.168.2.68.8.8.80x1cfStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:54.055927992 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:54.073595047 CEST192.168.2.68.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:54.095084906 CEST192.168.2.68.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:54.115288973 CEST192.168.2.68.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:54.135454893 CEST192.168.2.68.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:54.320693016 CEST192.168.2.68.8.8.80x81dbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.331852913 CEST192.168.2.68.8.8.80x81dbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.379616976 CEST192.168.2.68.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:55.399161100 CEST192.168.2.68.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.417422056 CEST192.168.2.68.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                  Aug 31, 2022 23:45:55.435640097 CEST192.168.2.68.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.456579924 CEST192.168.2.68.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                  Aug 31, 2022 23:43:29.787338972 CEST8.8.8.8192.168.2.60x157aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.826931000 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:29.845730066 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.865859032 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:29.887485027 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:29.907727003 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:31.062170982 CEST8.8.8.8192.168.2.60xe7f5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:31.096620083 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:31.118815899 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:31.139120102 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:31.163194895 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:31.188503981 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:32.284269094 CEST8.8.8.8192.168.2.60xb58eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:32.323657990 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:32.344270945 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:32.364722967 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:32.383225918 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:32.403651953 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:34.281522036 CEST8.8.8.8192.168.2.60x5447Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:34.420568943 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:34.507476091 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:34.527868986 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:34.548209906 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:34.608354092 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:39.915618896 CEST8.8.8.8192.168.2.60xd552Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:39.955585957 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:39.976094961 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:39.999306917 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:40.017430067 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:40.037492037 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:41.581630945 CEST8.8.8.8192.168.2.60xd289Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:41.629317045 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:41.647600889 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:41.672156096 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:41.692521095 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:41.712446928 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:42.090478897 CEST8.8.8.8192.168.2.60xd552Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.188271999 CEST8.8.8.8192.168.2.60x36a0Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.254477024 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:44.274674892 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.294872999 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:44.312819958 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:44.331306934 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:44.684417009 CEST8.8.8.8192.168.2.60x36a0Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.499958038 CEST8.8.8.8192.168.2.60x6e9cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.510267019 CEST8.8.8.8192.168.2.60x6e9cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.551563978 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:46.579423904 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.602025032 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:46.622019053 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:46.644733906 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:48.172422886 CEST8.8.8.8192.168.2.60x1fdeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:48.281683922 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:48.299957037 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:48.318428040 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:48.336926937 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:48.362144947 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:50.869615078 CEST8.8.8.8192.168.2.60xdc6dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.879436016 CEST8.8.8.8192.168.2.60xdc6dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.908133030 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:50.926266909 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.948179960 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:50.969118118 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:50.989043951 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:51.996550083 CEST8.8.8.8192.168.2.60xa66cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:52.054335117 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:52.074793100 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:52.092959881 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:52.113110065 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:52.131578922 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:56.771748066 CEST8.8.8.8192.168.2.60xe578Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.812232018 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:56.832400084 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.856908083 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:56.876498938 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:56.897021055 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:57.493695974 CEST8.8.8.8192.168.2.60xe578Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.437196016 CEST8.8.8.8192.168.2.60x15adName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.552953005 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:43:58.573885918 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.593951941 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:43:58.613837957 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:43:58.632070065 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:00.746181965 CEST8.8.8.8192.168.2.60x76a5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:00.862198114 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:00.885832071 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:00.906203032 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:00.926271915 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:00.950309992 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:02.498614073 CEST8.8.8.8192.168.2.60xe899Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:02.585666895 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:02.606394053 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:02.626574039 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:02.647193909 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:02.667031050 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:04.712783098 CEST8.8.8.8192.168.2.60x2315Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:04.763520956 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:04.784681082 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:04.804680109 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:04.822841883 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:04.843600988 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:07.404920101 CEST8.8.8.8192.168.2.60xdaabName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.489322901 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:07.509794950 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.529654026 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:07.550762892 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:07.574573040 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:07.958069086 CEST8.8.8.8192.168.2.60xdaabName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.030044079 CEST8.8.8.8192.168.2.60xa02dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.070871115 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:09.089035034 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.112163067 