Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2fiDcmkaZY.exe

Overview

General Information

Sample Name:2fiDcmkaZY.exe
Analysis ID:694570
MD5:a8ac57500de5dadf8c4db19959ddf2ec
SHA1:202baa4b862222951619adc032fd2883562113b2
SHA256:fcc7cc8f57d5a2a525d8026e81f69318262ca4e9036a726e26b1e3406f6f52d5
Tags:exe
Infos:

Detection

Gandcrab
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Gandcrab
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Snort IDS alert for network traffic
Found evasive API chain (may stop execution after checking mutex)
Contains functionality to determine the online IP of the system
Found Tor onion address
Uses nslookup.exe to query domains
Machine Learning detection for sample
May check the online IP address of the machine
Machine Learning detection for dropped file
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
Too many similar processes found
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a DirectInput object (often for capturing keystrokes)
Queries information about the installed CPU (vendor, model number etc)
Drops PE files
Found evaded block containing many API calls
Contains functionality to enumerate device drivers
Checks for available system drives (often done to infect USB drives)
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • 2fiDcmkaZY.exe (PID: 6752 cmdline: "C:\Users\user\Desktop\2fiDcmkaZY.exe" MD5: A8AC57500DE5DADF8C4DB19959DDF2EC)
    • nslookup.exe (PID: 6896 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6920 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6972 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6980 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7032 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 7040 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7084 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 7092 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7144 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 7152 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5388 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5320 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6392 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 2992 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 3096 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5808 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5940 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5836 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6024 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6036 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5872 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6568 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6632 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6636 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5964 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6460 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6308 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6524 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6952 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6964 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6848 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6844 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7044 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5040 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7040 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 7036 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7104 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5684 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 7148 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 712 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 4556 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6092 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5844 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5888 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5976 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5944 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6564 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6028 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 5860 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 5892 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6608 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6588 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6032 cmdline: nslookup gandcrab.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6912 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6440 cmdline: nslookup nomoreransom.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6076 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • nslookup.exe (PID: 6460 cmdline: nslookup emsisoft.bit dns1.soprodns.ru MD5: 8E82529D1475D67615ADCB4E1B8F4EEC)
      • conhost.exe (PID: 6788 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • tdicrr.exe (PID: 1476 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe" MD5: D2E112FDFFC314778285E837BC0BED47)
  • tdicrr.exe (PID: 5864 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe" MD5: D2E112FDFFC314778285E837BC0BED47)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
2fiDcmkaZY.exeSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
  • 0xf716:$: DECRYPT.txt
  • 0xf784:$: DECRYPT.txt
2fiDcmkaZY.exeJoeSecurity_GandcrabYara detected GandcrabJoe Security
    2fiDcmkaZY.exeGandcrabGandcrab Payloadkevoreilly
    • 0xf70c:$string1: GDCB-DECRYPT.txt
    • 0xf77a:$string1: GDCB-DECRYPT.txt
    • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
    • 0xf716:$: DECRYPT.txt
    • 0xf784:$: DECRYPT.txt
    C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeJoeSecurity_GandcrabYara detected GandcrabJoe Security
      C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeGandcrabGandcrab Payloadkevoreilly
      • 0xf70c:$string1: GDCB-DECRYPT.txt
      • 0xf77a:$string1: GDCB-DECRYPT.txt
      • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
      SourceRuleDescriptionAuthorStrings
      0000000D.00000000.343462206.0000000000C79000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
        0000000D.00000002.346586335.0000000000C79000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
          00000014.00000002.363374033.0000000000C79000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
            00000000.00000000.304343043.0000000000A69000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
              00000014.00000000.360474661.0000000000C79000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_GandcrabYara detected GandcrabJoe Security
                Click to see the 4 entries
                SourceRuleDescriptionAuthorStrings
                13.0.tdicrr.exe.c70000.0.unpackSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
