Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
9gkAKTWOXp.exe

Overview

General Information

Sample Name:9gkAKTWOXp.exe
Analysis ID:694569
MD5:74e135b472b7496b371ce3ba3acfeea8
SHA1:b64fdd870ff28291b8347317a838a5fb210a6056
SHA256:d093322a612760cb00ae6fb4c453851ba26f59f2e6a0920b5871a28bbddf9355
Tags:exe
Infos:

Detection

Gandcrab
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Gandcrab
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Snort IDS alert for network traffic
Contains functionality to determine the online IP of the system
Found Tor onion address
Uses nslookup.exe to query domains
Machine Learning detection for sample
May check the online IP address of the machine
Machine Learning detection for dropped file
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
Too many similar processes found
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Queries information about the installed CPU (vendor, model number etc)
Drops PE files
Found evaded block containing many API calls
Contains functionality to enumerate device drivers
Checks for available system drives (often done to infect USB drives)
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • 9gkAKTWOXp.exe (PID: 4664 cmdline: "C:\Users\user\Desktop\9gkAKTWOXp.exe" MD5: 74E135B472B7496B371CE3BA3ACFEEA8)
    • nslookup.exe (PID: 5752 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5460 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 484 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1944 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5368 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4184 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6080 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5208 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 3232 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5816 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 3460 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 3880 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 408 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5920 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 996 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5116 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5780 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5360 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5880 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4272 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4948 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1328 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6064 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1976 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5784 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5956 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2516 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 3184 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 576 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5500 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5964 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5972 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4512 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 1360 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 1556 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 2140 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 2764 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4820 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4272 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 3184 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5236 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 4996 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5708 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 3196 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • vkspii.exe (PID: 6028 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe" MD5: 551DA842D854798E9D42602EB420BD96)
  • vkspii.exe (PID: 4024 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe" MD5: 551DA842D854798E9D42602EB420BD96)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
9gkAKTWOXp.exeSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
  • 0xf716:$: DECRYPT.txt
  • 0xf784:$: DECRYPT.txt
9gkAKTWOXp.exeJoeSecurity_GandcrabYara detected GandcrabJoe Security
    9gkAKTWOXp.exeGandcrabGandcrab Payloadkevoreilly
    • 0xf70c:$string1: GDCB-DECRYPT.txt
    • 0xf77a:$string1: GDCB-DECRYPT.txt
    • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
    • 0xf716:$: DECRYPT.txt
    • 0xf784:$: DECRYPT.txt
    C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeJoeSecurity_GandcrabYara detected GandcrabJoe Security
      C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeGandcrabGandcrab Payloadkevoreilly
      • 0xf70c:$string1: GDCB-DECRYPT.txt
      • 0xf77a:$string1: GDCB-DECRYPT.txt
      • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
      SourceRuleDescriptionAuthorStrings
      0000000D.00000002.295326787.000000000040E000.00000004.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
        0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
          00000015.00000002.305269157.000000000040E000.00000004.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
            00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
              00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
                Click to see the 6 entries
                SourceRuleDescriptionAuthorStrings
                13.0.vkspii.exe.400000.0.unpackSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
                • 0xf716:$: DECRYPT.txt
                • 0xf784:$: DECRYPT.txt
                13.0.vkspii.exe.400000.0.unpackJoeSecurity_GandcrabYara detected GandcrabJoe Security
                  13.0.vkspii.exe.400000.0.unpackGandcrabGandcrab Payloadkevoreilly
                  • 0xf70c:$string1: GDCB-DECRYPT.txt
                  • 0xf77a:$string1: GDCB-DECRYPT.txt
                  • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
                  1.2.9gkAKTWOXp.exe.400000.0.unpackSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
                  • 0xf716:$: DECRYPT.txt
                  • 0xf784:$: DECRYPT.txt
                  1.2.9gkAKTWOXp.exe.400000.0.unpackJoeSecurity_GandcrabYara detected GandcrabJoe Security
                    Click to see the 13 entries
                    No Sigma rule has matched
                    Timestamp:192.168.2.38.8.8.855642532829498 09/01/22-00:01:41.321667
                    SID:2829498
                    Source Port:55642
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860090532829500 09/01/22-00:02:16.489371
                    SID:2829500
                    Source Port:60090
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862436532026737 09/01/22-00:02:57.542714
                    SID:2026737
                    Source Port:62436
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855955532829500 09/01/22-00:03:25.632008
                    SID:2829500
                    Source Port:55955
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853431532829498 09/01/22-00:02:18.409896
                    SID:2829498
                    Source Port:53431
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865513532829500 09/01/22-00:02:19.430995
                    SID:2829500
                    Source Port:65513
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864276532829498 09/01/22-00:03:00.100399
                    SID:2829498
                    Source Port:64276
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851891532026737 09/01/22-00:03:31.975246
                    SID:2026737
                    Source Port:51891
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859765532026737 09/01/22-00:03:34.032990
                    SID:2026737
                    Source Port:59765
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853309532829500 09/01/22-00:01:54.918396
                    SID:2829500
                    Source Port:53309
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854155532829498 09/01/22-00:02:39.711366
                    SID:2829498
                    Source Port:54155
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849169532829500 09/01/22-00:02:32.443414
                    SID:2829500
                    Source Port:49169
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864378532829500 09/01/22-00:03:19.972139
                    SID:2829500
                    Source Port:64378
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857391532829500 09/01/22-00:02:53.276938
                    SID:2829500
                    Source Port:57391
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851597532026737 09/01/22-00:03:26.976848
                    SID:2026737
                    Source Port:51597
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853271532829498 09/01/22-00:02:55.260307
                    SID:2829498
                    Source Port:53271
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853471532829500 09/01/22-00:02:00.665796
                    SID:2829500
                    Source Port:53471
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865323532026737 09/01/22-00:01:43.859132
                    SID:2026737
                    Source Port:65323
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860647532829498 09/01/22-00:03:25.300157
                    SID:2829498
                    Source Port:60647
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850230532026737 09/01/22-00:02:54.735839
                    SID:2026737
                    Source Port:50230
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850624532026737 09/01/22-00:03:18.677171
                    SID:2026737
                    Source Port:50624
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853468532829500 09/01/22-00:02:00.604247
                    SID:2829500
                    Source Port:53468
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858122532829498 09/01/22-00:02:27.905128
                    SID:2829498
                    Source Port:58122
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854436532829498 09/01/22-00:03:36.045306
                    SID:2829498
                    Source Port:54436
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862426532026737 09/01/22-00:03:13.145963
                    SID:2026737
                    Source Port:62426
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856046532829500 09/01/22-00:01:38.500367
                    SID:2829500
                    Source Port:56046
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859378532829500 09/01/22-00:02:48.340518
                    SID:2829500
                    Source Port:59378
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858305532026737 09/01/22-00:02:34.497221
                    SID:2026737
                    Source Port:58305
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861418532829498 09/01/22-00:02:02.984507
                    SID:2829498
                    Source Port:61418
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850095532026737 09/01/22-00:03:38.741458
                    SID:2026737
                    Source Port:50095
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852114532026737 09/01/22-00:03:20.324395
                    SID:2026737
                    Source Port:52114
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865466532829500 09/01/22-00:03:37.373699
                    SID:2829500
                    Source Port:65466
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853042532026737 09/01/22-00:03:06.339869
                    SID:2026737
                    Source Port:53042
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849877532829500 09/01/22-00:02:36.035379
                    SID:2829500
                    Source Port:49877
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864971532829500 09/01/22-00:03:05.617213
                    SID:2829500
                    Source Port:64971
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861186532829498 09/01/22-00:02:52.648140
                    SID:2829498
                    Source Port:61186
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859829532829500 09/01/22-00:02:55.953112
                    SID:2829500
                    Source Port:59829
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849204532026737 09/01/22-00:02:46.678054
                    SID:2026737
                    Source Port:49204
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861364532829498 09/01/22-00:03:28.558638
                    SID:2829498
                    Source Port:61364
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857829532829500 09/01/22-00:03:23.021549
                    SID:2829500
                    Source Port:57829
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850788532026737 09/01/22-00:02:43.387386
                    SID:2026737
                    Source Port:50788
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851996532026737 09/01/22-00:02:26.312895
                    SID:2026737
                    Source Port:51996
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857706532829500 09/01/22-00:01:42.686131
                    SID:2829500
                    Source Port:57706
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859436532026737 09/01/22-00:01:57.638087
                    SID:2026737
                    Source Port:59436
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859822532026737 09/01/22-00:02:19.952319
                    SID:2026737
                    Source Port:59822
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860587532026737 09/01/22-00:01:27.550732
                    SID:2026737
                    Source Port:60587
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852957532829500 09/01/22-00:01:25.328522
                    SID:2829500
                    Source Port:52957
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858914532829500 09/01/22-00:03:18.020601
                    SID:2829500
                    Source Port:58914
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853850532026737 09/01/22-00:01:50.247028
                    SID:2026737
                    Source Port:53850
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856619532026737 09/01/22-00:02:49.126045
                    SID:2026737
                    Source Port:56619
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852112532026737 09/01/22-00:03:20.284135
                    SID:2026737
                    Source Port:52112
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865198532829500 09/01/22-00:02:04.768621
                    SID:2829500
                    Source Port:65198
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853848532829498 09/01/22-00:01:59.462827
                    SID:2829498
                    Source Port:53848
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851893532026737 09/01/22-00:03:32.036713
                    SID:2026737
                    Source Port:51893
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854433532829498 09/01/22-00:03:35.979601
                    SID:2829498
                    Source Port:54433
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853310532829500 09/01/22-00:01:54.940366
                    SID:2829500
                    Source Port:53310
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859438532026737 09/01/22-00:01:57.681285
                    SID:2026737
                    Source Port:59438
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861421532829498 09/01/22-00:02:03.043258
                    SID:2829498
                    Source Port:61421
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852458532026737 09/01/22-00:03:02.844406
                    SID:2026737
                    Source Port:52458
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855652532829498 09/01/22-00:03:19.259211
                    SID:2829498
                    Source Port:55652
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861130532829498 09/01/22-00:03:15.942186
                    SID:2829498
                    Source Port:61130
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860421532829498 09/01/22-00:03:32.382333
                    SID:2829498
                    Source Port:60421
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864973532829500 09/01/22-00:03:05.661525
                    SID:2829500
                    Source Port:64973
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863567532026737 09/01/22-00:02:17.089606
                    SID:2026737
                    Source Port:63567
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865463532829500 09/01/22-00:03:37.309587
                    SID:2829500
                    Source Port:65463
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865389532026737 09/01/22-00:02:38.719558
                    SID:2026737
                    Source Port:65389
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853040532026737 09/01/22-00:03:06.300781
                    SID:2026737
                    Source Port:53040
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857827532829500 09/01/22-00:03:22.978908
                    SID:2829500
                    Source Port:57827
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853039532026737 09/01/22-00:03:06.280270
                    SID:2026737
                    Source Port:53039
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859585532026737 09/01/22-00:02:11.746820
                    SID:2026737
                    Source Port:59585
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857708532829500 09/01/22-00:01:42.729663
                    SID:2829500
                    Source Port:57708
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851142532829498 09/01/22-00:01:24.090037
                    SID:2829498
                    Source Port:51142
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853433532829498 09/01/22-00:02:18.458138
                    SID:2829498
                    Source Port:53433
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860093532829500 09/01/22-00:02:16.558554
                    SID:2829500
                    Source Port:60093
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849206532026737 09/01/22-00:02:46.717208
                    SID:2026737
                    Source Port:49206
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851143532829498 09/01/22-00:01:24.124615
                    SID:2829498
                    Source Port:51143
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854158532829498 09/01/22-00:02:39.772185
                    SID:2829498
                    Source Port:54158
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859376532829500 09/01/22-00:02:48.263272
                    SID:2829500
                    Source Port:59376
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864825532829500 09/01/22-00:02:24.749273
                    SID:2829500
                    Source Port:64825
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864273532829498 09/01/22-00:03:00.036817
                    SID:2829498
                    Source Port:64273
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851894532026737 09/01/22-00:03:32.055555
                    SID:2026737
                    Source Port:51894
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854434532829498 09/01/22-00:03:36.001169
                    SID:2829498
                    Source Port:54434
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859768532026737 09/01/22-00:03:34.095324
                    SID:2026737
                    Source Port:59768
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853054532829498 09/01/22-00:02:15.078816
                    SID:2829498
                    Source Port:53054
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863448532829498 09/01/22-00:02:35.455212
                    SID:2829498
                    Source Port:63448
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865111532829500 09/01/22-00:01:46.954181
                    SID:2829500
                    Source Port:65111
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853627532026737 09/01/22-00:02:01.832804
                    SID:2026737
                    Source Port:53627
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865200532829500 09/01/22-00:02:04.820486
                    SID:2829500
                    Source Port:65200
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855461532829498 09/01/22-00:03:07.325312
                    SID:2829498
                    Source Port:55461
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865390532026737 09/01/22-00:02:38.738598
                    SID:2026737
                    Source Port:65390
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865516532829500 09/01/22-00:02:19.492210
                    SID:2829500
                    Source Port:65516
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855654532829498 09/01/22-00:03:19.297074
                    SID:2829498
                    Source Port:55654
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854288532829500 09/01/22-00:03:33.756470
                    SID:2829500
                    Source Port:54288
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865515532829500 09/01/22-00:02:19.472414
                    SID:2829500
                    Source Port:65515
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859767532026737 09/01/22-00:03:34.075907
                    SID:2026737
                    Source Port:59767
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860649532829498 09/01/22-00:03:25.341169
                    SID:2829498
                    Source Port:60649
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853628532026737 09/01/22-00:02:01.851234
                    SID:2026737
                    Source Port:53628
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864970532829500 09/01/22-00:02:44.867082
                    SID:2829500
                    Source Port:64970
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862434532026737 09/01/22-00:02:57.492445
                    SID:2026737
                    Source Port:62434
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859583532026737 09/01/22-00:02:11.706174
                    SID:2026737
                    Source Port:59583
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850232532026737 09/01/22-00:02:54.777871
                    SID:2026737
                    Source Port:50232
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852959532829500 09/01/22-00:01:25.367458
                    SID:2829500
                    Source Port:52959
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850787532026737 09/01/22-00:02:43.367194
                    SID:2026737
                    Source Port:50787
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858123532829498 09/01/22-00:02:27.969558
                    SID:2829498
                    Source Port:58123
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860423532829498 09/01/22-00:03:32.424188
                    SID:2829498
                    Source Port:60423
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865201532829500 09/01/22-00:02:04.842170
                    SID:2829500
                    Source Port:65201
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854157532829498 09/01/22-00:02:39.751533
                    SID:2829498
                    Source Port:54157
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865112532829500 09/01/22-00:01:46.974641
                    SID:2829500
                    Source Port:65112
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859830532829500 09/01/22-00:02:55.974495
                    SID:2829500
                    Source Port:59830
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855460532829498 09/01/22-00:03:07.301197
                    SID:2829498
                    Source Port:55460
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853307532829500 09/01/22-00:01:54.875889
                    SID:2829500
                    Source Port:53307
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851595532026737 09/01/22-00:03:26.929732
                    SID:2026737
                    Source Port:51595
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856044532829500 09/01/22-00:01:38.460693
                    SID:2829500
                    Source Port:56044
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857828532829500 09/01/22-00:03:23.000023
                    SID:2829500
                    Source Port:57828
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864606532829500 09/01/22-00:02:41.903320
                    SID:2829500
                    Source Port:64606
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853273532829498 09/01/22-00:02:55.304130
                    SID:2829498
                    Source Port:53273
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856047532829500 09/01/22-00:01:38.529181
                    SID:2829500
                    Source Port:56047
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850626532026737 09/01/22-00:03:18.717464
                    SID:2026737
                    Source Port:50626
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863691532829498 09/01/22-00:03:21.687512
                    SID:2829498
                    Source Port:63691
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859825532026737 09/01/22-00:02:20.014612
                    SID:2026737
                    Source Port:59825
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855954532829500 09/01/22-00:03:25.612012
                    SID:2829500
                    Source Port:55954
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862428532026737 09/01/22-00:03:13.188986
                    SID:2026737
                    Source Port:62428
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861419532829498 09/01/22-00:02:03.004767
                    SID:2829498
                    Source Port:61419
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860474532829498 09/01/22-00:02:47.119975
                    SID:2829498
                    Source Port:60474
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864274532829498 09/01/22-00:03:00.057400
                    SID:2829498
                    Source Port:64274
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853853532026737 09/01/22-00:01:50.543832
                    SID:2026737
                    Source Port:53853
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855248532829498 09/01/22-00:03:03.486266
                    SID:2829498
                    Source Port:55248
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853432532829498 09/01/22-00:02:18.428585
                    SID:2829498
                    Source Port:53432
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853849532829498 09/01/22-00:01:59.483040
                    SID:2829498
                    Source Port:53849
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859586532026737 09/01/22-00:02:11.767488
                    SID:2026737
                    Source Port:59586
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860477532829498 09/01/22-00:02:47.180255
                    SID:2829498
                    Source Port:60477
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852743532026737 09/01/22-00:03:23.998658
                    SID:2026737
                    Source Port:52743
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849170532829500 09/01/22-00:02:32.467435
                    SID:2829500
                    Source Port:49170
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865325532026737 09/01/22-00:01:43.903174
                    SID:2026737
                    Source Port:65325
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857575532829498 09/01/22-00:01:53.271847
                    SID:2829498
                    Source Port:57575
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849879532829500 09/01/22-00:02:36.072251
                    SID:2829500
                    Source Port:49879
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859640532026737 09/01/22-00:01:39.971866
                    SID:2026737
                    Source Port:59640
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865109532829500 09/01/22-00:01:46.914019
                    SID:2829500
                    Source Port:65109
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863450532829498 09/01/22-00:02:35.496675
                    SID:2829498
                    Source Port:63450
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860646532829498 09/01/22-00:03:25.281760
                    SID:2829498
                    Source Port:60646
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854285532829500 09/01/22-00:03:33.695070
                    SID:2829500
                    Source Port:54285
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858915532829500 09/01/22-00:03:18.040653
                    SID:2829500
                    Source Port:58915
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864974532829500 09/01/22-00:03:05.683602
                    SID:2829500
                    Source Port:64974
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858482532829500 09/01/22-00:03:29.362481
                    SID:2829500
                    Source Port:58482
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864125532829498 09/01/22-00:02:44.347197
                    SID:2829498
                    Source Port:64125
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859437532026737 09/01/22-00:01:57.658266
                    SID:2026737
                    Source Port:59437
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857137532829498 09/01/22-00:01:34.192981
                    SID:2829498
                    Source Port:57137
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860819532829500 09/01/22-00:03:08.807703
                    SID:2829500
                    Source Port:60819
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864598532829498 09/01/22-00:02:22.069673
                    SID:2829498
                    Source Port:64598
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865388532026737 09/01/22-00:02:38.683294
                    SID:2026737
                    Source Port:65388
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852460532026737 09/01/22-00:03:02.922606
                    SID:2026737
                    Source Port:52460
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861361532829498 09/01/22-00:03:28.363595
                    SID:2829498
                    Source Port:61361
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865464532829500 09/01/22-00:03:37.331573
                    SID:2829500
                    Source Port:65464
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863566532026737 09/01/22-00:02:17.069143
                    SID:2026737
                    Source Port:63566
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849203532026737 09/01/22-00:02:46.656883
                    SID:2026737
                    Source Port:49203
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864972532829500 09/01/22-00:03:05.639386
                    SID:2829500
                    Source Port:64972
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853051532829498 09/01/22-00:02:15.015452
                    SID:2829498
                    Source Port:53051
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851995532026737 09/01/22-00:02:26.294405
                    SID:2026737
                    Source Port:51995
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851107532829500 09/01/22-00:03:01.623107
                    SID:2829500
                    Source Port:51107
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864969532829500 09/01/22-00:02:44.846895
                    SID:2829500
                    Source Port:64969
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852113532026737 09/01/22-00:03:20.304409
                    SID:2026737
                    Source Port:52113
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858121532829498 09/01/22-00:02:27.883460
                    SID:2829498
                    Source Port:58121
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857707532829500 09/01/22-00:01:42.707644
                    SID:2829500
                    Source Port:57707
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861420532829498 09/01/22-00:02:03.023139
                    SID:2829498
                    Source Port:61420
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860772532829498 09/01/22-00:01:45.515640
                    SID:2829498
                    Source Port:60772
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859379532829500 09/01/22-00:02:48.360270
                    SID:2829500
                    Source Port:59379
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860420532829498 09/01/22-00:03:32.361100
                    SID:2829498
                    Source Port:60420
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858306532026737 09/01/22-00:02:34.518930
                    SID:2026737
                    Source Port:58306
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857136532829498 09/01/22-00:01:34.170593
                    SID:2829498
                    Source Port:57136
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863692532829498 09/01/22-00:03:21.709351
                    SID:2829498
                    Source Port:63692
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851110532829500 09/01/22-00:03:01.687030
                    SID:2829500
                    Source Port:51110
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855651532829498 09/01/22-00:03:19.239137
                    SID:2829498
                    Source Port:55651
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861187532829498 09/01/22-00:02:52.669551
                    SID:2829498
                    Source Port:61187
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850789532026737 09/01/22-00:02:43.405655
                    SID:2026737
                    Source Port:50789
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864126532829498 09/01/22-00:02:44.367092
                    SID:2829498
                    Source Port:64126
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856045532829500 09/01/22-00:01:38.479108
                    SID:2829500
                    Source Port:56045
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849876532829500 09/01/22-00:02:36.017097
                    SID:2829500
                    Source Port:49876
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853430532829498 09/01/22-00:02:18.389778
                    SID:2829498
                    Source Port:53430
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864275532829498 09/01/22-00:03:00.076893
                    SID:2829498
                    Source Port:64275
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852746532026737 09/01/22-00:03:24.060420
                    SID:2026737
                    Source Port:52746
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865199532829500 09/01/22-00:02:04.790776
                    SID:2829500
                    Source Port:65199
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855643532829498 09/01/22-00:01:41.349610
                    SID:2829498
                    Source Port:55643
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865322532026737 09/01/22-00:01:43.838373
                    SID:2026737
                    Source Port:65322
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857389532829500 09/01/22-00:02:53.228134
                    SID:2829500
                    Source Port:57389
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852457532026737 09/01/22-00:03:02.822494
                    SID:2026737
                    Source Port:52457
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859766532026737 09/01/22-00:03:34.053456
                    SID:2026737
                    Source Port:59766
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850094532026737 09/01/22-00:03:38.722516
                    SID:2026737
                    Source Port:50094
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863689532829498 09/01/22-00:03:21.642301
                    SID:2829498
                    Source Port:63689
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864828532829500 09/01/22-00:02:24.814616
                    SID:2829500
                    Source Port:64828
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862427532026737 09/01/22-00:03:13.168037
                    SID:2026737
                    Source Port:62427
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858485532829500 09/01/22-00:03:30.012594
                    SID:2829500
                    Source Port:58485
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860586532026737 09/01/22-00:01:27.526553
                    SID:2026737
                    Source Port:60586
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860648532829498 09/01/22-00:03:25.320562
                    SID:2829498
                    Source Port:60648
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850231532026737 09/01/22-00:02:54.755739
                    SID:2026737
                    Source Port:50231
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859831532829500 09/01/22-00:02:55.995864
                    SID:2829500
                    Source Port:59831
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857138532829498 09/01/22-00:01:34.214783
                    SID:2829498
                    Source Port:57138
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865465532829500 09/01/22-00:03:37.351949
                    SID:2829500
                    Source Port:65465
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859641532026737 09/01/22-00:01:39.990388
                    SID:2026737
                    Source Port:59641
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859638532026737 09/01/22-00:01:39.931325
                    SID:2026737
                    Source Port:59638
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854435532829498 09/01/22-00:03:36.023381
                    SID:2829498
                    Source Port:54435
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860818532829500 09/01/22-00:03:08.745097
                    SID:2829500
                    Source Port:60818
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857576532829498 09/01/22-00:01:53.290249
                    SID:2829498
                    Source Port:57576
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849171532829500 09/01/22-00:02:32.489443
                    SID:2829500
                    Source Port:49171
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851144532829498 09/01/22-00:01:24.145242
                    SID:2829498
                    Source Port:51144
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852115532026737 09/01/22-00:03:20.348262
                    SID:2026737
                    Source Port:52115
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856620532026737 09/01/22-00:02:49.146584
                    SID:2026737
                    Source Port:56620
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851109532829500 09/01/22-00:03:01.665772
                    SID:2829500
                    Source Port:51109
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864379532829500 09/01/22-00:03:19.992460
                    SID:2829500
                    Source Port:64379
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864599532829498 09/01/22-00:02:22.089885
                    SID:2829498
                    Source Port:64599
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860821532829500 09/01/22-00:03:08.846909
                    SID:2829500
                    Source Port:60821
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849205532026737 09/01/22-00:02:46.696702
                    SID:2026737
                    Source Port:49205
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849878532829500 09/01/22-00:02:36.053729
                    SID:2829500
                    Source Port:49878
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853846532829498 09/01/22-00:01:59.423880
                    SID:2829498
                    Source Port:53846
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860091532829500 09/01/22-00:02:16.509694
                    SID:2829500
                    Source Port:60091
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859377532829500 09/01/22-00:02:48.283085
                    SID:2829500
                    Source Port:59377
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859824532026737 09/01/22-00:02:19.994370
                    SID:2026737
                    Source Port:59824
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864607532829500 09/01/22-00:02:41.921899
                    SID:2829500
                    Source Port:64607
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855249532829498 09/01/22-00:03:03.506251
                    SID:2829498
                    Source Port:55249
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864380532829500 09/01/22-00:03:20.011368
                    SID:2829500
                    Source Port:64380
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850092532026737 09/01/22-00:03:38.678470
                    SID:2026737
                    Source Port:50092
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853272532829498 09/01/22-00:02:55.282821
                    SID:2829498
                    Source Port:53272
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857392532829500 09/01/22-00:02:53.296910
                    SID:2829500
                    Source Port:57392
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858916532829500 09/01/22-00:03:18.060823
                    SID:2829500
                    Source Port:58916
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853053532829498 09/01/22-00:02:15.057233
                    SID:2829498
                    Source Port:53053
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864826532829500 09/01/22-00:02:24.770961
                    SID:2829500
                    Source Port:64826
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853625532026737 09/01/22-00:02:01.788642
                    SID:2026737
                    Source Port:53625
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851596532026737 09/01/22-00:03:26.954769
                    SID:2026737
                    Source Port:51596
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862435532026737 09/01/22-00:02:57.512287
                    SID:2026737
                    Source Port:62435
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853852532026737 09/01/22-00:01:50.489647
                    SID:2026737
                    Source Port:53852
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862429532026737 09/01/22-00:03:13.209944
                    SID:2026737
                    Source Port:62429
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860584532026737 09/01/22-00:01:27.482735
                    SID:2026737
                    Source Port:60584
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864124532829498 09/01/22-00:02:44.327136
                    SID:2829498
                    Source Port:64124
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861189532829498 09/01/22-00:02:52.764321
                    SID:2829498
                    Source Port:61189
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.849168532829500 09/01/22-00:02:32.423642
                    SID:2829500
                    Source Port:49168
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863451532829498 09/01/22-00:02:35.516825
                    SID:2829498
                    Source Port:63451
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850625532026737 09/01/22-00:03:18.697259
                    SID:2026737
                    Source Port:50625
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854286532829500 09/01/22-00:03:33.715891
                    SID:2829500
                    Source Port:54286
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860769532829498 09/01/22-00:01:45.451637
                    SID:2829498
                    Source Port:60769
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852744532026737 09/01/22-00:03:24.019183
                    SID:2026737
                    Source Port:52744
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855641532829498 09/01/22-00:01:41.302395
                    SID:2829498
                    Source Port:55641
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853469532829500 09/01/22-00:02:00.624524
                    SID:2829500
                    Source Port:53469
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860770532829498 09/01/22-00:01:45.473540
                    SID:2829498
                    Source Port:60770
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853470532829500 09/01/22-00:02:00.646017
                    SID:2829500
                    Source Port:53470
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865324532026737 09/01/22-00:01:43.883100
                    SID:2026737
                    Source Port:65324
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853851532026737 09/01/22-00:01:50.267332
                    SID:2026737
                    Source Port:53851
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.862433532026737 09/01/22-00:02:57.467935
                    SID:2026737
                    Source Port:62433
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859584532026737 09/01/22-00:02:11.726579
                    SID:2026737
                    Source Port:59584
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860475532829498 09/01/22-00:02:47.139274
                    SID:2829498
                    Source Port:60475
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864123532829498 09/01/22-00:02:44.306860
                    SID:2829498
                    Source Port:64123
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858483532829500 09/01/22-00:03:29.383909
                    SID:2829500
                    Source Port:58483
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856618532026737 09/01/22-00:02:49.105935
                    SID:2026737
                    Source Port:56618
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855247532829498 09/01/22-00:03:03.466197
                    SID:2829498
                    Source Port:55247
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861362532829498 09/01/22-00:03:28.520063
                    SID:2829498
                    Source Port:61362
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861129532829498 09/01/22-00:03:15.922110
                    SID:2829498
                    Source Port:61129
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857574532829498 09/01/22-00:01:53.251460
                    SID:2829498
                    Source Port:57574
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864597532829498 09/01/22-00:02:22.051454
                    SID:2829498
                    Source Port:64597
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858303532026737 09/01/22-00:02:34.435886
                    SID:2026737
                    Source Port:58303
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865387532026737 09/01/22-00:02:38.660218
                    SID:2026737
                    Source Port:65387
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853274532829498 09/01/22-00:02:55.325848
                    SID:2829498
                    Source Port:53274
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851594532026737 09/01/22-00:03:26.907030
                    SID:2026737
                    Source Port:51594
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863565532026737 09/01/22-00:02:17.049623
                    SID:2026737
                    Source Port:63565
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850627532026737 09/01/22-00:03:18.737468
                    SID:2026737
                    Source Port:50627
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858124532829498 09/01/22-00:02:27.993076
                    SID:2829498
                    Source Port:58124
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850786532026737 09/01/22-00:02:43.346779
                    SID:2026737
                    Source Port:50786
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850233532026737 09/01/22-00:02:54.805593
                    SID:2026737
                    Source Port:50233
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854287532829500 09/01/22-00:03:33.736226
                    SID:2829500
                    Source Port:54287
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864605532829500 09/01/22-00:02:41.882665
                    SID:2829500
                    Source Port:64605
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864604532829500 09/01/22-00:02:41.862105
                    SID:2829500
                    Source Port:64604
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855246532829498 09/01/22-00:03:03.448041
                    SID:2829498
                    Source Port:55246
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855953532829500 09/01/22-00:03:25.594151
                    SID:2829500
                    Source Port:55953
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858484532829500 09/01/22-00:03:29.402067
                    SID:2829500
                    Source Port:58484
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857139532829498 09/01/22-00:01:34.235761
                    SID:2829498
                    Source Port:57139
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859435532026737 09/01/22-00:01:57.617695
                    SID:2026737
                    Source Port:59435
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863564532026737 09/01/22-00:02:17.026690
                    SID:2026737
                    Source Port:63564
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852958532829500 09/01/22-00:01:25.347118
                    SID:2829500
                    Source Port:52958
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860092532829500 09/01/22-00:02:16.532570
                    SID:2829500
                    Source Port:60092
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863690532829498 09/01/22-00:03:21.664385
                    SID:2829498
                    Source Port:63690
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858304532026737 09/01/22-00:02:34.463044
                    SID:2026737
                    Source Port:58304
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855459532829498 09/01/22-00:03:07.276022
                    SID:2829498
                    Source Port:55459
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860476532829498 09/01/22-00:02:47.160135
                    SID:2829498
                    Source Port:60476
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865110532829500 09/01/22-00:01:46.934130
                    SID:2829500
                    Source Port:65110
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.863449532829498 09/01/22-00:02:35.476503
                    SID:2829498
                    Source Port:63449
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852960532829500 09/01/22-00:01:25.385522
                    SID:2829500
                    Source Port:52960
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857390532829500 09/01/22-00:02:53.250639
                    SID:2829500
                    Source Port:57390
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857573532829498 09/01/22-00:01:53.226527
                    SID:2829498
                    Source Port:57573
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.865514532829500 09/01/22-00:02:19.450712
                    SID:2829500
                    Source Port:65514
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861131532829498 09/01/22-00:03:15.960645
                    SID:2829498
                    Source Port:61131
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851141532829498 09/01/22-00:01:24.068248
                    SID:2829498
                    Source Port:51141
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853052532829498 09/01/22-00:02:15.036327
                    SID:2829498
                    Source Port:53052
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861128532829498 09/01/22-00:03:15.903464
                    SID:2829498
                    Source Port:61128
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852745532026737 09/01/22-00:03:24.040007
                    SID:2026737
                    Source Port:52745
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.854156532829498 09/01/22-00:02:39.730598
                    SID:2829498
                    Source Port:54156
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857709532829500 09/01/22-00:01:42.750967
                    SID:2829500
                    Source Port:57709
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861363532829498 09/01/22-00:03:28.538480
                    SID:2829498
                    Source Port:61363
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853308532829500 09/01/22-00:01:54.898418
                    SID:2829500
                    Source Port:53308
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860585532026737 09/01/22-00:01:27.503002
                    SID:2026737
                    Source Port:60585
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860771532829498 09/01/22-00:01:45.495695
                    SID:2829498
                    Source Port:60771
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860422532829498 09/01/22-00:03:32.403375
                    SID:2829498
                    Source Port:60422
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.850093532026737 09/01/22-00:03:38.699985
                    SID:2026737
                    Source Port:50093
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853041532026737 09/01/22-00:03:06.319112
                    SID:2026737
                    Source Port:53041
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851994532026737 09/01/22-00:02:26.273853
                    SID:2026737
                    Source Port:51994
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.858917532829500 09/01/22-00:03:18.082512
                    SID:2829500
                    Source Port:58917
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864827532829500 09/01/22-00:02:24.792802
                    SID:2829500
                    Source Port:64827
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.860820532829500 09/01/22-00:03:08.828384
                    SID:2829500
                    Source Port:60820
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851997532026737 09/01/22-00:02:26.333413
                    SID:2026737
                    Source Port:51997
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.861188532829498 09/01/22-00:02:52.691629
                    SID:2829498
                    Source Port:61188
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859832532829500 09/01/22-00:02:56.017085
                    SID:2829500
                    Source Port:59832
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864600532829498 09/01/22-00:02:22.108885
                    SID:2829498
                    Source Port:64600
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855640532829498 09/01/22-00:01:41.280696
                    SID:2829498
                    Source Port:55640
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855462532829498 09/01/22-00:03:07.346617
                    SID:2829498
                    Source Port:55462
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859639532026737 09/01/22-00:01:39.951734
                    SID:2026737
                    Source Port:59639
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855653532829498 09/01/22-00:03:19.277165
                    SID:2829498
                    Source Port:55653
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.857826532829500 09/01/22-00:03:22.956962
                    SID:2829500
                    Source Port:57826
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853847532829498 09/01/22-00:01:59.444336
                    SID:2829498
                    Source Port:53847
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851108532829500 09/01/22-00:03:01.644612
                    SID:2829500
                    Source Port:51108
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.852459532026737 09/01/22-00:03:02.900983
                    SID:2026737
                    Source Port:52459
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.864381532829500 09/01/22-00:03:20.034172
                    SID:2829500
                    Source Port:64381
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.853626532026737 09/01/22-00:02:01.814516
                    SID:2026737
                    Source Port:53626
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.859823532026737 09/01/22-00:02:19.973756
                    SID:2026737
                    Source Port:59823
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.851892532026737 09/01/22-00:03:31.996527
                    SID:2026737
                    Source Port:51892
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.856621532026737 09/01/22-00:02:49.211680
                    SID:2026737
                    Source Port:56621
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.38.8.8.855956532829500 09/01/22-00:03:25.650230
                    SID:2829500
                    Source Port:55956
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: 9gkAKTWOXp.exeVirustotal: Detection: 81%Perma Link
                    Source: 9gkAKTWOXp.exeMetadefender: Detection: 72%Perma Link
                    Source: 9gkAKTWOXp.exeReversingLabs: Detection: 100%
                    Source: 9gkAKTWOXp.exeAvira: detected
                    Source: http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144deAvira URL Cloud: Label: malware
                    Source: http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144deAvira URL Cloud: Label: phishing
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeAvira: detection malicious, Label: TR/Crypt.XPACK.Gen3
                    Source: 9gkAKTWOXp.exeJoe Sandbox ML: detected
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeJoe Sandbox ML: detected
                    Source: 13.0.vkspii.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 1.2.9gkAKTWOXp.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 13.2.vkspii.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 21.2.vkspii.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 1.0.9gkAKTWOXp.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 21.0.vkspii.exe.400000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00405750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00405D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004048A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00407DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00405540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004048A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00405540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00405750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00405D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00407DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004048A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00405540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00405750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00405D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00407DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: 9gkAKTWOXp.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 9gkAKTWOXp.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: z:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: x:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: v:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: t:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: r:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: p:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: n:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: l:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: j:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: h:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: f:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: b:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: y:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: w:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: u:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: s:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: q:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: o:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: m:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: k:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: i:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: g:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: e:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile opened: a:
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,