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:09.132690907 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:09.151197910 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:10.521003008 CEST8.8.8.8192.168.2.60x26baName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:10.584431887 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:10.605585098 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:10.625139952 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:10.645028114 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:10.664766073 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:14.085079908 CEST8.8.8.8192.168.2.60xf735Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:14.127676010 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:14.146212101 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:14.164454937 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:14.184348106 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:14.210242033 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:15.491667032 CEST8.8.8.8192.168.2.60xc22bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:15.534033060 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:15.554707050 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:15.578181982 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:15.598711014 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:15.619543076 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:17.061666965 CEST8.8.8.8192.168.2.60x1614Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:17.126076937 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:17.199198961 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:17.219321012 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:17.244647026 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:17.262830019 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:20.621330023 CEST8.8.8.8192.168.2.60xb64bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.672352076 CEST8.8.8.8192.168.2.60xb64bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.785567999 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:20.805774927 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.825907946 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:20.846116066 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:20.866101980 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:21.033593893 CEST8.8.8.8192.168.2.60xb64bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.367536068 CEST8.8.8.8192.168.2.60x5585Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.396424055 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:23.421693087 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.439786911 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:23.459907055 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:23.480061054 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:24.138417959 CEST8.8.8.8192.168.2.60x5585Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.916491032 CEST8.8.8.8192.168.2.60x870eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.954788923 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:24.966316938 CEST8.8.8.8192.168.2.60x870eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.972978115 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:24.993294001 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:25.013444901 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:25.034226894 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:26.310862064 CEST8.8.8.8192.168.2.60x5b60Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:26.338895082 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:26.359158993 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:26.383789062 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:26.401676893 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:26.420916080 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:27.353720903 CEST8.8.8.8192.168.2.60x894Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.377182007 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:27.397227049 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.415566921 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:27.433887959 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.454647064 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:27.878129959 CEST8.8.8.8192.168.2.60xc33Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.912081957 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:27.930186987 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.948191881 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:27.966533899 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:27.989063978 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:29.633094072 CEST8.8.8.8192.168.2.60x59cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.658077955 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:29.678369999 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.746664047 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:29.764878988 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:29.784965992 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:30.184921026 CEST8.8.8.8192.168.2.60x59cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:30.873771906 CEST8.8.8.8192.168.2.60x8a16Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:30.898199081 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:30.923027992 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:30.983294010 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:31.003328085 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:31.058240891 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:32.867783070 CEST8.8.8.8192.168.2.60x6ca1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:32.892914057 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:32.913737059 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:32.935492039 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:32.960941076 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:32.982760906 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:33.501940966 CEST8.8.8.8192.168.2.60x6372Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:33.535860062 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:33.556155920 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:33.576621056 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:33.596858978 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:33.617141962 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:34.576379061 CEST8.8.8.8192.168.2.60x5b1cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:34.601655960 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:34.621896982 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:34.641765118 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:34.662103891 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:34.682557106 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:35.214416027 CEST8.8.8.8192.168.2.60xdd95Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:35.237657070 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:35.257749081 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:35.284265041 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:35.302470922 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:35.322506905 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:36.706327915 CEST8.8.8.8192.168.2.60xee4aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.731586933 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:36.750371933 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.773665905 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:36.791744947 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:36.816457033 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:36.939074039 CEST8.8.8.8192.168.2.60xee4aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.313386917 CEST8.8.8.8192.168.2.60xd110Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.337385893 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:37.361768007 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.381539106 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:37.399224997 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:37.419363976 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:38.436364889 CEST8.8.8.8192.168.2.60x177dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.465503931 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:38.484422922 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.502108097 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:38.521826982 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.539650917 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:38.938251019 CEST8.8.8.8192.168.2.60x6c8cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:38.969208002 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:38.987540007 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.007621050 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:39.027304888 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.047132015 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:39.475492001 