                • 0xf716:$: DECRYPT.txt
                • 0xf784:$: DECRYPT.txt
                13.0.tdicrr.exe.c70000.0.unpackJoeSecurity_GandcrabYara detected GandcrabJoe Security
                  13.0.tdicrr.exe.c70000.0.unpackGandcrabGandcrab Payloadkevoreilly
                  • 0xf70c:$string1: GDCB-DECRYPT.txt
                  • 0xf77a:$string1: GDCB-DECRYPT.txt
                  • 0xf460:$string3: action=result&e_files=%d&e_size=%I64u&e_time=%d&
                  20.0.tdicrr.exe.c70000.0.unpackSUSP_RANSOMWARE_Indicator_Jul20Detects ransomware indicatorFlorian Roth
                  • 0xf716:$: DECRYPT.txt
                  • 0xf784:$: DECRYPT.txt
                  20.0.tdicrr.exe.c70000.0.unpackJoeSecurity_GandcrabYara detected GandcrabJoe Security
                    Click to see the 13 entries
                    No Sigma rule has matched
                    Timestamp:192.168.2.58.8.8.860180532829500 09/01/22-00:02:50.502751
                    SID:2829500
                    Source Port:60180
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854371532026737 09/01/22-00:04:03.802921
                    SID:2026737
                    Source Port:54371
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858474532829498 09/01/22-00:02:46.409357
                    SID:2829498
                    Source Port:58474
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856690532026737 09/01/22-00:02:34.794476
                    SID:2026737
                    Source Port:56690
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852975532829500 09/01/22-00:03:40.177431
                    SID:2829500
                    Source Port:52975
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859224532829500 09/01/22-00:02:18.976716
                    SID:2829500
                    Source Port:59224
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853975532829500 09/01/22-00:02:39.645914
                    SID:2829500
                    Source Port:53975
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861348532829498 09/01/22-00:02:38.530362
                    SID:2829498
                    Source Port:61348
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860024532829498 09/01/22-00:02:55.250291
                    SID:2829498
                    Source Port:60024
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853827532026737 09/01/22-00:03:02.774286
                    SID:2026737
                    Source Port:53827
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860910532026737 09/01/22-00:03:28.310952
                    SID:2026737
                    Source Port:60910
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863730532829498 09/01/22-00:03:33.977550
                    SID:2829498
                    Source Port:63730
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860183532829498 09/01/22-00:03:48.283959
                    SID:2829498
                    Source Port:60183
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854587532829498 09/01/22-00:03:23.124735
                    SID:2829498
                    Source Port:54587
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850904532829500 09/01/22-00:02:58.051616
                    SID:2829500
                    Source Port:50904
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855070532026737 09/01/22-00:02:20.361607
                    SID:2026737
                    Source Port:55070
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850089532829500 09/01/22-00:03:18.466985
                    SID:2829500
                    Source Port:50089
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859587532829498 09/01/22-00:04:04.114751
                    SID:2829498
                    Source Port:59587
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855597532026737 09/01/22-00:04:09.936181
                    SID:2026737
                    Source Port:55597
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865325532026737 09/01/22-00:02:04.877624
                    SID:2026737
                    Source Port:65325
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862662532026737 09/01/22-00:02:25.469721
                    SID:2026737
                    Source Port:62662
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865120532829498 09/01/22-00:04:10.763289
                    SID:2829498
                    Source Port:65120
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861296532829498 09/01/22-00:03:15.496749
                    SID:2829498
                    Source Port:61296
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857484532026737 09/01/22-00:03:30.517521
                    SID:2026737
                    Source Port:57484
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858446532829498 09/01/22-00:03:43.925486
                    SID:2829498
                    Source Port:58446
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864315532829498 09/01/22-00:03:59.415810
                    SID:2829498
                    Source Port:64315
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865333532829498 09/01/22-00:03:39.670910
                    SID:2829498
                    Source Port:65333
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852193532026737 09/01/22-00:03:21.210468
                    SID:2026737
                    Source Port:52193
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852103532829500 09/01/22-00:03:27.689357
                    SID:2829500
                    Source Port:52103
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865119532829498 09/01/22-00:04:10.743391
                    SID:2829498
                    Source Port:65119
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850566532829500 09/01/22-00:04:04.976212
                    SID:2829500
                    Source Port:50566
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863448532829500 09/01/22-00:02:12.612834
                    SID:2829500
                    Source Port:63448
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862059532829500 09/01/22-00:03:32.850991
                    SID:2829500
                    Source Port:62059
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858476532829498 09/01/22-00:02:46.511401
                    SID:2829498
                    Source Port:58476
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862938532026737 09/01/22-00:03:42.736982
                    SID:2026737
                    Source Port:62938
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860181532829498 09/01/22-00:03:48.237956
                    SID:2829498
                    Source Port:60181
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858626532829498 09/01/22-00:03:28.872267