                    Networking

                    barindex
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:51141 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:51142 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:51143 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:51144 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:52957 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:52958 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:52959 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:52960 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:60584 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:60585 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:60586 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:60587 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57136 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57137 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57138 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57139 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:56044 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:56045 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:56046 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:56047 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59638 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59639 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59640 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59641 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55640 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55641 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55642 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55643 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57706 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57707 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57708 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57709 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65322 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65323 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65324 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65325 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60769 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60770 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60771 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60772 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65109 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65110 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65111 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65112 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53850 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53851 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53852 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53853 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57573 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57574 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57575 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:57576 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53307 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53308 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53309 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53310 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59435 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59436 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59437 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59438 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53846 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53847 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53848 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53849 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53468 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53469 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53470 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:53471 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53625 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53626 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53627 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53628 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61418 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61419 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61420 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61421 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65198 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65199 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65200 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65201 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59583 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59584 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59585 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59586 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53051 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53052 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53053 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53054 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60090 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60091 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60092 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60093 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:63564 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:63565 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:63566 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:63567 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53430 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53431 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53432 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53433 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65513 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65514 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65515 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65516 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59822 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59823 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59824 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59825 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64597 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64598 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64599 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64600 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64825 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64826 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64827 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64828 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51994 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51995 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51996 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51997 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:58121 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:58122 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:58123 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:58124 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49168 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49169 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49170 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49171 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:58303 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:58304 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:58305 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:58306 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63448 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63449 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63450 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63451 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49876 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49877 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49878 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:49879 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65387 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65388 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65389 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:65390 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54155 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54156 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54157 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54158 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64604 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64605 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64606 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64607 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50786 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50787 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50788 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50789 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64123 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64124 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64125 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64126 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64969 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64970 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64971 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64972 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:49203 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:49204 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:49205 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:49206 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60474 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60475 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60476 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60477 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59376 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59377 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59378 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59379 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:56618 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:56619 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:56620 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:56621 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61186 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61187 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61188 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61189 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57389 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57390 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57391 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57392 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50230 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50231 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50232 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50233 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53271 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53272 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53273 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:53274 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59829 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59830 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59831 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:59832 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62433 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62434 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62435 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62436 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64273 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64274 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64275 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:64276 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:51107 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:51108 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:51109 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:51110 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52457 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52458 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52459 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52460 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55246 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55247 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55248 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55249 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64973 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64974 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53039 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53040 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53041 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:53042 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55459 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55460 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55461 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55462 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60818 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60819 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60820 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:60821 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62426 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62427 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62428 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:62429 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61128 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61129 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61130 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61131 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58914 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58915 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58916 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58917 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50624 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50625 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50626 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50627 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55651 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55652 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55653 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:55654 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64378 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64379 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64380 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:64381 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52112 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52113 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52114 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52115 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63689 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63690 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63691 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:63692 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57826 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57827 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57828 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:57829 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52743 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52744 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52745 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:52746 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60646 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60647 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60648 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60649 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:55953 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:55954 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:55955 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:55956 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51594 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51595 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51596 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51597 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61361 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61362 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61363 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:61364 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58482 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58483 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58484 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:58485 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51891 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51892 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51893 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:51894 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60420 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60421 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60422 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:60423 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:54285 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:54286 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:54287 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:54288 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59765 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59766 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59767 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:59768 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54433 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54434 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54435 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.3:54436 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65463 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65464 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65465 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.3:65466 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50092 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50093 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50094 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.3:50095 -> 8.8.8.8:53
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004068F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: 9gkAKTWOXp.exe, 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: vkspii.exe, 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: vkspii.exe, 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: 9gkAKTWOXp.exeString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: 9gkAKTWOXp.exeString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: 9gkAKTWOXp.exeString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: 9gkAKTWOXp.exeString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: 9gkAKTWOXp.exeString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: 9gkAKTWOXp.exeString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: vkspii.exe.1.drString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: vkspii.exe.1.drString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: vkspii.exe.1.drString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: vkspii.exe.1.drString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: vkspii.exe.1.drString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: vkspii.exe.1.drString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: http://gdcbghvjyqy7jclk.onion/e644d32fec6144de
                    Source: 9gkAKTWOXp.exe, vkspii.exe.1.drString found in binary or memory: https://www.torproject.org/
                    Source: unknownDNS traffic detected: queries for: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00407A00 lstrcatW,InternetCloseHandle,InternetConnectW,VirtualAlloc,wsprintfW,HttpOpenRequestW,HttpAddRequestHeadersW,HttpSendRequestW,InternetReadFile,InternetReadFile,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,VirtualFree,