CEST8.8.8.8192.168.2.60x6aa3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.556307077 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:39.577370882 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.597099066 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:39.615369081 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:39.635468960 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:41.036927938 CEST8.8.8.8192.168.2.60xea7dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.062947989 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:41.082788944 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.102920055 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:41.121021986 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.141063929 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:41.169985056 CEST8.8.8.8192.168.2.60xea7dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.811177969 CEST8.8.8.8192.168.2.60xab1aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.837889910 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:41.857992887 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.877934933 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:41.898178101 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:41.918279886 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:42.382412910 CEST8.8.8.8192.168.2.60xacc3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:42.410130024 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:42.430150986 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:42.450306892 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:42.470879078 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:42.491142035 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:43.413260937 CEST8.8.8.8192.168.2.60x56d3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.442663908 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:43.460849047 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.491415024 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:43.511894941 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.531490088 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:43.961663008 CEST8.8.8.8192.168.2.60x5cfcName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:43.991935968 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:44.009932995 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.030059099 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:44.048516035 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.068895102 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:44.411514997 CEST8.8.8.8192.168.2.60x6ce9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.437238932 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:44.457220078 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.475223064 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:44.493381023 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:44.517654896 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:45.435556889 CEST8.8.8.8192.168.2.60x3503Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.460696936 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:45.478576899 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.500251055 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:45.520853996 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.539642096 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:45.881977081 CEST8.8.8.8192.168.2.60xbc22Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.907064915 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:45.927283049 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.948478937 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:45.968255043 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:45.988017082 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:46.337909937 CEST8.8.8.8192.168.2.60x7051Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:46.363435984 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:46.383466005 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:46.401216030 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:46.421830893 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:46.442011118 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:48.821460009 CEST8.8.8.8192.168.2.60xaa50Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.847312927 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:48.867320061 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.885781050 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:48.910540104 CEST8.8.8.8192.168.2.60xaa50Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.957782030 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:48.977746010 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:49.891845942 CEST8.8.8.8192.168.2.60xaa50Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:50.972193956 CEST8.8.8.8192.168.2.60xf6e1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.004219055 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:51.024416924 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.044862986 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:51.070853949 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.093216896 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:51.589247942 CEST8.8.8.8192.168.2.60x893bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.620028019 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:51.640378952 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.660531044 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:51.683698893 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:51.703880072 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:53.151417971 CEST8.8.8.8192.168.2.60x1223Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.176506996 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:53.194789886 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.215109110 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:53.235271931 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:53.255618095 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:53.625669956 CEST8.8.8.8192.168.2.60x1223Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.619091034 CEST8.8.8.8192.168.2.60x812dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.646353960 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:54.664908886 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.685338974 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:54.703402996 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:54.721267939 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:54.741657972 CEST8.8.8.8192.168.2.60x812dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.097080946 CEST8.8.8.8192.168.2.60x3588Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.124034882 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:56.144139051 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.165666103 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:56.185373068 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:56.206304073 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:57.057044029 CEST8.8.8.8192.168.2.60x745fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:57.084417105 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:57.104636908 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:57.124588966 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:57.144799948 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:57.165554047 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:57.657109976 CEST8.8.8.8192.168.2.60x3588Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.709364891 CEST8.8.8.8192.168.2.60x1e86Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.744060993 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:58.762052059 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.775975943 CEST8.8.8.8192.168.2.60x1e86Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.781868935 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:58.802098036 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:58.822364092 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:59.175309896 CEST8.8.8.8192.168.2.60x598eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:59.208067894 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:44:59.228351116 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:59.248884916 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:44:59.268644094 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:44:59.286719084 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:00.215579033 CEST8.8.8.8192.168.2.60x1a73Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:00.255872011 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:00.286022902 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:00.325176001 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:00.348517895 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:00.371310949 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:01.091835022 CEST8.8.8.8192.168.2.60x98c5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:01.120204926 