                    Spam, unwanted Advertisements and Ransom Demands

                    barindex
                    Source: Yara matchFile source: 9gkAKTWOXp.exe, type: SAMPLE
                    Source: Yara matchFile source: 13.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 1.2.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 13.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 21.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 1.0.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 21.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0000000D.00000002.295326787.000000000040E000.00000004.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000015.00000002.305269157.000000000040E000.00000004.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: 9gkAKTWOXp.exe PID: 4664, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: vkspii.exe PID: 6028, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: vkspii.exe PID: 4024, type: MEMORYSTR
                    Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, type: DROPPED
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00406000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: nslookup.exeProcess created: 43

                    System Summary

                    barindex
                    Source: 9gkAKTWOXp.exe, type: SAMPLEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 13.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 1.2.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 13.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 21.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 1.0.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 21.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, type: DROPPEDMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 9gkAKTWOXp.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 9gkAKTWOXp.exe, type: SAMPLEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 9gkAKTWOXp.exe, type: SAMPLEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 13.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 13.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 1.2.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 1.2.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 13.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 13.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 21.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 1.0.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 21.2.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 1.0.9gkAKTWOXp.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 21.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 21.0.vkspii.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, type: DROPPEDMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, type: DROPPEDMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00402000
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00407EE0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00402000
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_00407EE0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00402000
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_00407EE0
                    Source: 9gkAKTWOXp.exeVirustotal: Detection: 81%
                    Source: 9gkAKTWOXp.exeMetadefender: Detection: 72%
                    Source: 9gkAKTWOXp.exeReversingLabs: Detection: 100%
                    Source: 9gkAKTWOXp.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
                    Source: unknownProcess created: C:\Users\user\Desktop\9gkAKTWOXp.exe "C:\Users\user\Desktop\9gkAKTWOXp.exe"
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe "C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe"
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe "C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe"
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeJump to behavior
                    Source: classification engineClassification label: mal100.rans.troj.evad.winEXE@127/2@529/0
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00406D90 VirtualAlloc,VirtualAlloc,GetUserNameW,VirtualAlloc,GetComputerNameW,wsprintfW,VirtualAlloc,wsprintfW,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,VirtualFree,VirtualAlloc,VirtualAlloc,wsprintfW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrcmpiW,wsprintfW,wsprintfW,VirtualFree,VirtualAlloc,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,wsprintfW,GetNativeSystemInfo,VirtualAlloc,wsprintfW,VirtualAlloc,VirtualAlloc,GetWindowsDirectoryW,GetVolumeInformationW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrlenW,wsprintfW,lstrcatW,lstrcatW,GetModuleHandleW,GetProcAddress,lstrlenW,VirtualFree,lstrcatW,VirtualAlloc,GetDriveTypeW,lstrcatW,lstrcatW,lstrcatW,GetDiskFreeSpaceW,lstrlenW,wsprintfW,wsprintfW,lstrlenW,lstrlenW,wsprintfW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00404640 CreateToolhelp32Snapshot,VirtualAlloc,Process32FirstW,CloseHandle,lstrcmpiW,OpenProcess,TerminateProcess,CloseHandle,CloseHandle,CloseHandle,Process32NextW,VirtualFree,FindCloseChangeNotification,
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5972:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5360:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1976:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3196:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4272:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5500:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4996:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4184:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5116:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5956:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3184:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4820:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1328:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3880:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5920:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5460:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1944:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1360:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5816:120:WilError_01
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeMutant created: \Sessions\1\BaseNamedObjects\Global\pc_group=WORKGROUP&ransom_id=66326910ce147b1b
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5208:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2140:120:WilError_01
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: Window RecorderWindow detected: More than 3 window changes detected
                    Source: 9gkAKTWOXp.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeJump to dropped file
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce qfkhrdewlalJump to behavior
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce qfkhrdewlalJump to behavior
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce qfkhrdewlalJump to behavior
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce qfkhrdewlalJump to behavior
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exe TID: 4584Thread sleep count: 80 > 30
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exe TID: 4584Thread sleep time: -800000s >= -30000s
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeEvaded block: after key decision
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeEvaded block: after key decision
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: EnumDeviceDrivers,K32EnumDeviceDrivers,VirtualAlloc,K32EnumDeviceDrivers,K32GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: EnumDeviceDrivers,EnumDeviceDrivers,VirtualAlloc,EnumDeviceDrivers,GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: EnumDeviceDrivers,EnumDeviceDrivers,VirtualAlloc,EnumDeviceDrivers,GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 13_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004066F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeCode function: 21_2_004064A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeSystem information queried: ModuleInformation
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00407C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00405050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00403A60 AllocateAndInitializeSid,GetModuleHandleA,GetProcAddress,FreeSid,
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00408BC0 cpuid
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
                    Source: C:\Users\user\Desktop\9gkAKTWOXp.exeCode function: 1_2_00406D90 VirtualAlloc,VirtualAlloc,GetUserNameW,VirtualAlloc,GetComputerNameW,wsprintfW,VirtualAlloc,wsprintfW,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,VirtualFree,VirtualAlloc,VirtualAlloc,wsprintfW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrcmpiW,wsprintfW,wsprintfW,VirtualFree,VirtualAlloc,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,wsprintfW,GetNativeSystemInfo,VirtualAlloc,wsprintfW,VirtualAlloc,VirtualAlloc,GetWindowsDirectoryW,GetVolumeInformationW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrlenW,wsprintfW,lstrcatW,lstrcatW,GetModuleHandleW,GetProcAddress,lstrlenW,VirtualFree,lstrcatW,VirtualAlloc,GetDriveTypeW,lstrcatW,lstrcatW,lstrcatW,GetDiskFreeSpaceW,lstrlenW,wsprintfW,wsprintfW,lstrlenW,lstrlenW,wsprintfW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,VirtualFree,
                    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                    1
                    Replication Through Removable Media
                    2
                    Native API
                    1
                    Registry Run Keys / Startup Folder
                    11
                    Process Injection
                    1
                    Masquerading
                    OS Credential Dumping1
                    Security Software Discovery
                    1
                    Replication Through Removable Media
                    11
                    Archive Collected Data
                    Exfiltration Over Other Network Medium2
                    Encrypted Channel
                    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
                    Data Encrypted for Impact
                    Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                    Registry Run Keys / Startup Folder
                    1
                    Virtualization/Sandbox Evasion
                    LSASS Memory1
                    Virtualization/Sandbox Evasion
                    Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
                    Ingress Tool Transfer
                    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)11
                    Process Injection
                    Security Account Manager1
                    Process Discovery
                    SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
                    Non-Application Layer Protocol
                    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
                    Software Packing
                    NTDS11
                    Peripheral Device Discovery
                    Distributed Component Object ModelInput CaptureScheduled Transfer1
                    Application Layer Protocol
                    SIM Card SwapCarrier Billing Fraud
                    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
                    Account Discovery
                    SSHKeyloggingData Transfer Size Limits1
                    Proxy
                    Manipulate Device CommunicationManipulate App Store Rankings or Ratings
                    Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain Credentials1
                    System Owner/User Discovery
                    VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                    External Remote ServicesScheduled TaskStartup ItemsStartup ItemsCompile After DeliveryDCSync1
                    Remote System Discovery
                    Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                    Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem2
                    System Network Configuration Discovery
                    Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                    Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Masquerading/etc/passwd and /etc/shadow1
                    System Network Connections Discovery
                    Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
                    Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)Invalid Code SignatureNetwork Sniffing1
                    File and Directory Discovery
                    Taint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
                    Compromise Software Dependencies and Development ToolsWindows Command ShellCronCronRight-to-Left OverrideInput Capture44
                    System Information Discovery
                    Replication Through Removable MediaRemote Data StagingExfiltration Over Physical MediumMail ProtocolsService Stop
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet
                    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 694569 Sample: 9gkAKTWOXp.exe Startdate: 01/09/2022 Architecture: WINDOWS Score: 100 57 nomoreransom.bit 2->57 59 gandcrab.bit 2->59 61 3 other IPs or domains 2->61 65 Snort IDS alert for network traffic 2->65 67 Malicious sample detected (through community Yara rule) 2->67 69 Antivirus detection for URL or domain 2->69 71 5 other signatures 2->71 8 9gkAKTWOXp.exe 1 28 2->8         started        13 vkspii.exe 2->13         started        15 vkspii.exe 2->15         started        signatures3 process4 dnsIp5 63 ipv4bot.whatismyipaddress.com 8->63 40 C:\Users\user\AppData\Roaming\...\vkspii.exe, PE32 8->40 dropped 73 Contains functionality to determine the online IP of the system 8->73 75 May check the online IP address of the machine 8->75 77 Uses nslookup.exe to query domains 8->77 17 nslookup.exe 1 8->17         started        20 nslookup.exe 1 8->20         started        22 nslookup.exe 1 8->22         started        24 19 other processes 8->24 79 Antivirus detection for dropped file 13->79 81 Machine Learning detection for dropped file 13->81 file6 signatures7 process8 dnsIp9 42 dns1.soprodns.ru 17->42 45 nomoreransom.bit 17->45 47 8.8.8.8.in-addr.arpa 17->47 26 conhost.exe 17->26         started        51 3 other IPs or domains 20->51 28 conhost.exe 20->28         started        53 3 other IPs or domains 22->53 30 conhost.exe 22->30         started        49 nomoreransom.bit 24->49 55 57 other IPs or domains 24->55 32 conhost.exe 24->32         started        34 conhost.exe 24->34         started        36 conhost.exe 24->36         started        38 16 other processes 24->38 signatures10 83 May check the online IP address of the machine 42->83 process11

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    9gkAKTWOXp.exe81%VirustotalBrowse
                    9gkAKTWOXp.exe73%MetadefenderBrowse
                    9gkAKTWOXp.exe100%ReversingLabsWin32.Ransomware.GandCrab
                    9gkAKTWOXp.exe100%AviraTR/Crypt.XPACK.Gen3
                    9gkAKTWOXp.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLink
                    C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe100%AviraTR/Crypt.XPACK.Gen3
                    C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLinkDownload
                    13.0.vkspii.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    1.2.9gkAKTWOXp.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    13.2.vkspii.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    21.2.vkspii.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    1.0.9gkAKTWOXp.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    21.0.vkspii.exe.400000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    SourceDetectionScannerLabelLink
                    emsisoft.bit0%VirustotalBrowse
                    nomoreransom.bit1%VirustotalBrowse
                    SourceDetectionScannerLabelLink
                    http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de100%Avira URL Cloudmalware
                    http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de100%Avira URL Cloudphishing
                    http://gdcbghvjyqy7jclk.onion/e644d32fec6144de0%Avira URL Cloudsafe
                    NameIPActiveMaliciousAntivirus DetectionReputation
                    emsisoft.bit
                    unknown
                    unknowntrueunknown
                    ipv4bot.whatismyipaddress.com
                    unknown
                    unknownfalse
                      high
                      nomoreransom.bit
                      unknown
                      unknowntrueunknown
                      gandcrab.bit
                      unknown
                      unknowntrue
                        unknown
                        dns1.soprodns.ru
                        unknown
                        unknowntrue
                          unknown
                          8.8.8.8.in-addr.arpa
                          unknown
                          unknownfalse
                            unknown
                            NameSourceMaliciousAntivirus DetectionReputation
                            https://www.torproject.org/9gkAKTWOXp.exe, vkspii.exe.1.drfalse
                              high
                              http://gdcbghvjyqy7jclk.onion.guide/e644d32fec6144de9gkAKTWOXp.exe, vkspii.exe.1.drfalse
                                high
                                http://gdcbghvjyqy7jclk.onion.plus/e644d32fec6144de9gkAKTWOXp.exe, vkspii.exe.1.drfalse
                                  high
                                  http://gdcbghvjyqy7jclk.onion.casa/e644d32fec6144de9gkAKTWOXp.exe, vkspii.exe.1.drtrue
                                  • Avira URL Cloud: malware
                                  unknown
                                  http://gdcbghvjyqy7jclk.onion.top/e644d32fec6144de9gkAKTWOXp.exe, vkspii.exe.1.drtrue
                                  • Avira URL Cloud: phishing
                                  unknown
                                  http://gdcbghvjyqy7jclk.onion/e644d32fec6144de9gkAKTWOXp.exe, vkspii.exe.1.drtrue
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://gdcbghvjyqy7jclk.onion.rip/e644d32fec6144de9gkAKTWOXp.exe, vkspii.exe.1.drfalse
                                    high
                                    No contacted IP infos
                                    Joe Sandbox Version:35.0.0 Citrine
                                    Analysis ID:694569
                                    Start date and time:2022-09-01 00:00:17 +02:00
                                    Joe Sandbox Product:CloudBasic
                                    Overall analysis duration:0h 8m 5s
                                    Hypervisor based Inspection enabled:false
                                    Report type:light
                                    Sample file name:9gkAKTWOXp.exe
                                    Cookbook file name:default.jbs
                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                    Number of analysed new started processes analysed:62
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • HDC enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Detection:MAL
                                    Classification:mal100.rans.troj.evad.winEXE@127/2@529/0
                                    EGA Information:
                                    • Successful, ratio: 100%
                                    HDC Information:
                                    • Successful, ratio: 100% (good quality ratio 96.9%)
                                    • Quality average: 84.4%
                                    • Quality standard deviation: 23.4%
                                    HCA Information:
                                    • Successful, ratio: 99%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    Cookbook Comments:
                                    • Found application associated with file extension: .exe
                                    • Adjust boot time
                                    • Enable AMSI
                                    • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, svchost.exe
                                    • Excluded IPs from analysis (whitelisted): 20.82.228.9, 20.82.154.241
                                    • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, client.wns.windows.com, rp-consumer-prod-displaycatalog-geomap.trafficmanager.net, fs.microsoft.com, eudb.ris.api.iris.microsoft.com, neus2c-displaycatalog.frontdoor.bigcatalog.commerce.microsoft.com, ctldl.windowsupdate.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com, displaycatalog-rp.md.mp.microsoft.com.akadns.net, neus1c-displaycatalog.frontdoor.bigcatalog.commerce.microsoft.com
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size exceeded maximum capacity and may have missing behavior information.
                                    • Report size getting too big, too many NtOpenKeyEx calls found.
                                    • Report size getting too big, too many NtQueryValueKey calls found.
                                    TimeTypeDescription
                                    00:01:18AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce qfkhrdewlal "C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe"
                                    00:01:22API Interceptor80x Sleep call for process: 9gkAKTWOXp.exe modified
                                    00:01:26AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\RunOnce qfkhrdewlal "C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe"
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    Process:C:\Users\user\Desktop\9gkAKTWOXp.exe
                                    File Type:data
                                    Category:dropped
                                    Size (bytes):2218
                                    Entropy (8bit):0.0
                                    Encrypted:false
                                    SSDEEP:3::
                                    MD5:F97F9E17EAFDD0105A4E11BAFDE04B40
                                    SHA1:BA06A7ABE986A61B71889B80A6F9B02B22D40667
                                    SHA-256:4783424121E6C2F870DC931B374D20C62C764EDDC5769D2F536609ADC1226ABB
                                    SHA-512:778C4AAB55F6F0FE44DBC9A97F53B59EC8ED2E35901F77AFEBAEA57C738AD301412760709AB909B51335DDD7676CD8F8C1410C5751F2EF5CC74282BCD6C5F50E
                                    Malicious:false
                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                    Process:C:\Users\user\Desktop\9gkAKTWOXp.exe
                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                    Category:dropped
                                    Size (bytes):75264
                                    Entropy (8bit):4.804275425971981
                                    Encrypted:false
                                    SSDEEP:1536:ugSeGDjtQhnwmmB0yjMqqUM2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:uMSjOnrmBbMqqMmr3IdE8we0Avu5r++N
                                    MD5:551DA842D854798E9D42602EB420BD96
                                    SHA1:B44E2B41F17EC56135BE9ED3F545025078E912EC
                                    SHA-256:F54A4A6120B5236D4621F4D38F496E2025A352D19A191799DB53F38E60C9C7EA
                                    SHA-512:877A04DC6730634E59C9395291CE80AD4F049CA1C24AE7D064129AC5DE5F65A67A2F1FABA6486353CC2676D838CEB7C4C6018456A8B7AF7F2BB703FD6865489C
                                    Malicious:true
                                    Yara Hits:
                                    • Rule: SUSP_RANSOMWARE_Indicator_Jul20, Description: Detects ransomware indicator, Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, Author: Florian Roth
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, Author: Joe Security
                                    • Rule: Gandcrab, Description: Gandcrab Payload, Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, Author: kevoreilly
                                    Antivirus:
                                    • Antivirus: Avira, Detection: 100%
                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                    Preview:MZ......................@...............................................!..L.!This @i...5m cannot be run in DOS mode....$.......AU@..4...4...4..Ce...4..Ce...4...f...4...4...4...L...4...4/.4...f...4...f...4...f...4..Rich.4..................PE..L...].vZ.............................J............@..........................`............@.................................p........@.......................P.......................................................................................text............................... ..`.rdata..............................@....data........ ......................@....CRT.........0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................................
                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                    Entropy (8bit):4.804368489925485
                                    TrID:
                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                    • DOS Executable Generic (2002/1) 0.02%
                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                    File name:9gkAKTWOXp.exe
                                    File size:75264
                                    MD5:74e135b472b7496b371ce3ba3acfeea8
                                    SHA1:b64fdd870ff28291b8347317a838a5fb210a6056
                                    SHA256:d093322a612760cb00ae6fb4c453851ba26f59f2e6a0920b5871a28bbddf9355
                                    SHA512:c7c3fc7db77b5d450b857917b4157c2e1d2dcc41e18e248e50139711a04ee9893be26679e969a769113349ef9122387333ec7fe57d4d84dc541a4c9f9e25300b
                                    SSDEEP:1536:kgSeGDjtQhnwmmB0yjMqqUM2mr3IdE8mne0Avu5r++yy7CA7GcIaapavdv:kMSjOnrmBbMqqMmr3IdE8we0Avu5r++N
                                    TLSH:787317053AE18133FAF2F9B265B869E1587B7E541B287ADF00E8043E19275E25D30B4F
                                    File Content Preview:MZ......................@...............................................!..L.!This ..^.:_m cannot be run in DOS mode....$.......AU@..4...4...4..Ce...4..Ce...4...f...4...4...4...L...4...4/..4...f...4...f...4...f...4..Rich.4..................PE..L...].vZ...
                                    Icon Hash:00828e8e8686b000
                                    Entrypoint:0x404af0
                                    Entrypoint Section:.text
                                    Digitally signed:false
                                    Imagebase:0x400000
                                    Subsystem:windows gui
                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                    Time Stamp:0x5A76065D [Sat Feb 3 18:58:37 2018 UTC]
                                    TLS Callbacks:
                                    CLR (.Net) Version:
                                    OS Version Major:5
                                    OS Version Minor:1
                                    File Version Major:5
                                    File Version Minor:1
                                    Subsystem Version Major:5
                                    Subsystem Version Minor:1
                                    Import Hash:40306b615af659fc1f93cfb121cc38d9
                                    Instruction
                                    push ebp
                                    mov ebp, esp
                                    call 00007F7110ADC4ADh
                                    push 00000000h
                                    call dword ptr [00409168h]
                                    pop ebp
                                    ret
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    push ebp
                                    mov ebp, esp
                                    sub esp, 5Ch
                                    push esi
                                    push 00000044h
                                    lea eax, dword ptr [ebp-58h]
                                    xorps xmm0, xmm0
                                    push 00000000h
                                    push eax
                                    mov esi, ecx
                                    movdqu dqword ptr [ebp-10h], xmm0
                                    call 00007F7110AE0707h
                                    mov eax, dword ptr [00412B0Ch]
                                    add esp, 0Ch
                                    mov dword ptr [ebp-18h], eax
                                    mov dword ptr [ebp-1Ch], eax
                                    mov eax, dword ptr [00412B08h]
                                    or dword ptr [ebp-2Ch], 00000101h
                                    mov dword ptr [ebp-20h], eax
                                    xor eax, eax
                                    mov word ptr [ebp-28h], ax
                                    lea eax, dword ptr [ebp-10h]
                                    push eax
                                    lea eax, dword ptr [ebp-58h]
                                    mov dword ptr [ebp-58h], 00000044h
                                    push eax
                                    push 00000000h
                                    push 00000000h
                                    push 00000000h
                                    push 00000001h
                                    push 00000000h
                                    push 00000000h
                                    push esi
                                    push 00000000h
                                    call dword ptr [00409164h]
                                    test eax, eax
                                    jne 00007F7110ADC70Dh
                                    call dword ptr [00409064h]
                                    pop esi
                                    mov esp, ebp
                                    pop ebp
                                    ret
                                    push dword ptr [ebp-10h]
                                    mov esi, dword ptr [0040910Ch]
                                    call esi
                                    push dword ptr [ebp-0Ch]
                                    call esi
                                    pop esi
                                    mov esp, ebp
                                    pop ebp
                                    ret
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    int3
                                    push ebp
                                    mov ebp, esp
                                    sub esp, 10h
                                    movq xmm0, qword ptr [0040FF2Ch]
                                    mov al, byte ptr [0040FF34h]
                                    push ebx
                                    mov ebx, dword ptr [ebp+08h]
                                    Programming Language:
                                    • [ C ] VS2013 build 21005
                                    • [IMP] VS2008 SP1 build 30729
                                    • [RES] VS2013 build 21005
                                    • [LNK] VS2013 build 21005
                                    NameVirtual AddressVirtual Size Is in Section
                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x109700xb4.rdata
                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x140000x1e0.rsrc
                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x150000xab0.reloc
                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                    .text0x10000x80000x8000False0.439727783203125data5.762192122939682IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                    .rdata0x90000x90000x8600False0.26437150186567165data3.71703192533741IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .data0x120000x10000xc00False0.2613932291666667data3.15531156836296IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                    .CRT0x130000x10000x200False0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .rsrc0x140000x10000x200False0.52734375data4.710061382693063IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .reloc0x150000x10000xc00False0.008138020833333334data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                    NameRVASizeTypeLanguageCountry
                                    RT_MANIFEST0x140600x17dXML 1.0 document textEnglishUnited States
                                    DLLImport
                                    KERNEL32.dllSetFilePointer, GetFileAttributesW, ReadFile, GetLastError, MoveFileW, lstrcpyW, SetFileAttributesW, CreateMutexW, GetDriveTypeW, VerSetConditionMask, WaitForSingleObject, GetTickCount, InitializeCriticalSection, OpenProcess, GetSystemDirectoryW, TerminateThread, Sleep, TerminateProcess, VerifyVersionInfoW, WaitForMultipleObjects, DeleteCriticalSection, ExpandEnvironmentStringsW, lstrlenW, SetHandleInformation, lstrcatA, MultiByteToWideChar, CreatePipe, lstrcmpiA, Process32NextW, CreateToolhelp32Snapshot, LeaveCriticalSection, EnterCriticalSection, FindFirstFileW, lstrcmpW, FindClose, FindNextFileW, GetNativeSystemInfo, GetComputerNameW, GetDiskFreeSpaceW, GetWindowsDirectoryW, GetVolumeInformationW, LoadLibraryA, lstrcmpiW, VirtualFree, CreateThread, CloseHandle, lstrcatW, CreateFileMappingW, ExitThread, CreateFileW, GetModuleFileNameW, WriteFile, GetModuleHandleW, UnmapViewOfFile, MapViewOfFile, GetFileSize, GetEnvironmentVariableW, lstrcpyA, GetModuleHandleA, VirtualAlloc, Process32FirstW, GetTempPathW, GetProcAddress, GetProcessHeap, HeapFree, HeapAlloc, lstrlenA, CreateProcessW, ExitProcess, IsProcessorFeaturePresent
                                    USER32.dllwsprintfW, TranslateMessage, RegisterClassExW, LoadIconW, SetWindowLongW, EndPaint, BeginPaint, LoadCursorW, GetMessageW, ShowWindow, CreateWindowExW, SendMessageW, DispatchMessageW, DefWindowProcW, UpdateWindow, GetForegroundWindow, DestroyWindow
                                    GDI32.dllTextOutW
                                    ADVAPI32.dllCryptExportKey, AllocateAndInitializeSid, RegSetValueExW, RegCreateKeyExW, RegCloseKey, CryptAcquireContextW, CryptGetKeyParam, CryptReleaseContext, CryptImportKey, CryptEncrypt, CryptGenKey, CryptDestroyKey, GetUserNameW, RegQueryValueExW, RegOpenKeyExW, FreeSid
                                    SHELL32.dllSHGetSpecialFolderPathW, ShellExecuteExW, ShellExecuteW
                                    CRYPT32.dllCryptStringToBinaryA, CryptBinaryToStringA
                                    WININET.dllInternetCloseHandle, HttpAddRequestHeadersW, HttpSendRequestW, InternetConnectW, HttpOpenRequestW, InternetOpenW, InternetReadFile
                                    PSAPI.DLLEnumDeviceDrivers, GetDeviceDriverBaseNameW
                                    Language of compilation systemCountry where language is spokenMap
                                    EnglishUnited States
                                    TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                    192.168.2.38.8.8.855642532829498 09/01/22-00:01:41.321667UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15564253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860090532829500 09/01/22-00:02:16.489371UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36009053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862436532026737 09/01/22-00:02:57.542714UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6243653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855955532829500 09/01/22-00:03:25.632008UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35595553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853431532829498 09/01/22-00:02:18.409896UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15343153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865513532829500 09/01/22-00:02:19.430995UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864276532829498 09/01/22-00:03:00.100399UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16427653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851891532026737 09/01/22-00:03:31.975246UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859765532026737 09/01/22-00:03:34.032990UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5976553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853309532829500 09/01/22-00:01:54.918396UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35330953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854155532829498 09/01/22-00:02:39.711366UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15415553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849169532829500 09/01/22-00:02:32.443414UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34916953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864378532829500 09/01/22-00:03:19.972139UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36437853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857391532829500 09/01/22-00:02:53.276938UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35739153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851597532026737 09/01/22-00:03:26.976848UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5159753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853271532829498 09/01/22-00:02:55.260307UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853471532829500 09/01/22-00:02:00.665796UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35347153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865323532026737 09/01/22-00:01:43.859132UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860647532829498 09/01/22-00:03:25.300157UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16064753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850230532026737 09/01/22-00:02:54.735839UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5023053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850624532026737 09/01/22-00:03:18.677171UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5062453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853468532829500 09/01/22-00:02:00.604247UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35346853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858122532829498 09/01/22-00:02:27.905128UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15812253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854436532829498 09/01/22-00:03:36.045306UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15443653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862426532026737 09/01/22-00:03:13.145963UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6242653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856046532829500 09/01/22-00:01:38.500367UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35604653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859378532829500 09/01/22-00:02:48.340518UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35937853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858305532026737 09/01/22-00:02:34.497221UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5830553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861418532829498 09/01/22-00:02:02.984507UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16141853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850095532026737 09/01/22-00:03:38.741458UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5009553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852114532026737 09/01/22-00:03:20.324395UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5211453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865466532829500 09/01/22-00:03:37.373699UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36546653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853042532026737 09/01/22-00:03:06.339869UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5304253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849877532829500 09/01/22-00:02:36.035379UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34987753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864971532829500 09/01/22-00:03:05.617213UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36497153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861186532829498 09/01/22-00:02:52.648140UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16118653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859829532829500 09/01/22-00:02:55.953112UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35982953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849204532026737 09/01/22-00:02:46.678054UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4920453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861364532829498 09/01/22-00:03:28.558638UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16136453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857829532829500 09/01/22-00:03:23.021549UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35782953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850788532026737 09/01/22-00:02:43.387386UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5078853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851996532026737 09/01/22-00:02:26.312895UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5199653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857706532829500 09/01/22-00:01:42.686131UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35770653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859436532026737 09/01/22-00:01:57.638087UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5943653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859822532026737 09/01/22-00:02:19.952319UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5982253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860587532026737 09/01/22-00:01:27.550732UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6058753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852957532829500 09/01/22-00:01:25.328522UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35295753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858914532829500 09/01/22-00:03:18.020601UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35891453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853850532026737 09/01/22-00:01:50.247028UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5385053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856619532026737 09/01/22-00:02:49.126045UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5661953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852112532026737 09/01/22-00:03:20.284135UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5211253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865198532829500 09/01/22-00:02:04.768621UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36519853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853848532829498 09/01/22-00:01:59.462827UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15384853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851893532026737 09/01/22-00:03:32.036713UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854433532829498 09/01/22-00:03:35.979601UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15443353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853310532829500 09/01/22-00:01:54.940366UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35331053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859438532026737 09/01/22-00:01:57.681285UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5943853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861421532829498 09/01/22-00:02:03.043258UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16142153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852458532026737 09/01/22-00:03:02.844406UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5245853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855652532829498 09/01/22-00:03:19.259211UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15565253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861130532829498 09/01/22-00:03:15.942186UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16113053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860421532829498 09/01/22-00:03:32.382333UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16042153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864973532829500 09/01/22-00:03:05.661525UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36497353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863567532026737 09/01/22-00:02:17.089606UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6356753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865463532829500 09/01/22-00:03:37.309587UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36546353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865389532026737 09/01/22-00:02:38.719558UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6538953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853040532026737 09/01/22-00:03:06.300781UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5304053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857827532829500 09/01/22-00:03:22.978908UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35782753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853039532026737 09/01/22-00:03:06.280270UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5303953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859585532026737 09/01/22-00:02:11.746820UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5958553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857708532829500 09/01/22-00:01:42.729663UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35770853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851142532829498 09/01/22-00:01:24.090037UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15114253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853433532829498 09/01/22-00:02:18.458138UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15343353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860093532829500 09/01/22-00:02:16.558554UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36009353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849206532026737 09/01/22-00:02:46.717208UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4920653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851143532829498 09/01/22-00:01:24.124615UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15114353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854158532829498 09/01/22-00:02:39.772185UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15415853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859376532829500 09/01/22-00:02:48.263272UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35937653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864825532829500 09/01/22-00:02:24.749273UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36482553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864273532829498 09/01/22-00:03:00.036817UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16427353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851894532026737 09/01/22-00:03:32.055555UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854434532829498 09/01/22-00:03:36.001169UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15443453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859768532026737 09/01/22-00:03:34.095324UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5976853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853054532829498 09/01/22-00:02:15.078816UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15305453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863448532829498 09/01/22-00:02:35.455212UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16344853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865111532829500 09/01/22-00:01:46.954181UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36511153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853627532026737 09/01/22-00:02:01.832804UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5362753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865200532829500 09/01/22-00:02:04.820486UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36520053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855461532829498 09/01/22-00:03:07.325312UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15546153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865390532026737 09/01/22-00:02:38.738598UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6539053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865516532829500 09/01/22-00:02:19.492210UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855654532829498 09/01/22-00:03:19.297074UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15565453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854288532829500 09/01/22-00:03:33.756470UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35428853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865515532829500 09/01/22-00:02:19.472414UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859767532026737 09/01/22-00:03:34.075907UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5976753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860649532829498 09/01/22-00:03:25.341169UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16064953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853628532026737 09/01/22-00:02:01.851234UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5362853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864970532829500 09/01/22-00:02:44.867082UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36497053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862434532026737 09/01/22-00:02:57.492445UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6243453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859583532026737 09/01/22-00:02:11.706174UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5958353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850232532026737 09/01/22-00:02:54.777871UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5023253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852959532829500 09/01/22-00:01:25.367458UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35295953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850787532026737 09/01/22-00:02:43.367194UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5078753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858123532829498 09/01/22-00:02:27.969558UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15812353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860423532829498 09/01/22-00:03:32.424188UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16042353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865201532829500 09/01/22-00:02:04.842170UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36520153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854157532829498 09/01/22-00:02:39.751533UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15415753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865112532829500 09/01/22-00:01:46.974641UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36511253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859830532829500 09/01/22-00:02:55.974495UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35983053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855460532829498 09/01/22-00:03:07.301197UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15546053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853307532829500 09/01/22-00:01:54.875889UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35330753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851595532026737 09/01/22-00:03:26.929732UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5159553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856044532829500 09/01/22-00:01:38.460693UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35604453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857828532829500 09/01/22-00:03:23.000023UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35782853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864606532829500 09/01/22-00:02:41.903320UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36460653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853273532829498 09/01/22-00:02:55.304130UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856047532829500 09/01/22-00:01:38.529181UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35604753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850626532026737 09/01/22-00:03:18.717464UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5062653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863691532829498 09/01/22-00:03:21.687512UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16369153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859825532026737 09/01/22-00:02:20.014612UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5982553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855954532829500 09/01/22-00:03:25.612012UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35595453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862428532026737 09/01/22-00:03:13.188986UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6242853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861419532829498 09/01/22-00:02:03.004767UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16141953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860474532829498 09/01/22-00:02:47.119975UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16047453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864274532829498 09/01/22-00:03:00.057400UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16427453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853853532026737 09/01/22-00:01:50.543832UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5385353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855248532829498 09/01/22-00:03:03.486266UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15524853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853432532829498 09/01/22-00:02:18.428585UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15343253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853849532829498 09/01/22-00:01:59.483040UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15384953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859586532026737 09/01/22-00:02:11.767488UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5958653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860477532829498 09/01/22-00:02:47.180255UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16047753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852743532026737 09/01/22-00:03:23.998658UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5274353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849170532829500 09/01/22-00:02:32.467435UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34917053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865325532026737 09/01/22-00:01:43.903174UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857575532829498 09/01/22-00:01:53.271847UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15757553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849879532829500 09/01/22-00:02:36.072251UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34987953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859640532026737 09/01/22-00:01:39.971866UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5964053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865109532829500 09/01/22-00:01:46.914019UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36510953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863450532829498 09/01/22-00:02:35.496675UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16345053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860646532829498 09/01/22-00:03:25.281760UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16064653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854285532829500 09/01/22-00:03:33.695070UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35428553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858915532829500 09/01/22-00:03:18.040653UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35891553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864974532829500 09/01/22-00:03:05.683602UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36497453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858482532829500 09/01/22-00:03:29.362481UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35848253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864125532829498 09/01/22-00:02:44.347197UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16412553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859437532026737 09/01/22-00:01:57.658266UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5943753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857137532829498 09/01/22-00:01:34.192981UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15713753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860819532829500 09/01/22-00:03:08.807703UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36081953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864598532829498 09/01/22-00:02:22.069673UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16459853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865388532026737 09/01/22-00:02:38.683294UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6538853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852460532026737 09/01/22-00:03:02.922606UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5246053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861361532829498 09/01/22-00:03:28.363595UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16136153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865464532829500 09/01/22-00:03:37.331573UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36546453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863566532026737 09/01/22-00:02:17.069143UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6356653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849203532026737 09/01/22-00:02:46.656883UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4920353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864972532829500 09/01/22-00:03:05.639386UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36497253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853051532829498 09/01/22-00:02:15.015452UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15305153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851995532026737 09/01/22-00:02:26.294405UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5199553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851107532829500 09/01/22-00:03:01.623107UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35110753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864969532829500 09/01/22-00:02:44.846895UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36496953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852113532026737 09/01/22-00:03:20.304409UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5211353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858121532829498 09/01/22-00:02:27.883460UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15812153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857707532829500 09/01/22-00:01:42.707644UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35770753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861420532829498 09/01/22-00:02:03.023139UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16142053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860772532829498 09/01/22-00:01:45.515640UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859379532829500 09/01/22-00:02:48.360270UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35937953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860420532829498 09/01/22-00:03:32.361100UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16042053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858306532026737 09/01/22-00:02:34.518930UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5830653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857136532829498 09/01/22-00:01:34.170593UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15713653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863692532829498 09/01/22-00:03:21.709351UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16369253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851110532829500 09/01/22-00:03:01.687030UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35111053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855651532829498 09/01/22-00:03:19.239137UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15565153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861187532829498 09/01/22-00:02:52.669551UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16118753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850789532026737 09/01/22-00:02:43.405655UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5078953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864126532829498 09/01/22-00:02:44.367092UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16412653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856045532829500 09/01/22-00:01:38.479108UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35604553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849876532829500 09/01/22-00:02:36.017097UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34987653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853430532829498 09/01/22-00:02:18.389778UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15343053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864275532829498 09/01/22-00:03:00.076893UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16427553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852746532026737 09/01/22-00:03:24.060420UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5274653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865199532829500 09/01/22-00:02:04.790776UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36519953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855643532829498 09/01/22-00:01:41.349610UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15564353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865322532026737 09/01/22-00:01:43.838373UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857389532829500 09/01/22-00:02:53.228134UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35738953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852457532026737 09/01/22-00:03:02.822494UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5245753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859766532026737 09/01/22-00:03:34.053456UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5976653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850094532026737 09/01/22-00:03:38.722516UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5009453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863689532829498 09/01/22-00:03:21.642301UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16368953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864828532829500 09/01/22-00:02:24.814616UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36482853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862427532026737 09/01/22-00:03:13.168037UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6242753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858485532829500 09/01/22-00:03:30.012594UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35848553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860586532026737 09/01/22-00:01:27.526553UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6058653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860648532829498 09/01/22-00:03:25.320562UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16064853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850231532026737 09/01/22-00:02:54.755739UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5023153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859831532829500 09/01/22-00:02:55.995864UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35983153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857138532829498 09/01/22-00:01:34.214783UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15713853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865465532829500 09/01/22-00:03:37.351949UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36546553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859641532026737 09/01/22-00:01:39.990388UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5964153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859638532026737 09/01/22-00:01:39.931325UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5963853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854435532829498 09/01/22-00:03:36.023381UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15443553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860818532829500 09/01/22-00:03:08.745097UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36081853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857576532829498 09/01/22-00:01:53.290249UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15757653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849171532829500 09/01/22-00:02:32.489443UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34917153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851144532829498 09/01/22-00:01:24.145242UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15114453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852115532026737 09/01/22-00:03:20.348262UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5211553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856620532026737 09/01/22-00:02:49.146584UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5662053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851109532829500 09/01/22-00:03:01.665772UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35110953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864379532829500 09/01/22-00:03:19.992460UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36437953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864599532829498 09/01/22-00:02:22.089885UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16459953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860821532829500 09/01/22-00:03:08.846909UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36082153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849205532026737 09/01/22-00:02:46.696702UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4920553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849878532829500 09/01/22-00:02:36.053729UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34987853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853846532829498 09/01/22-00:01:59.423880UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15384653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860091532829500 09/01/22-00:02:16.509694UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36009153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859377532829500 09/01/22-00:02:48.283085UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35937753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859824532026737 09/01/22-00:02:19.994370UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5982453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864607532829500 09/01/22-00:02:41.921899UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36460753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855249532829498 09/01/22-00:03:03.506251UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15524953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864380532829500 09/01/22-00:03:20.011368UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36438053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850092532026737 09/01/22-00:03:38.678470UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5009253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853272532829498 09/01/22-00:02:55.282821UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857392532829500 09/01/22-00:02:53.296910UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35739253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858916532829500 09/01/22-00:03:18.060823UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35891653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853053532829498 09/01/22-00:02:15.057233UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15305353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864826532829500 09/01/22-00:02:24.770961UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36482653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853625532026737 09/01/22-00:02:01.788642UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5362553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851596532026737 09/01/22-00:03:26.954769UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5159653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862435532026737 09/01/22-00:02:57.512287UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6243553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853852532026737 09/01/22-00:01:50.489647UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5385253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862429532026737 09/01/22-00:03:13.209944UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6242953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860584532026737 09/01/22-00:01:27.482735UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6058453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864124532829498 09/01/22-00:02:44.327136UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16412453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861189532829498 09/01/22-00:02:52.764321UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16118953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.849168532829500 09/01/22-00:02:32.423642UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34916853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863451532829498 09/01/22-00:02:35.516825UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16345153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850625532026737 09/01/22-00:03:18.697259UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5062553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854286532829500 09/01/22-00:03:33.715891UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35428653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860769532829498 09/01/22-00:01:45.451637UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16076953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852744532026737 09/01/22-00:03:24.019183UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5274453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855641532829498 09/01/22-00:01:41.302395UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15564153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853469532829500 09/01/22-00:02:00.624524UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35346953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860770532829498 09/01/22-00:01:45.473540UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853470532829500 09/01/22-00:02:00.646017UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35347053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865324532026737 09/01/22-00:01:43.883100UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853851532026737 09/01/22-00:01:50.267332UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5385153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.862433532026737 09/01/22-00:02:57.467935UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6243353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859584532026737 09/01/22-00:02:11.726579UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5958453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860475532829498 09/01/22-00:02:47.139274UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16047553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864123532829498 09/01/22-00:02:44.306860UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16412353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858483532829500 09/01/22-00:03:29.383909UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35848353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856618532026737 09/01/22-00:02:49.105935UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5661853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855247532829498 09/01/22-00:03:03.466197UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15524753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861362532829498 09/01/22-00:03:28.520063UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16136253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861129532829498 09/01/22-00:03:15.922110UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16112953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857574532829498 09/01/22-00:01:53.251460UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15757453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864597532829498 09/01/22-00:02:22.051454UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16459753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858303532026737 09/01/22-00:02:34.435886UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5830353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865387532026737 09/01/22-00:02:38.660218UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6538753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853274532829498 09/01/22-00:02:55.325848UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15327453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851594532026737 09/01/22-00:03:26.907030UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5159453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863565532026737 09/01/22-00:02:17.049623UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6356553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850627532026737 09/01/22-00:03:18.737468UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5062753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858124532829498 09/01/22-00:02:27.993076UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15812453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850786532026737 09/01/22-00:02:43.346779UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5078653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850233532026737 09/01/22-00:02:54.805593UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5023353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854287532829500 09/01/22-00:03:33.736226UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35428753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864605532829500 09/01/22-00:02:41.882665UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36460553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864604532829500 09/01/22-00:02:41.862105UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36460453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855246532829498 09/01/22-00:03:03.448041UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15524653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855953532829500 09/01/22-00:03:25.594151UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35595353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858484532829500 09/01/22-00:03:29.402067UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35848453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857139532829498 09/01/22-00:01:34.235761UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15713953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859435532026737 09/01/22-00:01:57.617695UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5943553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863564532026737 09/01/22-00:02:17.026690UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6356453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852958532829500 09/01/22-00:01:25.347118UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35295853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860092532829500 09/01/22-00:02:16.532570UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36009253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863690532829498 09/01/22-00:03:21.664385UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16369053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858304532026737 09/01/22-00:02:34.463044UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5830453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855459532829498 09/01/22-00:03:07.276022UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15545953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860476532829498 09/01/22-00:02:47.160135UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16047653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865110532829500 09/01/22-00:01:46.934130UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36511053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.863449532829498 09/01/22-00:02:35.476503UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16344953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852960532829500 09/01/22-00:01:25.385522UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35296053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857390532829500 09/01/22-00:02:53.250639UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35739053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857573532829498 09/01/22-00:01:53.226527UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15757353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.865514532829500 09/01/22-00:02:19.450712UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861131532829498 09/01/22-00:03:15.960645UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16113153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851141532829498 09/01/22-00:01:24.068248UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15114153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853052532829498 09/01/22-00:02:15.036327UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15305253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861128532829498 09/01/22-00:03:15.903464UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16112853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852745532026737 09/01/22-00:03:24.040007UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5274553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.854156532829498 09/01/22-00:02:39.730598UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15415653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857709532829500 09/01/22-00:01:42.750967UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35770953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861363532829498 09/01/22-00:03:28.538480UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16136353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853308532829500 09/01/22-00:01:54.898418UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35330853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860585532026737 09/01/22-00:01:27.503002UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6058553192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860771532829498 09/01/22-00:01:45.495695UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16077153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860422532829498 09/01/22-00:03:32.403375UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16042253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.850093532026737 09/01/22-00:03:38.699985UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5009353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853041532026737 09/01/22-00:03:06.319112UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5304153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851994532026737 09/01/22-00:02:26.273853UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5199453192.168.2.38.8.8.8