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:01.138207912 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:01.158245087 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:01.178411007 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:01.204669952 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:02.615139008 CEST8.8.8.8192.168.2.60x6670Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.640677929 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:02.661689997 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.681889057 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:02.703619003 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:02.723409891 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:03.106302977 CEST8.8.8.8192.168.2.60x6670Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.158047915 CEST8.8.8.8192.168.2.60x7330Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.184478045 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:03.206196070 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.228708982 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:03.248331070 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:03.268287897 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:04.125479937 CEST8.8.8.8192.168.2.60xc2b1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:04.150804043 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:04.172810078 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:04.193243027 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:04.211317062 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:04.231714964 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:05.642608881 CEST8.8.8.8192.168.2.60x2d1bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.668690920 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:05.679235935 CEST8.8.8.8192.168.2.60x2d1bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.688968897 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.708745956 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:05.726625919 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:05.746467113 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:07.123591900 CEST8.8.8.8192.168.2.60xbeceName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.147948027 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:07.166426897 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.184499979 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:07.210597992 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:07.230631113 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:07.638503075 CEST8.8.8.8192.168.2.60xbeceName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.604301929 CEST8.8.8.8192.168.2.60x5212Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.609941006 CEST8.8.8.8192.168.2.60x5212Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.636708975 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:08.657493114 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.678095102 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:08.699327946 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:08.720056057 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:09.086039066 CEST8.8.8.8192.168.2.60xb3f3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:09.111648083 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:09.129959106 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:09.148557901 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:09.166651011 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:09.184634924 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:10.048824072 CEST8.8.8.8192.168.2.60x439fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:10.074271917 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:10.094129086 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:10.114101887 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:10.134094954 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:10.153976917 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:11.069394112 CEST8.8.8.8192.168.2.60xccc6Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.093446970 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:11.111608028 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.129561901 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:11.147553921 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.167288065 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:11.493338108 CEST8.8.8.8192.168.2.60xef39Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.518835068 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:11.537653923 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.555847883 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:11.575905085 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:11.596256971 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:12.086657047 CEST8.8.8.8192.168.2.60x92a8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:12.115483999 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:12.133847952 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:12.156578064 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:12.177124977 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:12.199208975 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:13.795871973 CEST8.8.8.8192.168.2.60x46d2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.822742939 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:13.843261957 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.863305092 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:13.881822109 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:13.899844885 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:14.276071072 CEST8.8.8.8192.168.2.60x46d2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.455116987 CEST8.8.8.8192.168.2.60xf01aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.478157043 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:14.498713970 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.520136118 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:14.540436983 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:14.560705900 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:15.212640047 CEST8.8.8.8192.168.2.60x7c76Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:15.245517015 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:15.268943071 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:15.289814949 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:15.309674978 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:15.330753088 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:16.762197018 CEST8.8.8.8192.168.2.60x26ffName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.790291071 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:16.810615063 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.830655098 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:16.848545074 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:16.868464947 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:17.734127045 CEST8.8.8.8192.168.2.60x32faName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:17.759524107 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:17.779627085 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:17.803694963 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:17.821728945 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:17.841531038 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:18.213179111 CEST8.8.8.8192.168.2.60x43f4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.245822906 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:18.264169931 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.282655001 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:18.303041935 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.323292971 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:18.727078915 CEST8.8.8.8192.168.2.60xf9a1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.758493900 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:18.779901028 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.801358938 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:18.821578026 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:18.839883089 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:19.169836044 CEST8.8.8.8192.168.2.60x53fcName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:19.197752953 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:19.218126059 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:19.237973928 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:19.258479118 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:19.278409958 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:20.108885050 CEST8.8.8.8192.168.2.60x901cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:20.133389950 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:20.151463985 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:20.171344042 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:20.191129923 