                                    192.168.2.38.8.8.858917532829500 09/01/22-00:03:18.082512UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35891753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864827532829500 09/01/22-00:02:24.792802UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36482753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.860820532829500 09/01/22-00:03:08.828384UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36082053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851997532026737 09/01/22-00:02:26.333413UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5199753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.861188532829498 09/01/22-00:02:52.691629UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16118853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859832532829500 09/01/22-00:02:56.017085UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35983253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864600532829498 09/01/22-00:02:22.108885UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16460053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855640532829498 09/01/22-00:01:41.280696UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15564053192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855462532829498 09/01/22-00:03:07.346617UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15546253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859639532026737 09/01/22-00:01:39.951734UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5963953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855653532829498 09/01/22-00:03:19.277165UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15565353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.857826532829500 09/01/22-00:03:22.956962UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35782653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853847532829498 09/01/22-00:01:59.444336UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15384753192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851108532829500 09/01/22-00:03:01.644612UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35110853192.168.2.38.8.8.8
                                    192.168.2.38.8.8.852459532026737 09/01/22-00:03:02.900983UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5245953192.168.2.38.8.8.8
                                    192.168.2.38.8.8.864381532829500 09/01/22-00:03:20.034172UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36438153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.853626532026737 09/01/22-00:02:01.814516UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5362653192.168.2.38.8.8.8
                                    192.168.2.38.8.8.859823532026737 09/01/22-00:02:19.973756UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5982353192.168.2.38.8.8.8
                                    192.168.2.38.8.8.851892532026737 09/01/22-00:03:31.996527UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5189253192.168.2.38.8.8.8
                                    192.168.2.38.8.8.856621532026737 09/01/22-00:02:49.211680UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5662153192.168.2.38.8.8.8
                                    192.168.2.38.8.8.855956532829500 09/01/22-00:03:25.650230UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35595653192.168.2.38.8.8.8
                                    TimestampSource PortDest PortSource IPDest IP
                                    Sep 1, 2022 00:01:23.064902067 CEST5397553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:23.084820032 CEST53539758.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:23.994477034 CEST5113953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:24.030497074 CEST53511398.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:24.049179077 CEST5114053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:24.067482948 CEST53511408.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:24.068248034 CEST5114153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:24.088715076 CEST53511418.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:24.090037107 CEST5114253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:24.110754013 CEST53511428.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:24.124614954 CEST5114353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:24.144764900 CEST53511438.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:24.145241976 CEST5114453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:24.164725065 CEST53511448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:25.247797012 CEST5295553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:25.283262014 CEST53529558.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:25.310718060 CEST5295653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:25.327796936 CEST53529568.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:25.328521967 CEST5295753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:25.346643925 CEST53529578.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:25.347117901 CEST5295853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:25.366964102 CEST53529588.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:25.367458105 CEST5295953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:25.385024071 CEST53529598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:25.385521889 CEST5296053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:25.405503035 CEST53529608.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:26.844472885 CEST6058253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:27.449457884 CEST53605828.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:27.464441061 CEST6058353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:27.481861115 CEST53605838.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:27.482734919 CEST6058453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:27.502418995 CEST53605848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:27.503001928 CEST6058553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:27.520689964 CEST53605858.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:27.526552916 CEST6058653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:27.550129890 CEST53605868.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:27.550731897 CEST6058753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:27.573137045 CEST53605878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:33.534245014 CEST5713453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:34.108952045 CEST53571348.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:34.150069952 CEST5713553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:34.169861078 CEST53571358.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:34.170593023 CEST5713653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:34.192428112 CEST53571368.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:34.192981005 CEST5713753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:34.214257956 CEST53571378.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:34.214782953 CEST5713853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:34.234899998 CEST53571388.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:34.235760927 CEST5713953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:34.256675959 CEST53571398.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:35.764401913 CEST6205053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:36.800379992 CEST6205053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:37.845704079 CEST6205053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:38.424983025 CEST53620508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:38.440474033 CEST5604353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:38.459913969 CEST53560438.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:38.460692883 CEST5604453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:38.478588104 CEST53560448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:38.479108095 CEST5604553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:38.499536037 CEST53560458.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:38.500366926 CEST5604653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:38.522388935 CEST53560468.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:38.529181004 CEST5604753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:38.547306061 CEST53560478.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.520437956 CEST53620508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.759217024 CEST5963653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:39.869720936 CEST53596368.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.895581007 CEST5963753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:39.914973974 CEST53596378.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.931324959 CEST5963853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:39.951137066 CEST53596388.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.951734066 CEST5963953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:39.971240997 CEST53596398.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.971865892 CEST5964053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:39.989907026 CEST53596408.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:39.990387917 CEST5964153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:40.010957003 CEST53596418.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:40.783550978 CEST53620508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:41.157733917 CEST5563853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:41.194181919 CEST53556388.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:41.261158943 CEST5563953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:41.280056000 CEST53556398.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:41.280695915 CEST5564053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:41.300605059 CEST53556408.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:41.302395105 CEST5564153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:41.320178032 CEST53556418.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:41.321666956 CEST5564253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:41.341320992 CEST53556428.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:41.349610090 CEST5564353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:41.369268894 CEST53556438.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:42.602513075 CEST5770453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:42.639774084 CEST53577048.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:42.666846037 CEST5770553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:42.685431004 CEST53577058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:42.686131001 CEST5770653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:42.707127094 CEST53577068.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:42.707643986 CEST5770753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:42.729058981 CEST53577078.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:42.729662895 CEST5770853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:42.750449896 CEST53577088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:42.750967026 CEST5770953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:42.771682978 CEST53577098.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:43.750798941 CEST6532053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:43.786712885 CEST53653208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:43.818617105 CEST6532153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:43.837654114 CEST53653218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:43.838372946 CEST6532253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:43.857835054 CEST53653228.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:43.859132051 CEST6532353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:43.878863096 CEST53653238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:43.883100033 CEST6532453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:43.902585030 CEST53653248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:43.903173923 CEST6532553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:43.922862053 CEST53653258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:44.873297930 CEST6076753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:45.412717104 CEST53607678.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:45.432225943 CEST6076853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:45.450937986 CEST53607688.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:45.451637030 CEST6076953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:45.472791910 CEST53607698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:45.473540068 CEST6077053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:45.495043039 CEST53607708.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:45.495695114 CEST6077153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:45.514930964 CEST53607718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:45.515640020 CEST6077253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:45.535151958 CEST53607728.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:46.825660944 CEST6510753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:46.863656044 CEST53651078.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:46.895714045 CEST6510853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:46.913108110 CEST53651088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:46.914019108 CEST6510953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:46.933680058 CEST53651098.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:46.934129953 CEST6511053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:46.953710079 CEST53651108.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:46.954180956 CEST6511153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:46.973721981 CEST53651118.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:46.974641085 CEST6511253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:46.994463921 CEST53651128.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:47.966227055 CEST5384853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:48.969243050 CEST5384853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.027492046 CEST5384853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.163376093 CEST53538488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:50.193775892 CEST5384953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.211262941 CEST53538498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:50.247028112 CEST5385053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.265369892 CEST53538508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:50.267332077 CEST5385153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.285290956 CEST53538518.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:50.489646912 CEST5385253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.507364035 CEST53538528.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:50.543832064 CEST5385353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:50.561597109 CEST53538538.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:50.793282986 CEST53538488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:52.259315968 CEST53538488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:52.586035013 CEST5757153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:53.162805080 CEST53575718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:53.206665039 CEST5757253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:53.225925922 CEST53575728.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:53.226526976 CEST5757353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:53.246345043 CEST53575738.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:53.251460075 CEST5757453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:53.271325111 CEST53575748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:53.271847010 CEST5757553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:53.289664030 CEST53575758.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:53.290249109 CEST5757653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:53.310367107 CEST53575768.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:54.258793116 CEST5330553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:54.812717915 CEST53533058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:54.856652975 CEST5330653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:54.875181913 CEST53533068.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:54.875889063 CEST5330753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:54.897751093 CEST53533078.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:54.898417950 CEST5330853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:54.917856932 CEST53533088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:54.918395996 CEST5330953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:54.939847946 CEST53533098.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:54.940366030 CEST5331053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:54.961664915 CEST53533108.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:55.904305935 CEST5943353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:56.898372889 CEST5943353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:57.544912100 CEST53594338.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:57.597537994 CEST5943453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:57.616928101 CEST53594348.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:57.617695093 CEST5943553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:57.637340069 CEST53594358.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:57.638087034 CEST5943653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:57.657670021 CEST53594368.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:57.658266068 CEST5943753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:57.680296898 CEST53594378.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:57.681284904 CEST5943853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:57.700737000 CEST53594388.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:58.788856030 CEST5384453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:59.361457109 CEST53538448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:59.402009010 CEST5384553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:59.421237946 CEST53538458.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:59.423880100 CEST5384653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:59.443866014 CEST53538468.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:59.444335938 CEST5384753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:59.462193966 CEST53538478.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:59.462826967 CEST5384853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:59.482578039 CEST53538488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:01:59.483040094 CEST5384953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:01:59.500787973 CEST53538498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:00.502871990 CEST5346653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:00.540338039 CEST53534668.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:00.582490921 CEST5346753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:00.602976084 CEST53534678.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:00.604247093 CEST5346853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:00.623477936 CEST53534688.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:00.624524117 CEST5346953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:00.645464897 CEST53534698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:00.646017075 CEST5347053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:00.665227890 CEST53534708.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:00.665796041 CEST5347153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:00.686867952 CEST53534718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.677488089 CEST5362353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:01.711468935 CEST53536238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.768798113 CEST5362453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:01.787820101 CEST53536248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.788641930 CEST5362553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:01.813957930 CEST53536258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.814516068 CEST5362653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:01.832298040 CEST53536268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.832803965 CEST5362753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:01.850697994 CEST53536278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.851233959 CEST5362853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:01.870028019 CEST53536288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:01.915724039 CEST53594338.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:02.841990948 CEST6141653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:02.924088001 CEST53614168.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:02.966444016 CEST6141753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:02.983864069 CEST53614178.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:02.984507084 CEST6141853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:03.004199028 CEST53614188.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:03.004766941 CEST6141953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:03.022608995 CEST53614198.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:03.023139000 CEST6142053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:03.041289091 CEST53614208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:03.043257952 CEST6142153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:03.060731888 CEST53614218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:04.111052990 CEST6519653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:04.694045067 CEST53651968.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:04.748806953 CEST6519753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:04.767615080 CEST53651978.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:04.768620968 CEST6519853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:04.790055037 CEST53651988.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:04.790776014 CEST6519953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:04.812170982 CEST53651998.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:04.820486069 CEST6520053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:04.841615915 CEST53652008.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:04.842170000 CEST6520153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:04.861390114 CEST53652018.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:05.931890965 CEST5870853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:06.949732065 CEST5870853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:07.982110023 CEST5870853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:10.088450909 CEST5870853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:10.950472116 CEST53587088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:11.685623884 CEST5958253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:11.704813957 CEST53595828.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:11.706173897 CEST5958353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:11.725864887 CEST53595838.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:11.726578951 CEST5958453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:11.746112108 CEST53595848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:11.746819973 CEST5958553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:11.766913891 CEST53595858.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:11.767488003 CEST5958653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:11.787333965 CEST53595868.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:11.967653036 CEST53587088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:12.846661091 CEST5304953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:12.999161005 CEST53587088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:13.892630100 CEST5304953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:14.387511015 CEST53587088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:14.908216953 CEST5304953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:14.971482038 CEST53530498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:14.995146036 CEST5305053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:15.014755964 CEST53530508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:15.015451908 CEST5305153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:15.035367012 CEST53530518.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:15.036326885 CEST5305253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:15.056536913 CEST53530528.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:15.057233095 CEST5305353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:15.078147888 CEST53530538.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:15.078815937 CEST5305453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:15.099627018 CEST53530548.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:15.420219898 CEST6008853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.408524990 CEST6008853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.448688984 CEST53600888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:16.468611002 CEST6008953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.488795042 CEST53600898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:16.489371061 CEST6009053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.509176016 CEST53600908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:16.509694099 CEST6009153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.530898094 CEST53600918.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:16.532569885 CEST6009253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.553879023 CEST53600928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:16.558553934 CEST6009353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.580022097 CEST53600938.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:16.953728914 CEST6356253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:16.991344929 CEST53635628.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.000292063 CEST6356353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:17.021205902 CEST53635638.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.026690006 CEST6356453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:17.048921108 CEST53635648.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.049623013 CEST6356553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:17.068710089 CEST53635658.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.069143057 CEST6356653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:17.089041948 CEST53635668.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.089606047 CEST6356753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:17.109560966 CEST53635678.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.505155087 CEST53600888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:17.824410915 CEST5342853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.361676931 CEST53534288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:18.368638039 CEST5342953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.389043093 CEST53534298.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:18.389777899 CEST5343053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.408541918 CEST53534308.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:18.409895897 CEST5343153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.427966118 CEST53534318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:18.428585052 CEST5343253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.449790001 CEST53534328.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:18.458137989 CEST5343353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.479060888 CEST53534338.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:18.825237036 CEST6551153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:18.912440062 CEST53530498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.401741028 CEST53655118.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.409481049 CEST6551253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.430453062 CEST53655128.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.430994987 CEST6551353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.450289965 CEST53655138.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.450711966 CEST6551453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.471883059 CEST53655148.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.472414017 CEST6551553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.491760969 CEST53655158.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.492209911 CEST6551653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.512691975 CEST53655168.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.849414110 CEST5982053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.925700903 CEST53598208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.930727959 CEST53530498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.932447910 CEST5982153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.951675892 CEST53598218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.952318907 CEST5982253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.970587015 CEST53598228.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.973756075 CEST5982353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:19.993907928 CEST53598238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:19.994369984 CEST5982453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:20.013947010 CEST53598248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:20.014611959 CEST5982553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:20.035240889 CEST53598258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:20.450695992 CEST6459553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:21.440356970 CEST6459553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:22.022486925 CEST53645958.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.031480074 CEST6459653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:22.050517082 CEST53645968.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.051454067 CEST6459753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:22.069267035 CEST53645978.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.069673061 CEST6459853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:22.074369907 CEST53645958.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.089488983 CEST53645988.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.089884996 CEST6459953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:22.108500004 CEST53645998.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.108885050 CEST6460053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:22.129991055 CEST53646008.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:22.575946093 CEST5207953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:23.581091881 CEST5207953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.596934080 CEST5207953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.712889910 CEST53520798.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:24.728225946 CEST6482453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.748702049 CEST53648248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:24.749273062 CEST6482553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.770515919 CEST53648258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:24.770961046 CEST6482653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.792413950 CEST53648268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:24.792802095 CEST6482753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.814188957 CEST53648278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:24.814615965 CEST6482853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:24.833614111 CEST53648288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:25.179150105 CEST5199253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.190792084 CEST5199253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.233566046 CEST53519928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.252104998 CEST5199353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.270071030 CEST53519938.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.273853064 CEST5199453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.293915987 CEST53519948.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.294404984 CEST5199553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.312290907 CEST53519958.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.312895060 CEST5199653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.332462072 CEST53519968.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.333412886 CEST5199753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.352917910 CEST53519978.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.695220947 CEST5811953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:26.714562893 CEST53520798.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:26.841078043 CEST53520798.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.386841059 CEST53519928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.750152111 CEST5811953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:27.784187078 CEST53581198.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.817483902 CEST53581198.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.858907938 CEST5812053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:27.877135992 CEST53581208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.883460045 CEST5812153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:27.904680967 CEST53581218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.905128002 CEST5812253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:27.926455975 CEST53581228.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.969558001 CEST5812353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:27.989053965 CEST53581238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:27.993076086 CEST5812453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:28.014046907 CEST53581248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:29.601125002 CEST4916653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:30.826258898 CEST53491668.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:32.371490955 CEST4916653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:32.404072046 CEST4916753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:32.422898054 CEST53491678.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:32.423641920 CEST4916853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:32.442924023 CEST53491688.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:32.443413973 CEST4916953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:32.465111017 CEST53491698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:32.467434883 CEST4917053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:32.486720085 CEST53491708.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:32.489443064 CEST4917153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:32.510637999 CEST53491718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:32.867223024 CEST5830153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:33.862488031 CEST5830153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:33.985611916 CEST53491668.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.407073975 CEST53583018.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.417866945 CEST5830253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:34.435112000 CEST53583028.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.435885906 CEST5830353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:34.459167957 CEST53583038.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.463043928 CEST5830453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:34.484791994 CEST53583048.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.489913940 CEST53583018.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.497220993 CEST5830553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:34.517954111 CEST53583058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.518929958 CEST5830653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:34.537820101 CEST53583068.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:34.851964951 CEST6344653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.427285910 CEST53634468.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.437273979 CEST6344753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.454541922 CEST53634478.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.455212116 CEST6344853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.475027084 CEST53634488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.476502895 CEST6344953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.496222973 CEST53634498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.496675014 CEST6345053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.516345024 CEST53634508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.516824961 CEST6345153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.536685944 CEST53634518.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.859457016 CEST4987453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:35.984587908 CEST53498748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:35.995635033 CEST4987553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:36.012811899 CEST53498758.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:36.017096996 CEST4987653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:36.034972906 CEST53498768.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:36.035378933 CEST4987753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:36.053332090 CEST53498778.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:36.053729057 CEST4987853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:36.071810961 CEST53498788.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:36.072251081 CEST4987953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:36.091907978 CEST53498798.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:36.459953070 CEST6545953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:37.472609997 CEST6545953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.497634888 CEST6545953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.631139994 CEST53654598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:38.640486956 CEST6538653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.659338951 CEST53653868.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:38.660218000 CEST6538753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.680645943 CEST53653878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:38.683294058 CEST6538853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.701905012 CEST53653888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:38.719558001 CEST6538953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.738066912 CEST53653898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:38.738598108 CEST6539053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:38.759218931 CEST53653908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.027879000 CEST53654598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.088742971 CEST5415353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:39.143616915 CEST53654598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.675185919 CEST53541538.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.691652060 CEST5415453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:39.710722923 CEST53541548.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.711365938 CEST5415553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:39.729000092 CEST53541558.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.730597973 CEST5415653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:39.750302076 CEST53541568.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.751533031 CEST5415753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:39.771075010 CEST53541578.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:39.772185087 CEST5415853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:39.791596889 CEST53541588.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:40.153419018 CEST6460253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.172076941 CEST6460253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.822036982 CEST53646028.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:41.842334986 CEST6460353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.861427069 CEST53646038.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:41.862104893 CEST6460453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.881999969 CEST53646048.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:41.882664919 CEST6460553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.902828932 CEST53646058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:41.903320074 CEST6460653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.921314955 CEST53646068.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:41.921899080 CEST6460753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:41.941456079 CEST53646078.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:42.277318001 CEST5078453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:42.283397913 CEST53646028.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.285449982 CEST5078453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:43.320070028 CEST53507848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.328716993 CEST5078553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:43.345973015 CEST53507858.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.346779108 CEST5078653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:43.366689920 CEST53507868.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.367193937 CEST5078753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:43.386923075 CEST53507878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.387386084 CEST5078853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:43.405071020 CEST53507888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.405654907 CEST5078953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:43.425419092 CEST53507898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:43.751919985 CEST6412153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.279233932 CEST53641218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.286156893 CEST6412253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.305149078 CEST53641228.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.306859970 CEST6412353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.326653957 CEST53641238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.327136040 CEST6412453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.346456051 CEST53641248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.347197056 CEST6412553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.366677999 CEST53641258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.367091894 CEST6412653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.386941910 CEST53641268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.774935961 CEST6496753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.819075108 CEST53649678.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.827179909 CEST6496853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.846179008 CEST53649688.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.846894979 CEST6496953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.864609003 CEST53649698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.867082119 CEST6497053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.886693001 CEST53649708.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.887150049 CEST6497153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.908752918 CEST53649718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:44.909322977 CEST6497253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:44.929284096 CEST53649728.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:45.564925909 CEST6082553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.551074982 CEST6082553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.625612020 CEST53608258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:46.632401943 CEST4920253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.652822018 CEST53492028.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:46.656883001 CEST4920353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.677609921 CEST53492038.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:46.678054094 CEST4920453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.696248055 CEST53492048.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:46.696702003 CEST4920553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.716310978 CEST53492058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:46.717207909 CEST4920653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:46.736613989 CEST53492068.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.066291094 CEST6493653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:47.092792034 CEST53649368.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.096024036 CEST53608258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.102243900 CEST6493753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:47.119285107 CEST53649378.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.119975090 CEST6047453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:47.137702942 CEST53604748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.139273882 CEST6047553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:47.159663916 CEST53604758.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.160135031 CEST6047653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:47.179497957 CEST53604768.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.180254936 CEST6047753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:47.199672937 CEST53604778.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:47.295221090 CEST53507848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.143838882 CEST5937453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:48.169800997 CEST53593748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.243660927 CEST5937553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:48.262660027 CEST53593758.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.263272047 CEST5937653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:48.282622099 CEST53593768.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.283085108 CEST5937753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:48.302493095 CEST53593778.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.340517998 CEST5937853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:48.359857082 CEST53593788.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.360270023 CEST5937953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:48.378109932 CEST53593798.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:48.992279053 CEST5661653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:49.030847073 CEST53566168.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:49.039655924 CEST5661753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:49.060447931 CEST53566178.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:49.105935097 CEST5661853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:49.125612974 CEST53566188.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:49.126044989 CEST5661953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:49.145709991 CEST53566198.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:49.146584034 CEST5662053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:49.164716959 CEST53566208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:49.211679935 CEST5662153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:49.230854988 CEST53566218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:50.544686079 CEST6118453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:51.666511059 CEST53611848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:52.608259916 CEST6118453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:52.628920078 CEST6118553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:52.647394896 CEST53611858.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:52.648139954 CEST6118653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:52.669127941 CEST53611868.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:52.669550896 CEST6118753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:52.691092014 CEST53611878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:52.691628933 CEST6118853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:52.712511063 CEST53611888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:52.764321089 CEST6118953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:52.786346912 CEST53611898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.163081884 CEST5738753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:53.169249058 CEST53611848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.199151039 CEST53573878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.207458973 CEST5738853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:53.227545977 CEST53573888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.228133917 CEST5738953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:53.250277996 CEST53573898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.250638962 CEST5739053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:53.274090052 CEST53573908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.276937962 CEST5739153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:53.296488047 CEST53573918.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.296910048 CEST5739253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:53.315620899 CEST53573928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:53.660832882 CEST5022853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.678829908 CEST5022853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.707915068 CEST53502288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:54.715509892 CEST5022953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.727380991 CEST53502288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:54.735213995 CEST53502298.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:54.735838890 CEST5023053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.755316019 CEST53502308.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:54.755738974 CEST5023153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.777358055 CEST53502318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:54.777870893 CEST5023253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.797842026 CEST53502328.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:54.805593014 CEST5023353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:54.826921940 CEST53502338.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.193733931 CEST5326953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.222019911 CEST53532698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.231367111 CEST5327053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.248954058 CEST53532708.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.260307074 CEST5327153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.282449961 CEST53532718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.282820940 CEST5327253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.303663969 CEST53532728.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.304130077 CEST5327353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.325366020 CEST53532738.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.325848103 CEST5327453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.344696999 CEST53532748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.844996929 CEST5982753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.919511080 CEST53598278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.932115078 CEST5982853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.952475071 CEST53598288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.953111887 CEST5982953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.974069118 CEST53598298.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.974494934 CEST5983053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:55.995476007 CEST53598308.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:55.995863914 CEST5983153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:56.016655922 CEST53598318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:56.017085075 CEST5983253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:56.038196087 CEST53598328.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:56.404357910 CEST6243153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.411904097 CEST6243153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.439387083 CEST53624318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.447629929 CEST6243253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.449079037 CEST53624318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.467147112 CEST53624328.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.467935085 CEST6243353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.488708973 CEST53624338.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.492444992 CEST6243453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.511897087 CEST53624348.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.512286901 CEST6243553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.530978918 CEST53624358.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.542714119 CEST6243653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:57.561358929 CEST53624368.8.8.8192.168.2.3
                                    Sep 1, 2022 00:02:57.924940109 CEST6427153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:58.928544044 CEST6427153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:02:59.943011045 CEST6427153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:00.010236025 CEST53642718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:00.017366886 CEST6427253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:00.035882950 CEST53642728.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:00.036817074 CEST6427353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:00.057038069 CEST53642738.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:00.057399988 CEST6427453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:00.076392889 CEST53642748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:00.076893091 CEST6427553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:00.097615957 CEST53642758.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:00.100399017 CEST6427653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:00.121129990 CEST53642768.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:00.563648939 CEST5110553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.554763079 CEST5110553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.584554911 CEST53511058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:01.595273972 CEST53511058.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:01.601682901 CEST5110653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.622442007 CEST53511068.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:01.623106956 CEST5110753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.644107103 CEST53511078.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:01.644612074 CEST5110853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.665334940 CEST53511088.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:01.665771961 CEST5110953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.686562061 CEST53511098.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:01.687030077 CEST5111053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:01.706001043 CEST53511108.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.153387070 CEST5245553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:02.779787064 CEST53524558.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.801975012 CEST5245653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:02.821990013 CEST53524568.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.822494030 CEST5245753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:02.843368053 CEST53524578.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.844405890 CEST5245853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:02.865358114 CEST53524588.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.900983095 CEST5245953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:02.922287941 CEST53524598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.922605991 CEST5246053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:02.942126989 CEST53524608.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:02.945770025 CEST53642718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.343214035 CEST5524453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.418770075 CEST53552448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.427838087 CEST5524553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.446106911 CEST53552458.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.448040962 CEST5524653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.465781927 CEST53552468.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.466197014 CEST5524753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.485872984 CEST53552478.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.486265898 CEST5524853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.505850077 CEST53552488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.506251097 CEST5524953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.524724007 CEST53552498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:03.962084055 CEST6496953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:03.967163086 CEST53642718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:04.974921942 CEST6496953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:05.580583096 CEST53649698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:05.594440937 CEST6497053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:05.616434097 CEST53649708.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:05.617213011 CEST6497153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:05.638950109 CEST53649718.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:05.639385939 CEST6497253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:05.661201954 CEST53649728.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:05.661525011 CEST6497353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:05.683096886 CEST53649738.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:05.683602095 CEST6497453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:05.704983950 CEST53649748.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.090673923 CEST53649698.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.123651028 CEST5303753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:06.253566980 CEST53530378.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.260365963 CEST5303853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:06.279741049 CEST53530388.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.280270100 CEST5303953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:06.300148010 CEST53530398.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.300781012 CEST5304053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:06.318766117 CEST53530408.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.319112062 CEST5304153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:06.339133978 CEST53530418.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.339869022 CEST5304253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:06.360065937 CEST53530428.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:06.701911926 CEST5545753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:07.230133057 CEST53554578.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:07.240674019 CEST5545853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:07.261197090 CEST53554588.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:07.276021957 CEST5545953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:07.297318935 CEST53554598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:07.301197052 CEST5546053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:07.321963072 CEST53554608.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:07.325311899 CEST5546153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:07.345874071 CEST53554618.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:07.346616983 CEST5546253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:07.367491961 CEST53554628.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:08.098186970 CEST6081653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:08.672029018 CEST53608168.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:08.720036983 CEST6081753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:08.740346909 CEST53608178.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:08.745096922 CEST6081853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:08.766110897 CEST53608188.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:08.807703018 CEST6081953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:08.827946901 CEST53608198.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:08.828383923 CEST6082053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:08.846530914 CEST53608208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:08.846909046 CEST6082153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:08.866904974 CEST53608218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:11.312613964 CEST6242453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:11.907406092 CEST53624248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:13.124238968 CEST6242553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:13.145453930 CEST53624258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:13.145962954 CEST6242653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:13.167514086 CEST53624268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:13.168036938 CEST6242753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:13.187902927 CEST53624278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:13.188986063 CEST6242853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:13.209469080 CEST53624288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:13.209944010 CEST6242953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:13.232753992 CEST53624298.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:13.699589014 CEST6112653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:14.710131884 CEST6112653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.711199999 CEST6112653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.875538111 CEST53611268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:15.883177996 CEST6112753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.886709929 CEST53611268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:15.902874947 CEST53611278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:15.903464079 CEST6112853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.921664953 CEST53611288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:15.922110081 CEST6112953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.941783905 CEST53611298.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:15.942186117 CEST6113053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.960310936 CEST53611308.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:15.960644960 CEST6113153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:15.978528023 CEST53611318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:16.393064976 CEST5539053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:17.397872925 CEST5539053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:17.783536911 CEST53611268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:17.989558935 CEST53553908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.001125097 CEST5891353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.019994974 CEST53589138.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.020601034 CEST5891453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.040131092 CEST53589148.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.040652990 CEST5891553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.060370922 CEST53589158.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.060822964 CEST5891653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.080894947 CEST53589168.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.082511902 CEST5891753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.102590084 CEST53589178.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.621407986 CEST5062253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.650096893 CEST53506228.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.657192945 CEST5062353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.676616907 CEST53506238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.677170992 CEST5062453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.696774960 CEST53506248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.697258949 CEST5062553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.717092037 CEST53506258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.717463970 CEST5062653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.736999989 CEST53506268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:18.737468004 CEST5062753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:18.754909992 CEST53506278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.167845011 CEST5564953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.210956097 CEST53556498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.219196081 CEST5565053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.238610029 CEST53556508.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.239136934 CEST5565153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.258774996 CEST53556518.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.259211063 CEST5565253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.276746988 CEST53556528.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.277164936 CEST5565353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.296673059 CEST53556538.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.297074080 CEST5565453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.316821098 CEST53556548.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.696104050 CEST53553908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.834583998 CEST6437653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.938867092 CEST53643768.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.952431917 CEST6437753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.971436024 CEST53643778.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.972138882 CEST6437853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:19.991856098 CEST53643788.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:19.992460012 CEST6437953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.010216951 CEST53643798.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.011368036 CEST6438053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.031111956 CEST53643808.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.034172058 CEST6438153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.051709890 CEST53643818.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.228393078 CEST5211053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.256568909 CEST53521108.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.265758991 CEST5211153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.283133984 CEST53521118.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.284135103 CEST5211253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.303747892 CEST53521128.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.304409027 CEST5211353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.323898077 CEST53521138.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.324394941 CEST5211453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.344026089 CEST53521148.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.348262072 CEST5211553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:20.366065979 CEST53521158.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:20.534615040 CEST6368753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.523137093 CEST6368753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.609051943 CEST53636878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:21.620418072 CEST6368853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.641108990 CEST53636888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:21.642301083 CEST6368953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.663789988 CEST53636898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:21.664385080 CEST6369053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.686964035 CEST53636908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:21.687511921 CEST6369153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.708765030 CEST53636918.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:21.709351063 CEST6369253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:21.729496956 CEST53636928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:21.888966084 CEST5782453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:22.898207903 CEST5782453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:22.926181078 CEST53578248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:22.935939074 CEST5782553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:22.956406116 CEST53578258.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:22.956962109 CEST5782653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:22.978058100 CEST53578268.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:22.978908062 CEST5782753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:22.999502897 CEST53578278.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:23.000022888 CEST5782853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:23.021095037 CEST53578288.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:23.021548986 CEST5782953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:23.042824030 CEST53578298.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:23.209656954 CEST5274153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:23.514621973 CEST53578248.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:23.968266010 CEST53527418.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:23.980442047 CEST5274253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:23.997780085 CEST53527428.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:23.998657942 CEST5274353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:24.018424988 CEST53527438.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:24.019182920 CEST5274453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:24.039185047 CEST53527448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:24.040007114 CEST5274553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:24.059684038 CEST53527458.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:24.060420036 CEST5274653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:24.078253031 CEST53527468.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:24.239500046 CEST6064453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.226500988 CEST6064453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.255103111 CEST53606448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.263760090 CEST6064553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.281069994 CEST53606458.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.281759977 CEST6064653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.299524069 CEST53606468.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.300157070 CEST6064753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.319861889 CEST53606478.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.320561886 CEST6064853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.340485096 CEST53606488.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.341169119 CEST6064953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.361062050 CEST53606498.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.538189888 CEST5595153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.566684961 CEST53559518.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.576621056 CEST5595253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.593641996 CEST53559528.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.594151020 CEST5595353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.611632109 CEST53559538.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.612011909 CEST5595453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.631575108 CEST53559548.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.632008076 CEST5595553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.649888039 CEST53559558.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.650229931 CEST5595653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.669991970 CEST53559568.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:25.840779066 CEST5159253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:25.946975946 CEST53606448.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.542138100 CEST53636878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.836159945 CEST5159253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:26.874851942 CEST53515928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.882740974 CEST5159353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:26.904150963 CEST53515938.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.907030106 CEST5159453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:26.929198980 CEST53515948.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.929732084 CEST5159553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:26.951956987 CEST53515958.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.954768896 CEST5159653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:26.976304054 CEST53515968.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.976847887 CEST5159753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:26.997859001 CEST53515978.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:26.998966932 CEST53515928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:27.174635887 CEST6135953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.164587021 CEST6135953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.328942060 CEST53613598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.343839884 CEST6136053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.362921000 CEST53613608.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.363595009 CEST6136153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.383085012 CEST53613618.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.520062923 CEST6136253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.538108110 CEST53613628.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.538480043 CEST6136353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.558254004 CEST53613638.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.558638096 CEST6136453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:28.578342915 CEST53613648.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.692234039 CEST53613598.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:28.762604952 CEST5848053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:29.338186979 CEST53584808.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:29.344712973 CEST5848153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:29.362001896 CEST53584818.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:29.362481117 CEST5848253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:29.383466005 CEST53584828.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:29.383908987 CEST5848353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:29.401654959 CEST53584838.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:29.402066946 CEST5848453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:29.423216105 CEST53584848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:30.012593985 CEST5848553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:30.033303976 CEST53584858.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:30.204734087 CEST5188953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:30.819206953 CEST53518898.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:30.891808033 CEST5189053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:30.911178112 CEST53518908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:31.975245953 CEST5189153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:31.996062040 CEST53518918.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:31.996526957 CEST5189253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.016911030 CEST53518928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.036712885 CEST5189353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.055161953 CEST53518938.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.055555105 CEST5189453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.077513933 CEST53518948.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.280885935 CEST6041853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.328344107 CEST53604188.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.339962959 CEST6041953192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.360487938 CEST53604198.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.361099958 CEST6042053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.381845951 CEST53604208.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.382333040 CEST6042153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.402843952 CEST53604218.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.403374910 CEST6042253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.423881054 CEST53604228.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.424187899 CEST6042353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:32.444027901 CEST53604238.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:32.614773035 CEST5428353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.602144957 CEST5428353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.662503004 CEST53542838.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:33.674870014 CEST5428453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.694170952 CEST53542848.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:33.695070028 CEST5428553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.714600086 CEST53542858.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:33.715890884 CEST5428653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.735584974 CEST53542868.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:33.736226082 CEST5428753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.755711079 CEST53542878.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:33.756469965 CEST5428853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:33.774130106 CEST53542888.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:33.940355062 CEST5976353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.005925894 CEST53597638.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:34.015136957 CEST5976453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.032443047 CEST53597648.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:34.032989979 CEST5976553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.052963972 CEST53597658.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:34.053456068 CEST5976653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.075452089 CEST53597668.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:34.075906992 CEST5976753192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.093806982 CEST53597678.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:34.095324039 CEST5976853192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.114725113 CEST53597688.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:34.286489964 CEST5443153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:34.727765083 CEST53542838.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:35.289774895 CEST5443153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:35.952977896 CEST53544318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:35.959451914 CEST5443253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:35.979208946 CEST53544328.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:35.979600906 CEST5443353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:36.000792027 CEST53544338.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:36.001168966 CEST5443453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:36.022969007 CEST53544348.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:36.023380995 CEST5443553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:36.044903994 CEST53544358.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:36.045305967 CEST5443653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:36.066387892 CEST53544368.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:36.244251013 CEST6546153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.243447065 CEST6546153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.278584003 CEST53654618.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:37.287781000 CEST6546253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.308661938 CEST53654628.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:37.309587002 CEST6546353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.330910921 CEST53654638.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:37.331573009 CEST6546453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.351093054 CEST53654648.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:37.351948977 CEST6546553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.372787952 CEST53654658.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:37.373698950 CEST6546653192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:37.393057108 CEST53654668.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:37.563853979 CEST5009053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.572907925 CEST5009053192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.649069071 CEST53500908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:38.657994032 CEST5009153192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.677830935 CEST53500918.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:38.678469896 CEST5009253192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.699517965 CEST53500928.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:38.699985027 CEST5009353192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.719789982 CEST53500938.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:38.722516060 CEST5009453192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.740737915 CEST53500948.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:38.741457939 CEST5009553192.168.2.38.8.8.8
                                    Sep 1, 2022 00:03:38.761935949 CEST53500958.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:39.094896078 CEST53544318.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:40.677587986 CEST53500908.8.8.8192.168.2.3
                                    Sep 1, 2022 00:03:41.002669096 CEST53654618.8.8.8192.168.2.3
                                    TimestampSource IPDest IPChecksumCodeType
                                    Sep 1, 2022 00:01:39.520570993 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:01:40.783612013 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:01:50.793490887 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:01:52.259394884 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:01.915915966 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:11.967726946 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:12.999253988 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:14.387639999 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:17.505326033 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:18.912524939 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:19.930841923 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:22.074431896 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:26.716536045 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:27.817651033 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:33.986866951 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:39.027971983 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:42.283472061 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:47.096530914 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:53.169331074 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:54.727473974 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:02:57.449881077 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:01.595396042 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:02.946669102 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:03.968327999 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:06.090796947 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:15.886845112 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:17.783652067 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:19.698307991 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:23.514821053 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:25.947057962 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:26.542293072 CEST192.168.2.38.8.8.8cff3(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:28.692326069 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:34.727960110 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:39.095027924 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    Sep 1, 2022 00:03:40.678124905 CEST192.168.2.38.8.8.8d030(Port unreachable)Destination Unreachable
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                    Sep 1, 2022 00:01:23.064902067 CEST192.168.2.38.8.8.80x6ee5Standard query (0)ipv4bot.whatismyipaddress.comA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:23.994477034 CEST192.168.2.38.8.8.80x76aeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:24.049179077 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:24.068248034 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:24.090037107 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:24.124614954 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:24.145241976 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:25.247797012 CEST192.168.2.38.8.8.80xb801Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:25.310718060 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:25.328521967 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:25.347117901 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:25.367458105 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:25.385521889 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:26.844472885 CEST192.168.2.38.8.8.80xa52fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:27.464441061 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:27.482734919 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:27.503001928 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:27.526552916 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:27.550731897 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:33.534245014 CEST192.168.2.38.8.8.80x9347Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:34.150069952 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:34.170593023 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:34.192981005 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:34.214782953 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:34.235760927 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:35.764401913 CEST192.168.2.38.8.8.80x69c7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:36.800379992 CEST192.168.2.38.8.8.80x69c7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:37.845704079 CEST192.168.2.38.8.8.80x69c7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:38.440474033 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:38.460692883 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:38.479108095 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:38.500366926 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:38.529181004 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:39.759217024 CEST192.168.2.38.8.8.80xc269Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:39.895581007 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:39.931324959 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:39.951734066 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:39.971865892 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:39.990387917 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:41.157733917 CEST192.168.2.38.8.8.80xf1f3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.261158943 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:41.280695915 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.302395105 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:41.321666956 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.349610090 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:42.602513075 CEST192.168.2.38.8.8.80x8baStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:42.666846037 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:42.686131001 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:42.707643986 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:42.729662895 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:42.750967026 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:43.750798941 CEST192.168.2.38.8.8.80x25e1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:43.818617105 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:43.838372946 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:43.859132051 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:43.883100033 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:43.903173923 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:44.873297930 CEST192.168.2.38.8.8.80x51fbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:45.432225943 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:45.451637030 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:45.473540068 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:45.495695114 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:45.515640020 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:46.825660944 CEST192.168.2.38.8.8.80xb432Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:46.895714045 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:46.914019108 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:46.934129953 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:46.954180956 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:46.974641085 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:47.966227055 CEST192.168.2.38.8.8.80x1543Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:48.969243050 CEST192.168.2.38.8.8.80x1543Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.027492046 CEST192.168.2.38.8.8.80x1543Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.193775892 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:50.247028112 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.267332077 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:50.489646912 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.543832064 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:52.586035013 CEST192.168.2.38.8.8.80x84Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.206665039 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:53.226526976 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.251460075 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:53.271847010 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.290249109 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:54.258793116 CEST192.168.2.38.8.8.80x1368Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:54.856652975 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:54.875889063 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:54.898417950 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:54.918395996 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:54.940366030 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:55.904305935 CEST192.168.2.38.8.8.80xb069Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:56.898372889 CEST192.168.2.38.8.8.80xb069Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:57.597537994 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:57.617695093 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:57.638087034 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:57.658266068 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:57.681284904 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:58.788856030 CEST192.168.2.38.8.8.80x34aeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:59.402009010 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:59.423880100 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:59.444335938 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:01:59.462826967 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:59.483040094 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:00.502871990 CEST192.168.2.38.8.8.80x6c80Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:00.582490921 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:00.604247093 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:00.624524117 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:00.646017075 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:00.665796041 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:01.677488089 CEST192.168.2.38.8.8.80xe958Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:01.768798113 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:01.788641930 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:01.814516068 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:01.832803965 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:01.851233959 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:02.841990948 CEST192.168.2.38.8.8.80xb441Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:02.966444016 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:02.984507084 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:03.004766941 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:03.023139000 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:03.043257952 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:04.111052990 CEST192.168.2.38.8.8.80xf2b7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:04.748806953 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:04.768620968 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:04.790776014 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:04.820486069 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:04.842170000 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:05.931890965 CEST192.168.2.38.8.8.80x3f9eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:06.949732065 CEST192.168.2.38.8.8.80x3f9eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:07.982110023 CEST192.168.2.38.8.8.80x3f9eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:10.088450909 CEST192.168.2.38.8.8.80x3f9eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:11.685623884 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:11.706173897 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:11.726578951 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:11.746819973 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:11.767488003 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:12.846661091 CEST192.168.2.38.8.8.80xfea3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:13.892630100 CEST192.168.2.38.8.8.80xfea3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:14.908216953 CEST192.168.2.38.8.8.80xfea3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:14.995146036 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:15.015451908 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:15.036326885 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:15.057233095 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:15.078815937 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:15.420219898 CEST192.168.2.38.8.8.80x80a9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.408524990 CEST192.168.2.38.8.8.80x80a9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.468611002 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:16.489371061 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.509694099 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:16.532569885 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.558553934 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:16.953728914 CEST192.168.2.38.8.8.80x731Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:17.000292063 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:17.026690006 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:17.049623013 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:17.069143057 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:17.089606047 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:17.824410915 CEST192.168.2.38.8.8.80x84cbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.368638039 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:18.389777899 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.409895897 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:18.428585052 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.458137989 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:18.825237036 CEST192.168.2.38.8.8.80x49eaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.409481049 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:19.430994987 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.450711966 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:19.472414017 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.492209911 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:19.849414110 CEST192.168.2.38.8.8.80xeae8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.932447910 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:19.952318907 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.973756075 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:19.994369984 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:20.014611959 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:20.450695992 CEST192.168.2.38.8.8.80xc65dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:21.440356970 CEST192.168.2.38.8.8.80xc65dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.031480074 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:22.051454067 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.069673061 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:22.089884996 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.108885050 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:22.575946093 CEST192.168.2.38.8.8.80x4e9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:23.581091881 CEST192.168.2.38.8.8.80x4e9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.596934080 CEST192.168.2.38.8.8.80x4e9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.728225946 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:24.749273062 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.770961046 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:24.792802095 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.814615965 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:25.179150105 CEST192.168.2.38.8.8.80x7b7eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.190792084 CEST192.168.2.38.8.8.80x7b7eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.252104998 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:26.273853064 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.294404984 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:26.312895060 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.333412886 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:26.695220947 CEST192.168.2.38.8.8.80xd306Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.750152111 CEST192.168.2.38.8.8.80xd306Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.858907938 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:27.883460045 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.905128002 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:27.969558001 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.993076086 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:29.601125002 CEST192.168.2.38.8.8.80xefc8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.371490955 CEST192.168.2.38.8.8.80xefc8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.404072046 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:32.423641920 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.443413973 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:32.467434883 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.489443064 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:32.867223024 CEST192.168.2.38.8.8.80x4560Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:33.862488031 CEST192.168.2.38.8.8.80x4560Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.417866945 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:34.435885906 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.463043928 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:34.497220993 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.518929958 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:34.851964951 CEST192.168.2.38.8.8.80xbc32Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.437273979 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:35.455212116 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.476502895 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:35.496675014 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.516824961 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:35.859457016 CEST192.168.2.38.8.8.80x55acStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.995635033 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:36.017096996 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:36.035378933 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:36.053729057 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:36.072251081 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:36.459953070 CEST192.168.2.38.8.8.80xf2bbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:37.472609997 CEST192.168.2.38.8.8.80xf2bbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.497634888 CEST192.168.2.38.8.8.80xf2bbStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.640486956 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:38.660218000 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.683294058 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:38.719558001 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.738598108 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:39.088742971 CEST192.168.2.38.8.8.80x7eeaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.691652060 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:39.711365938 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.730597973 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:39.751533031 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.772185087 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:40.153419018 CEST192.168.2.38.8.8.80x6727Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.172076941 CEST192.168.2.38.8.8.80x6727Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.842334986 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:41.862104893 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.882664919 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:41.903320074 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.921899080 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:42.277318001 CEST192.168.2.38.8.8.80x27eeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.285449982 CEST192.168.2.38.8.8.80x27eeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.328716993 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:43.346779108 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.367193937 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:43.387386084 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.405654907 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:43.751919985 CEST192.168.2.38.8.8.80xdd39Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.286156893 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:44.306859970 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.327136040 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:44.347197056 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.367091894 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:44.774935961 CEST192.168.2.38.8.8.80x7cf8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.827179909 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:44.846894979 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.867082119 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:44.887150049 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.909322977 