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:20.211190939 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:20.750307083 CEST8.8.8.8192.168.2.60x26ffServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.173013926 CEST8.8.8.8192.168.2.60x6652Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.197968006 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:22.217995882 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.271331072 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:22.290329933 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:22.313796043 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:23.552133083 CEST8.8.8.8192.168.2.60x6652Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.331062078 CEST8.8.8.8192.168.2.60x6b1aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.354151011 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:24.374262094 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.394306898 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:24.416450024 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.435049057 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:24.800530910 CEST8.8.8.8192.168.2.60x46dbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.826673985 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:24.844790936 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.866312027 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:24.889637947 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:24.909706116 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:26.257894039 CEST8.8.8.8192.168.2.60x4aeaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.267116070 CEST8.8.8.8192.168.2.60x4aeaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.284495115 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:26.302685022 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.322731018 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:26.342674017 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.362843990 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:26.570079088 CEST8.8.8.8192.168.2.60xd8c1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.598028898 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:26.618112087 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.638072968 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:26.657855034 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:26.677685976 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:27.864686966 CEST8.8.8.8192.168.2.60xa842Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.888834953 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:27.909015894 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.929562092 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:27.953717947 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:27.971896887 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:28.669117928 CEST8.8.8.8192.168.2.60x8693Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:28.697978020 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:28.716156006 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:28.735982895 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:28.756066084 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:28.776252031 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.011524916 CEST8.8.8.8192.168.2.60xd7ddName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.037141085 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:29.057269096 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.077163935 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.097136974 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.117222071 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.381879091 CEST8.8.8.8192.168.2.60x9a3aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.407457113 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:29.427575111 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.447861910 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.468513966 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.488358974 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.606527090 CEST8.8.8.8192.168.2.60xa842Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.678388119 CEST8.8.8.8192.168.2.60x4aabName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.704013109 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:29.723932981 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.745117903 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.765243053 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:29.785756111 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:29.978842020 CEST8.8.8.8192.168.2.60xd438Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:30.005171061 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:30.029825926 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:30.050517082 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:30.070476055 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:30.090724945 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:31.870630980 CEST8.8.8.8192.168.2.60x3828Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.870671988 CEST8.8.8.8192.168.2.60x3828Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.894535065 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:31.914591074 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.932943106 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:31.953244925 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:31.973292112 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:32.671992064 CEST8.8.8.8192.168.2.60x12ddName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:32.697273970 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:32.717818022 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:32.738121986 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:32.758621931 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:32.776418924 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:33.008081913 CEST8.8.8.8192.168.2.60xb965Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.033670902 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:33.052232027 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.074173927 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:33.096429110 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.116456032 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:33.391014099 CEST8.8.8.8192.168.2.60x4fe0Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.420255899 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:33.440869093 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.461447954 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:33.482673883 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:33.502680063 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:34.205842018 CEST8.8.8.8192.168.2.60xfbe4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.237862110 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:34.258346081 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.276730061 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:34.297285080 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.317642927 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:34.563857079 CEST8.8.8.8192.168.2.60x2aa3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.590023994 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:34.608253002 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.632611990 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:34.650960922 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.671530008 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:34.861598015 CEST8.8.8.8192.168.2.60xbbb4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.889672041 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:34.910166979 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.930305958 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:34.948801041 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:34.966978073 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:35.659677029 CEST8.8.8.8192.168.2.60xc45cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:35.684854031 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:35.703336000 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:35.723376036 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:35.741929054 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:35.761758089 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:36.962335110 CEST8.8.8.8192.168.2.60xb850Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:36.988629103 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:37.008464098 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.028367996 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:37.046492100 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.068111897 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:37.328402042 CEST8.8.8.8192.168.2.60x86e7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.354845047 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:37.375205994 