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:45.564925909 CEST192.168.2.38.8.8.80xa05dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.551074982 CEST192.168.2.38.8.8.80xa05dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.632401943 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:46.656883001 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.678054094 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:46.696702003 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.717207909 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:47.066291094 CEST192.168.2.38.8.8.80xb75eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.102243900 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:47.119975090 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.139273882 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:47.160135031 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.180254936 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:48.143838882 CEST192.168.2.38.8.8.80x9344Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.243660927 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:48.263272047 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.283085108 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:48.340517998 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.360270023 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:48.992279053 CEST192.168.2.38.8.8.80x9098Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:49.039655924 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:49.105935097 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:49.126044989 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:49.146584034 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:49.211679935 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:50.544686079 CEST192.168.2.38.8.8.80xc31fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.608259916 CEST192.168.2.38.8.8.80xc31fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.628920078 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:52.648139954 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.669550896 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:52.691628933 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.764321089 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:53.163081884 CEST192.168.2.38.8.8.80xddd1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.207458973 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:53.228133917 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.250638962 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:53.276937962 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.296910048 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:53.660832882 CEST192.168.2.38.8.8.80x1ccaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.678829908 CEST192.168.2.38.8.8.80x1ccaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.715509892 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:54.735838890 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.755738974 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:54.777870893 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.805593014 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:55.193733931 CEST192.168.2.38.8.8.80x7331Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.231367111 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:55.260307074 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.282820940 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:55.304130077 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.325848103 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:55.844996929 CEST192.168.2.38.8.8.80x8ac0Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.932115078 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:55.953111887 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.974494934 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:55.995863914 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:56.017085075 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:56.404357910 CEST192.168.2.38.8.8.80xc34eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.411904097 CEST192.168.2.38.8.8.80xc34eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.447629929 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:57.467935085 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.492444992 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:57.512286901 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.542714119 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:02:57.924940109 CEST192.168.2.38.8.8.80xe6aaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:58.928544044 CEST192.168.2.38.8.8.80xe6aaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:59.943011045 CEST192.168.2.38.8.8.80xe6aaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:00.017366886 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:00.036817074 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:00.057399988 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:00.076893091 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:00.100399017 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:00.563648939 CEST192.168.2.38.8.8.80x1eaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.554763079 CEST192.168.2.38.8.8.80x1eaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.601682901 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:01.623106956 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.644612074 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:01.665771961 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.687030077 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:02.153387070 CEST192.168.2.38.8.8.80x9670Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:02.801975012 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:02.822494030 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:02.844405890 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:02.900983095 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:02.922605991 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:03.343214035 CEST192.168.2.38.8.8.80x101cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.427838087 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:03.448040962 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.466197014 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:03.486265898 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.506251097 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:03.962084055 CEST192.168.2.38.8.8.80x1236Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:04.974921942 CEST192.168.2.38.8.8.80x1236Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.594440937 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:05.617213011 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.639385939 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:05.661525011 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.683602095 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:06.123651028 CEST192.168.2.38.8.8.80x32f7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.260365963 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:06.280270100 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.300781012 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:06.319112062 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.339869022 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:06.701911926 CEST192.168.2.38.8.8.80xf50dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:07.240674019 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:07.276021957 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:07.301197052 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:07.325311899 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:07.346616983 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:08.098186970 CEST192.168.2.38.8.8.80x5b1cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:08.720036983 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:08.745096922 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:08.807703018 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:08.828383923 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:08.846909046 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:11.312613964 CEST192.168.2.38.8.8.80xb93eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:13.124238968 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:13.145962954 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:13.168036938 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:13.188986063 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:13.209944010 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:13.699589014 CEST192.168.2.38.8.8.80x78aaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:14.710131884 CEST192.168.2.38.8.8.80x78aaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.711199999 CEST192.168.2.38.8.8.80x78aaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.883177996 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:15.903464079 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.922110081 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:15.942186117 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.960644960 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:16.393064976 CEST192.168.2.38.8.8.80xd2e7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:17.397872925 CEST192.168.2.38.8.8.80xd2e7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.001125097 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:18.020601034 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.040652990 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:18.060822964 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.082511902 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:18.621407986 CEST192.168.2.38.8.8.80xe3b2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.657192945 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:18.677170992 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.697258949 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:18.717463970 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.737468004 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:19.167845011 CEST192.168.2.38.8.8.80x6266Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.219196081 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:19.239136934 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.259211063 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:19.277164936 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.297074080 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:19.834583998 CEST192.168.2.38.8.8.80x8bb8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.952431917 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:19.972138882 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.992460012 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:20.011368036 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.034172058 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:20.228393078 CEST192.168.2.38.8.8.80x3233Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.265758991 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:20.284135103 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.304409027 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:20.324394941 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.348262072 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:20.534615040 CEST192.168.2.38.8.8.80x9a4bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.523137093 CEST192.168.2.38.8.8.80x9a4bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.620418072 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:21.642301083 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.664385080 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:21.687511921 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.709351063 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:21.888966084 CEST192.168.2.38.8.8.80x6c47Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:22.898207903 CEST192.168.2.38.8.8.80x6c47Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:22.935939074 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:22.956962109 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:22.978908062 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:23.000022888 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:23.021548986 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:23.209656954 CEST192.168.2.38.8.8.80x878dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:23.980442047 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:23.998657942 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:24.019182920 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:24.040007114 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:24.060420036 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:24.239500046 CEST192.168.2.38.8.8.80xa1caStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.226500988 CEST192.168.2.38.8.8.80xa1caStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.263760090 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:25.281759977 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.300157070 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:25.320561886 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.341169119 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:25.538189888 CEST192.168.2.38.8.8.80xa11dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.576621056 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:25.594151020 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.612011909 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:25.632008076 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.650229931 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:25.840779066 CEST192.168.2.38.8.8.80xc72eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.836159945 CEST192.168.2.38.8.8.80xc72eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.882740974 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:26.907030106 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.929732084 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:26.954768896 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.976847887 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:27.174635887 CEST192.168.2.38.8.8.80xb6eaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.164587021 CEST192.168.2.38.8.8.80xb6eaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.343839884 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:28.363595009 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.520062923 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:28.538480043 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.558638096 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:28.762604952 CEST192.168.2.38.8.8.80xe04eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:29.344712973 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:29.362481117 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:29.383908987 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:29.402066946 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:30.012593985 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:30.204734087 CEST192.168.2.38.8.8.80x83d5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:30.891808033 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:31.975245953 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:31.996526957 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:32.036712885 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.055555105 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:32.280885935 CEST192.168.2.38.8.8.80x14b6Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.339962959 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:32.361099958 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.382333040 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:32.403374910 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.424187899 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:32.614773035 CEST192.168.2.38.8.8.80xedcaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.602144957 CEST192.168.2.38.8.8.80xedcaStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.674870014 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:33.695070028 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.715890884 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:33.736226082 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.756469965 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:33.940355062 CEST192.168.2.38.8.8.80xa3fcStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:34.015136957 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:34.032989979 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:34.053456068 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:34.075906992 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:34.095324039 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:34.286489964 CEST192.168.2.38.8.8.80xbc05Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:35.289774895 CEST192.168.2.38.8.8.80xbc05Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:35.959451914 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:35.979600906 CEST192.168.2.38.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:36.001168966 CEST192.168.2.38.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:36.023380995 CEST192.168.2.38.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:36.045305967 CEST192.168.2.38.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:36.244251013 CEST192.168.2.38.8.8.80x25c4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.243447065 CEST192.168.2.38.8.8.80x25c4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.287781000 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:37.309587002 CEST192.168.2.38.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.331573009 CEST192.168.2.38.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:37.351948977 CEST192.168.2.38.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.373698950 CEST192.168.2.38.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:37.563853979 CEST192.168.2.38.8.8.80x8bcStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.572907925 CEST192.168.2.38.8.8.80x8bcStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.657994032 CEST192.168.2.38.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:38.678469896 CEST192.168.2.38.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.699985027 CEST192.168.2.38.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                    Sep 1, 2022 00:03:38.722516060 CEST192.168.2.38.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.741457939 CEST192.168.2.38.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                    Sep 1, 2022 00:01:24.030497074 CEST8.8.8.8192.168.2.30x76aeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:24.067482948 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:24.088715076 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:24.110754013 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:24.144764900 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:24.164725065 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:25.283262014 CEST8.8.8.8192.168.2.30xb801Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:25.327796936 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:25.346643925 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:25.366964102 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:25.385024071 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:25.405503035 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:27.449457884 CEST8.8.8.8192.168.2.30xa52fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:27.481861115 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:27.502418995 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:27.520689964 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:27.550129890 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:27.573137045 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:34.108952045 CEST8.8.8.8192.168.2.30x9347Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:34.169861078 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:34.192428112 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:34.214257956 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:34.234899998 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:34.256675959 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:38.424983025 CEST8.8.8.8192.168.2.30x69c7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:38.459913969 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:38.478588104 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:38.499536037 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:38.522388935 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:38.547306061 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:39.520437956 CEST8.8.8.8192.168.2.30x69c7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:39.869720936 CEST8.8.8.8192.168.2.30xc269Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:39.914973974 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:39.951137066 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:39.971240997 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:39.989907026 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:40.010957003 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:40.783550978 CEST8.8.8.8192.168.2.30x69c7Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.194181919 CEST8.8.8.8192.168.2.30xf1f3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.280056000 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:41.300605059 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.320178032 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:41.341320992 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:41.369268894 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:42.639774084 CEST8.8.8.8192.168.2.30x8baName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:42.685431004 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:42.707127094 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:42.729058981 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:42.750449896 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:42.771682978 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:43.786712885 CEST8.8.8.8192.168.2.30x25e1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:43.837654114 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:43.857835054 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:43.878863096 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:43.902585030 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:43.922862053 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:45.412717104 CEST8.8.8.8192.168.2.30x51fbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:45.450937986 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:45.472791910 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:45.495043039 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:45.514930964 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:45.535151958 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:46.863656044 CEST8.8.8.8192.168.2.30xb432Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:46.913108110 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:46.933680058 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:46.953710079 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:46.973721981 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:46.994463921 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:50.163376093 CEST8.8.8.8192.168.2.30x1543Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.211262941 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:50.265369892 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.285290956 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:50.507364035 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:50.561597109 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:50.793282986 CEST8.8.8.8192.168.2.30x1543Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:52.259315968 CEST8.8.8.8192.168.2.30x1543Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.162805080 CEST8.8.8.8192.168.2.30x84Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.225925922 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:53.246345043 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.271325111 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:53.289664030 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:53.310367107 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:54.812717915 CEST8.8.8.8192.168.2.30x1368Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:54.875181913 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:54.897751093 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:54.917856932 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:54.939847946 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:54.961664915 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:57.544912100 CEST8.8.8.8192.168.2.30xb069Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:57.616928101 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:57.637340069 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:57.657670021 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:57.680296898 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:57.700737000 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:59.361457109 CEST8.8.8.8192.168.2.30x34aeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:59.421237946 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:01:59.443866014 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:59.462193966 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:01:59.482578039 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:01:59.500787973 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:00.540338039 CEST8.8.8.8192.168.2.30x6c80Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:00.602976084 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:00.623477936 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:00.645464897 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:00.665227890 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:00.686867952 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:01.711468935 CEST8.8.8.8192.168.2.30xe958Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:01.787820101 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:01.813957930 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:01.832298040 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:01.850697994 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:01.870028019 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:01.915724039 CEST8.8.8.8192.168.2.30xb069Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:02.924088001 CEST8.8.8.8192.168.2.30xb441Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:02.983864069 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:03.004199028 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:03.022608995 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:03.041289091 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:03.060731888 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:04.694045067 CEST8.8.8.8192.168.2.30xf2b7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:04.767615080 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:04.790055037 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:04.812170982 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:04.841615915 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:04.861390114 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:10.950472116 CEST8.8.8.8192.168.2.30x3f9eServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:11.704813957 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:11.725864887 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:11.746112108 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:11.766913891 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:11.787333965 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:11.967653036 CEST8.8.8.8192.168.2.30x3f9eServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:12.999161005 CEST8.8.8.8192.168.2.30x3f9eServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:14.387511015 CEST8.8.8.8192.168.2.30x3f9eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:14.971482038 CEST8.8.8.8192.168.2.30xfea3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:15.014755964 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:15.035367012 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:15.056536913 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:15.078147888 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:15.099627018 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:16.448688984 CEST8.8.8.8192.168.2.30x80a9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.488795042 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:16.509176016 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.530898094 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:16.553879023 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:16.580022097 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:16.991344929 CEST8.8.8.8192.168.2.30x731Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:17.021205902 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:17.048921108 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:17.068710089 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:17.089041948 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:17.109560966 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:17.505155087 CEST8.8.8.8192.168.2.30x80a9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.361676931 CEST8.8.8.8192.168.2.30x84cbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.389043093 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:18.408541918 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.427966118 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:18.449790001 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:18.479060888 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:18.912440062 CEST8.8.8.8192.168.2.30xfea3Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.401741028 CEST8.8.8.8192.168.2.30x49eaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.430453062 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:19.450289965 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.471883059 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:19.491760969 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.512691975 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:19.925700903 CEST8.8.8.8192.168.2.30xeae8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.930727959 CEST8.8.8.8192.168.2.30xfea3Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.951675892 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:19.970587015 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:19.993907928 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:20.013947010 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:20.035240889 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:22.022486925 CEST8.8.8.8192.168.2.30xc65dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.050517082 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:22.069267035 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.074369907 CEST8.8.8.8192.168.2.30xc65dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.089488983 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:22.108500004 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:22.129991055 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:24.712889910 CEST8.8.8.8192.168.2.30x4e9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.748702049 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:24.770515919 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.792413950 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:24.814188957 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:24.833614111 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:26.233566046 CEST8.8.8.8192.168.2.30x7b7eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.270071030 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:26.293915987 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.312290907 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:26.332462072 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.352917910 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:26.714562893 CEST8.8.8.8192.168.2.30x4e9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:26.841078043 CEST8.8.8.8192.168.2.30x4e9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.386841059 CEST8.8.8.8192.168.2.30x7b7eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.784187078 CEST8.8.8.8192.168.2.30xd306Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.817483902 CEST8.8.8.8192.168.2.30xd306Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.877135992 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:27.904680967 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:27.926455975 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:27.989053965 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:28.014046907 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:30.826258898 CEST8.8.8.8192.168.2.30xefc8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.422898054 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:32.442924023 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.465111017 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:32.486720085 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:32.510637999 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:33.985611916 CEST8.8.8.8192.168.2.30xefc8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.407073975 CEST8.8.8.8192.168.2.30x4560Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.435112000 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:34.459167957 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.484791994 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:34.489913940 CEST8.8.8.8192.168.2.30x4560Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.517954111 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:34.537820101 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:35.427285910 CEST8.8.8.8192.168.2.30xbc32Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.454541922 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:35.475027084 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.496222973 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:35.516345024 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:35.536685944 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:35.984587908 CEST8.8.8.8192.168.2.30x55acName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:36.012811899 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:36.034972906 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:36.053332090 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:36.071810961 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:36.091907978 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:38.631139994 CEST8.8.8.8192.168.2.30xf2bbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.659338951 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:38.680645943 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.701905012 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:38.738066912 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:38.759218931 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:39.027879000 CEST8.8.8.8192.168.2.30xf2bbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.143616915 CEST8.8.8.8192.168.2.30xf2bbName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.675185919 CEST8.8.8.8192.168.2.30x7eeaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.710722923 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:39.729000092 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.750302076 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:39.771075010 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:39.791596889 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:41.822036982 CEST8.8.8.8192.168.2.30x6727Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.861427069 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:41.881999969 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.902828932 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:41.921314955 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:41.941456079 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:42.283397913 CEST8.8.8.8192.168.2.30x6727Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.320070028 CEST8.8.8.8192.168.2.30x27eeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.345973015 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:43.366689920 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.386923075 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:43.405071020 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:43.425419092 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:44.279233932 CEST8.8.8.8192.168.2.30xdd39Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.305149078 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:44.326653957 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.346456051 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:44.366677999 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.386941910 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:44.819075108 CEST8.8.8.8192.168.2.30x7cf8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.846179008 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:44.864609003 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.886693001 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:44.908752918 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:44.929284096 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:46.625612020 CEST8.8.8.8192.168.2.30xa05dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.652822018 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:46.677609921 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.696248055 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:46.716310978 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:46.736613989 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:47.092792034 CEST8.8.8.8192.168.2.30xb75eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.096024036 CEST8.8.8.8192.168.2.30xa05dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.119285107 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:47.137702942 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.159663916 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:47.179497957 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:47.199672937 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:47.295221090 CEST8.8.8.8192.168.2.30x27eeServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.169800997 CEST8.8.8.8192.168.2.30x9344Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.262660027 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:48.282622099 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.302493095 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:48.359857082 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:48.378109932 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:49.030847073 CEST8.8.8.8192.168.2.30x9098Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:49.060447931 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:49.125612974 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:49.145709991 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:49.164716959 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:49.230854988 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:51.666511059 CEST8.8.8.8192.168.2.30xc31fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.647394896 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:52.669127941 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.691092014 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:52.712511063 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:52.786346912 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:53.169249058 CEST8.8.8.8192.168.2.30xc31fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.199151039 CEST8.8.8.8192.168.2.30xddd1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.227545977 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:53.250277996 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.274090052 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:53.296488047 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:53.315620899 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:54.707915068 CEST8.8.8.8192.168.2.30x1ccaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.727380991 CEST8.8.8.8192.168.2.30x1ccaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.735213995 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:54.755316019 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.777358055 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:54.797842026 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:54.826921940 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:55.222019911 CEST8.8.8.8192.168.2.30x7331Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.248954058 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:55.282449961 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.303663969 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:55.325366020 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.344696999 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:55.919511080 CEST8.8.8.8192.168.2.30x8ac0Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.952475071 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:55.974069118 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:55.995476007 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:56.016655922 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:56.038196087 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:57.439387083 CEST8.8.8.8192.168.2.30xc34eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.449079037 CEST8.8.8.8192.168.2.30xc34eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.467147112 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:02:57.488708973 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.511897087 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:02:57.530978918 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:02:57.561358929 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:00.010236025 CEST8.8.8.8192.168.2.30xe6aaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:00.035882950 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:00.057038069 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:00.076392889 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:00.097615957 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:00.121129990 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:01.584554911 CEST8.8.8.8192.168.2.30x1eaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.595273972 CEST8.8.8.8192.168.2.30x1eaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.622442007 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:01.644107103 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.665334940 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:01.686562061 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:01.706001043 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:02.779787064 CEST8.8.8.8192.168.2.30x9670Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:02.821990013 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:02.843368053 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:02.865358114 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:02.922287941 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:02.942126989 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:02.945770025 CEST8.8.8.8192.168.2.30xe6aaServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.418770075 CEST8.8.8.8192.168.2.30x101cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.446106911 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:03.465781927 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.485872984 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:03.505850077 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:03.524724007 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:03.967163086 CEST8.8.8.8192.168.2.30xe6aaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.580583096 CEST8.8.8.8192.168.2.30x1236Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.616434097 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:05.638950109 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.661201954 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:05.683096886 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:05.704983950 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:06.090673923 CEST8.8.8.8192.168.2.30x1236Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.253566980 CEST8.8.8.8192.168.2.30x32f7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.279741049 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:06.300148010 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.318766117 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:06.339133978 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:06.360065937 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:07.230133057 CEST8.8.8.8192.168.2.30xf50dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:07.261197090 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:07.297318935 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:07.321963072 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:07.345874071 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:07.367491961 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:08.672029018 CEST8.8.8.8192.168.2.30x5b1cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:08.740346909 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:08.766110897 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:08.827946901 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:08.846530914 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:08.866904974 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:11.907406092 CEST8.8.8.8192.168.2.30xb93eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:13.145453930 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:13.167514086 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:13.187902927 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:13.209469080 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:13.232753992 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:15.875538111 CEST8.8.8.8192.168.2.30x78aaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.886709929 CEST8.8.8.8192.168.2.30x78aaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.902874947 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:15.921664953 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.941783905 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:15.960310936 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:15.978528023 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:17.783536911 CEST8.8.8.8192.168.2.30x78aaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:17.989558935 CEST8.8.8.8192.168.2.30xd2e7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.019994974 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:18.040131092 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.060370922 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:18.080894947 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.102590084 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:18.650096893 CEST8.8.8.8192.168.2.30xe3b2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.676616907 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:18.696774960 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.717092037 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:18.736999989 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:18.754909992 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:19.210956097 CEST8.8.8.8192.168.2.30x6266Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.238610029 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:19.258774996 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.276746988 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:19.296673059 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.316821098 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:19.696104050 CEST8.8.8.8192.168.2.30xd2e7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.938867092 CEST8.8.8.8192.168.2.30x8bb8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:19.971436024 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:19.991856098 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.010216951 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:20.031111956 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.051709890 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:20.256568909 CEST8.8.8.8192.168.2.30x3233Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.283133984 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:20.303747892 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.323898077 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:20.344026089 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:20.366065979 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:21.609051943 CEST8.8.8.8192.168.2.30x9a4bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.641108990 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:21.663789988 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.686964035 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:21.708765030 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:21.729496956 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:22.926181078 CEST8.8.8.8192.168.2.30x6c47Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:22.956406116 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:22.978058100 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:22.999502897 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:23.021095037 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:23.042824030 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:23.514621973 CEST8.8.8.8192.168.2.30x6c47Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:23.968266010 CEST8.8.8.8192.168.2.30x878dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:23.997780085 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:24.018424988 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:24.039185047 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:24.059684038 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:24.078253031 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:25.255103111 CEST8.8.8.8192.168.2.30xa1caName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.281069994 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:25.299524069 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.319861889 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:25.340485096 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.361062050 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:25.566684961 CEST8.8.8.8192.168.2.30xa11dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.593641996 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:25.611632109 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.631575108 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:25.649888039 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:25.669991970 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:25.946975946 CEST8.8.8.8192.168.2.30xa1caName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.542138100 CEST8.8.8.8192.168.2.30x9a4bServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.874851942 CEST8.8.8.8192.168.2.30xc72eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.904150963 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:26.929198980 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.951956987 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:26.976304054 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:26.997859001 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:26.998966932 CEST8.8.8.8192.168.2.30xc72eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.328942060 CEST8.8.8.8192.168.2.30xb6eaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.362921000 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:28.383085012 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.538108110 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:28.558254004 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:28.578342915 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:28.692234039 CEST8.8.8.8192.168.2.30xb6eaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:29.338186979 CEST8.8.8.8192.168.2.30xe04eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:29.362001896 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:29.383466005 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:29.401654959 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:29.423216105 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:30.033303976 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:30.819206953 CEST8.8.8.8192.168.2.30x83d5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:30.911178112 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:31.996062040 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.016911030 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:32.055161953 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.077513933 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:32.328344107 CEST8.8.8.8192.168.2.30x14b6Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.360487938 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:32.381845951 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.402843952 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:32.423881054 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:32.444027901 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:33.662503004 CEST8.8.8.8192.168.2.30xedcaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.694170952 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:33.714600086 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.735584974 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:33.755711079 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:33.774130106 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:34.005925894 CEST8.8.8.8192.168.2.30xa3fcName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:34.032443047 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:34.052963972 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:34.075452089 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:34.093806982 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:34.114725113 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:34.727765083 CEST8.8.8.8192.168.2.30xedcaName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:35.952977896 CEST8.8.8.8192.168.2.30xbc05Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:35.979208946 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:36.000792027 CEST8.8.8.8192.168.2.30x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:36.022969007 CEST8.8.8.8192.168.2.30x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:36.044903994 CEST8.8.8.8192.168.2.30x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:36.066387892 CEST8.8.8.8192.168.2.30x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:37.278584003 CEST8.8.8.8192.168.2.30x25c4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.308661938 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:37.330910921 CEST8.8.8.8192.168.2.30x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.351093054 CEST8.8.8.8192.168.2.30x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:37.372787952 CEST8.8.8.8192.168.2.30x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:37.393057108 CEST8.8.8.8192.168.2.30x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:38.649069071 CEST8.8.8.8192.168.2.30x8bcName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.677830935 CEST8.8.8.8192.168.2.30x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                    Sep 1, 2022 00:03:38.699517965 CEST8.8.8.8192.168.2.30x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.719789982 CEST8.8.8.8192.168.2.30x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:38.740737915 CEST8.8.8.8192.168.2.30x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:38.761935949 CEST8.8.8.8192.168.2.30x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                    Sep 1, 2022 00:03:39.094896078 CEST8.8.8.8192.168.2.30xbc05Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:40.677587986 CEST8.8.8.8192.168.2.30x8bcName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                    Sep 1, 2022 00:03:41.002669096 CEST8.8.8.8192.168.2.30x25c4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)