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.395513058 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:37.415610075 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.435617924 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:37.646131992 CEST8.8.8.8192.168.2.60x6b88Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.672806025 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:37.693382025 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.713413000 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:37.733810902 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:37.752490044 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:39.287280083 CEST8.8.8.8192.168.2.60xb850Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:39.946167946 CEST8.8.8.8192.168.2.60xc3ebName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:39.973323107 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:39.991565943 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.011499882 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:40.029787064 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.050113916 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:40.095642090 CEST8.8.8.8192.168.2.60xc3ebName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.110693932 CEST8.8.8.8192.168.2.60xc3ebName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.811549902 CEST8.8.8.8192.168.2.60x85fcName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.838596106 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:40.857355118 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.877202034 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:40.897402048 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:40.919195890 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:42.722179890 CEST8.8.8.8192.168.2.60xeb3aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.751497984 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:42.772325993 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.795279980 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:42.813390017 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:42.831677914 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:43.071841955 CEST8.8.8.8192.168.2.60x79a2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.099137068 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:43.119312048 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.137548923 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:43.157763004 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.177860975 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:43.868730068 CEST8.8.8.8192.168.2.60x3d7aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.895756960 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:43.915795088 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.933940887 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:43.954459906 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:43.972961903 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:44.162213087 CEST8.8.8.8192.168.2.60x89daName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.189434052 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:44.209141016 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.229032993 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:44.252708912 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:44.273025990 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:44.985682964 CEST8.8.8.8192.168.2.60x4715Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.010627031 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:45.030633926 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.052932024 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:45.071058035 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.091566086 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:45.790606022 CEST8.8.8.8192.168.2.60xb4f5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.816375017 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:45.834777117 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.852967024 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:45.873301029 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:45.891820908 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:46.191735983 CEST8.8.8.8192.168.2.60x356aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:46.216659069 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:46.235269070 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:46.253509998 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:46.271697998 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:46.291834116 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:47.109087944 CEST8.8.8.8192.168.2.60xeb3aServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.489577055 CEST8.8.8.8192.168.2.60xd84dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.517317057 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:48.537610054 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.544222116 CEST8.8.8.8192.168.2.60xd84dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.557970047 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:48.578443050 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:48.602873087 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:49.040975094 CEST8.8.8.8192.168.2.60xd84dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.809185982 CEST8.8.8.8192.168.2.60xf4f9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.836035967 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:50.856573105 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.878010035 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:50.898149967 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:50.916162014 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:51.168813944 CEST8.8.8.8192.168.2.60xf4f9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.647681952 CEST8.8.8.8192.168.2.60x889Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.672899008 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:51.691550970 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.711776018 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:51.736037970 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:51.756360054 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:52.403012991 CEST8.8.8.8192.168.2.60xf4f9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:52.968674898 CEST8.8.8.8192.168.2.60xa6c5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:52.995096922 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:53.013417959 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.031677008 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:53.051702976 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.073030949 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:53.510509014 CEST8.8.8.8192.168.2.60xa6c5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.758115053 CEST8.8.8.8192.168.2.60x9daeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.783446074 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:53.807456970 CEST8.8.8.8192.168.2.60x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.825607061 CEST8.8.8.8192.168.2.60x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:53.846086025 CEST8.8.8.8192.168.2.60x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:53.866564035 CEST8.8.8.8192.168.2.60x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:54.049860954 CEST8.8.8.8192.168.2.60x1cfName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:54.073111057 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:54.093367100 CEST8.8.8.8192.168.2.60x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:54.114746094 CEST8.8.8.8192.168.2.60x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:54.135003090 CEST8.8.8.8192.168.2.60x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:54.154999018 CEST8.8.8.8192.168.2.60x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:55.368313074 CEST8.8.8.8192.168.2.60x81dbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.398617029 CEST8.8.8.8192.168.2.60x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                  Aug 31, 2022 23:45:55.417046070 CEST8.8.8.8192.168.2.60x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.435185909 CEST8.8.8.8192.168.2.60x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:55.456170082 CEST8.8.8.8192.168.2.60x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                  Aug 31, 2022 23:45:55.476073980 CEST8.8.8.8192.168.2.60x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                  Aug 31, 2022 23:45:55.889926910 CEST8.8.8.8192.168.2.60x81dbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)

                                  Click to jump to process

                                  Target ID:0
                                  Start time:23:43:19
                                  Start date:31/08/2022
                                  Path:C:\Users\user\Desktop\BUgAyPXboK.exe
                                  Wow64 process (32bit):true
                                  Commandline:"C:\Users\user\Desktop\BUgAyPXboK.exe"
                                  Imagebase:0x400000
                                  File size:75264 bytes
                                  MD5 hash:DDE91B6947D2B726E5BB8F5852CECB76
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000000.00000000.252253377.000000000040E000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000000.00000002.584330728.000000000040E000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                                  Reputation:low

                                  Target ID:2
                                  Start time:23:43:28
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:moderate

                                  Target ID:3
                                  Start time:23:43:28
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  Target ID:4
                                  Start time:23:43:29
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:moderate

                                  Target ID:6
                                  Start time:23:43:30
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  Target ID:7
                                  Start time:23:43:31
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:moderate

                                  Target ID:8
                                  Start time:23:43:31
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  Target ID:9
                                  Start time:23:43:32
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:moderate

                                  Target ID:10
                                  Start time:23:43:32
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:12
                                  Start time:23:43:35
                                  Start date:31/08/2022
                                  Path:C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe
                                  Wow64 process (32bit):true
                                  Commandline:"C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe"
                                  Imagebase:0x400000
                                  File size:75264 bytes
                                  MD5 hash:EE7A320AB14366D36D44CDC33B5E8238
                                  Has elevated privileges:false
                                  Has administrator privileges:false
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000C.00000002.292150068.0000000000412000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000C.00000000.289414377.000000000040E000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000C.00000002.292144226.000000000040E000.00000004.00000001.01000000.00000006.sdmp, Author: Joe Security
                                  • Rule: SUSP_RANSOMWARE_Indicator_Jul20, Description: Detects ransomware indicator, Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, Author: Florian Roth
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, Author: Joe Security
                                  • Rule: Gandcrab, Description: Gandcrab Payload, Source: C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe, Author: kevoreilly
                                  Antivirus matches:
                                  • Detection: 100%, Avira
                                  • Detection: 100%, Joe Sandbox ML

                                  Target ID:14
                                  Start time:23:43:35
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:15
                                  Start time:23:43:37
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:19
                                  Start time:23:43:39
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:21
                                  Start time:23:43:40
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:23
                                  Start time:23:43:41
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:24
                                  Start time:23:43:42
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:25
                                  Start time:23:43:43
                                  Start date:31/08/2022
                                  Path:C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe
                                  Wow64 process (32bit):true
                                  Commandline:"C:\Users\user\AppData\Roaming\Microsoft\ykbxzh.exe"
                                  Imagebase:0x400000
                                  File size:75264 bytes
                                  MD5 hash:EE7A320AB14366D36D44CDC33B5E8238
                                  Has elevated privileges:false
                                  Has administrator privileges:false
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000019.00000002.306373977.000000000040E000.00000004.00000001.01000000.00000006.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000019.00000000.303643193.000000000040E000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000019.00000002.306381807.0000000000412000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security

                                  Target ID:26
                                  Start time:23:43:44
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:27
                                  Start time:23:43:44
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:29
                                  Start time:23:43:46
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:30
                                  Start time:23:43:46
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:31
                                  Start time:23:43:48
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:32
                                  Start time:23:43:48
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:34
                                  Start time:23:43:50
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:35
                                  Start time:23:43:51
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:36
                                  Start time:23:43:51
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:37
                                  Start time:23:43:52
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:39
                                  Start time:23:43:56
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:40
                                  Start time:23:43:57
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:41
                                  Start time:23:43:58
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:42
                                  Start time:23:43:59
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:43
                                  Start time:23:44:01
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:44
                                  Start time:23:44:01
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:45
                                  Start time:23:44:02
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:46
                                  Start time:23:44:03
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:47
                                  Start time:23:44:04
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:48
                                  Start time:23:44:05
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:49
                                  Start time:23:44:07
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:50
                                  Start time:23:44:07
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:51
                                  Start time:23:44:09
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:52
                                  Start time:23:44:09
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:53
                                  Start time:23:44:10
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:54
                                  Start time:23:44:11
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:55
                                  Start time:23:44:14
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:56
                                  Start time:23:44:14
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:57
                                  Start time:23:44:15
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:58
                                  Start time:23:44:16
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:59
                                  Start time:23:44:17
                                  Start date:31/08/2022
                                  Path:C:\Windows\SysWOW64\nslookup.exe
                                  Wow64 process (32bit):true
                                  Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                  Imagebase:0xd60000
                                  File size:78336 bytes
                                  MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  Target ID:60
                                  Start time:23:44:17
                                  Start date:31/08/2022
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6da640000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  No disassembly