                                    Click to jump to process

                                    Target ID:1
                                    Start time:00:01:12
                                    Start date:01/09/2022
                                    Path:C:\Users\user\Desktop\9gkAKTWOXp.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Users\user\Desktop\9gkAKTWOXp.exe"
                                    Imagebase:0x400000
                                    File size:75264 bytes
                                    MD5 hash:74E135B472B7496B371CE3BA3ACFEEA8
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Yara matches:
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000001.00000000.253403415.000000000040E000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000001.00000002.561907295.000000000040E000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                                    Reputation:low

                                    Target ID:5
                                    Start time:00:01:21
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:6
                                    Start time:00:01:22
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high

                                    Target ID:7
                                    Start time:00:01:23
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:8
                                    Start time:00:01:23
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high

                                    Target ID:9
                                    Start time:00:01:24
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:10
                                    Start time:00:01:25
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:high

                                    Target ID:12
                                    Start time:00:01:26
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:13
                                    Start time:00:01:27
                                    Start date:01/09/2022
                                    Path:C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe"
                                    Imagebase:0x400000
                                    File size:75264 bytes
                                    MD5 hash:551DA842D854798E9D42602EB420BD96
                                    Has elevated privileges:false
                                    Has administrator privileges:false
                                    Programmed in:C, C++ or other language
                                    Yara matches:
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000D.00000002.295326787.000000000040E000.00000004.00000001.01000000.00000006.sdmp, Author: Joe Security
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000D.00000000.288179215.000000000040E000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000D.00000002.295333499.0000000000412000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security
                                    • Rule: SUSP_RANSOMWARE_Indicator_Jul20, Description: Detects ransomware indicator, Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, Author: Florian Roth
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, Author: Joe Security
                                    • Rule: Gandcrab, Description: Gandcrab Payload, Source: C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe, Author: kevoreilly
                                    Antivirus matches:
                                    • Detection: 100%, Avira
                                    • Detection: 100%, Joe Sandbox ML
                                    Reputation:low

                                    Target ID:14
                                    Start time:00:01:31
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:16
                                    Start time:00:01:33
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:18
                                    Start time:00:01:33
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:21
                                    Start time:00:01:35
                                    Start date:01/09/2022
                                    Path:C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Users\user\AppData\Roaming\Microsoft\vkspii.exe"
                                    Imagebase:0x400000
                                    File size:75264 bytes
                                    MD5 hash:551DA842D854798E9D42602EB420BD96
                                    Has elevated privileges:false
                                    Has administrator privileges:false
                                    Programmed in:C, C++ or other language
                                    Yara matches:
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000015.00000002.305269157.000000000040E000.00000004.00000001.01000000.00000006.sdmp, Author: Joe Security
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000015.00000000.302558828.000000000040E000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security
                                    • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000015.00000002.305274923.0000000000412000.00000008.00000001.01000000.00000006.sdmp, Author: Joe Security

                                    Target ID:24
                                    Start time:00:01:37
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:25
                                    Start time:00:01:37
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:26
                                    Start time:00:01:38
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:27
                                    Start time:00:01:39
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:29
                                    Start time:00:01:40
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:30
                                    Start time:00:01:40
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff651c80000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:31
                                    Start time:00:01:41
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:32
                                    Start time:00:01:42
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:33
                                    Start time:00:01:42
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:34
                                    Start time:00:01:43
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:35
                                    Start time:00:01:44
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:36
                                    Start time:00:01:45
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:37
                                    Start time:00:01:45
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:39
                                    Start time:00:01:46
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:41
                                    Start time:00:01:50
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:42
                                    Start time:00:01:50
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:43
                                    Start time:00:01:52
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:44
                                    Start time:00:01:52
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:45
                                    Start time:00:01:53
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:46
                                    Start time:00:01:54
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:47
                                    Start time:00:01:56
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:48
                                    Start time:00:01:57
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff75a330000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:49
                                    Start time:00:01:58
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:50
                                    Start time:00:01:58
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:51
                                    Start time:00:01:59
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:52
                                    Start time:00:01:59
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:53
                                    Start time:00:02:00
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:54
                                    Start time:00:02:01
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:55
                                    Start time:00:02:01
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:56
                                    Start time:00:02:02
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:57
                                    Start time:00:02:03
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:58
                                    Start time:00:02:04
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:60
                                    Start time:00:02:10
                                    Start date:01/09/2022
                                    Path:C:\Windows\SysWOW64\nslookup.exe
                                    Wow64 process (32bit):true
                                    Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                    Imagebase:0x2c0000
                                    File size:78336 bytes
                                    MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    Target ID:61
                                    Start time:00:02:11
                                    Start date:01/09/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff745070000
                                    File size:625664 bytes
                                    MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language

                                    No disassembly