                    SID:2829498
                    Source Port:58626
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865328532026737 09/01/22-00:02:04.942715
                    SID:2026737
                    Source Port:65328
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864497532026737 09/01/22-00:03:56.326355
                    SID:2026737
                    Source Port:64497
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860286532026737 09/01/22-00:02:53.057441
                    SID:2026737
                    Source Port:60286
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853559532026737 09/01/22-00:03:13.202744
                    SID:2026737
                    Source Port:53559
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850446532829498 09/01/22-00:03:53.963216
                    SID:2829498
                    Source Port:50446
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856116532026737 09/01/22-00:04:05.801650
                    SID:2026737
                    Source Port:56116
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849729532829498 09/01/22-00:02:01.433122
                    SID:2829498
                    Source Port:49729
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863451532829500 09/01/22-00:02:12.684530
                    SID:2829500
                    Source Port:63451
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858535532829500 09/01/22-00:02:23.142881
                    SID:2829500
                    Source Port:58535
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850448532829498 09/01/22-00:03:54.015145
                    SID:2829498
                    Source Port:50448
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864499532026737 09/01/22-00:03:56.365974
                    SID:2026737
                    Source Port:64499
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851489532829498 09/01/22-00:02:06.151880
                    SID:2829498
                    Source Port:51489
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865117532829498 09/01/22-00:04:10.704503
                    SID:2829498
                    Source Port:65117
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852191532026737 09/01/22-00:03:21.167674
                    SID:2026737
                    Source Port:52191
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856119532026737 09/01/22-00:04:05.881610
                    SID:2026737
                    Source Port:56119
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856689532026737 09/01/22-00:02:34.772206
                    SID:2026737
                    Source Port:56689
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858584532829498 09/01/22-00:02:31.231912
                    SID:2829498
                    Source Port:58584
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849963532026737 09/01/22-00:03:35.711880
                    SID:2026737
                    Source Port:49963
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860182532829500 09/01/22-00:02:50.545957
                    SID:2829500
                    Source Port:60182
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854589532829498 09/01/22-00:03:23.168676
                    SID:2829498
                    Source Port:54589
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865515532829500 09/01/22-00:02:32.912023
                    SID:2829500
                    Source Port:65515
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855072532026737 09/01/22-00:02:20.399331
                    SID:2026737
                    Source Port:55072
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858443532829498 09/01/22-00:03:43.862727
                    SID:2829498
                    Source Port:58443
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854590532829498 09/01/22-00:03:23.192418
                    SID:2829498
                    Source Port:54590
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849581532829500 09/01/22-00:03:11.014979
                    SID:2829500
                    Source Port:49581
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856754532026737 09/01/22-00:02:14.833183
                    SID:2026737
                    Source Port:56754
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849773532829498 09/01/22-00:03:05.323153
                    SID:2829498
                    Source Port:49773
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858444532829498 09/01/22-00:03:43.882038
                    SID:2829498
                    Source Port:58444
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853558532026737 09/01/22-00:03:13.174170
                    SID:2026737
                    Source Port:53558
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852105532829500 09/01/22-00:03:27.730338
                    SID:2829500
                    Source Port:52105
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849727532829498 09/01/22-00:02:01.394041
                    SID:2829498
                    Source Port:49727
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859301532829500 09/01/22-00:04:07.531976
                    SID:2829500
                    Source Port:59301
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858537532829500 09/01/22-00:02:23.186317
                    SID:2829500
                    Source Port:58537
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852101532829498 09/01/22-00:03:32.288887
                    SID:2829498
                    Source Port:52101
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853430532026737 09/01/22-00:03:47.092445
                    SID:2026737
                    Source Port:53430
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855595532026737 09/01/22-00:04:09.898241
                    SID:2026737
                    Source Port:55595
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852978532829500 09/01/22-00:03:40.236027
                    SID:2829500
                    Source Port:52978
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860912532026737 09/01/22-00:03:28.349098
                    SID:2026737
                    Source Port:60912
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851487532829498 09/01/22-00:02:06.112309
                    SID:2829498
                    Source Port:51487
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858628532829498 09/01/22-00:03:28.916264
                    SID:2829498
                    Source Port:58628
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851486532829498 09/01/22-00:02:06.080173
                    SID:2829498
                    Source Port:51486
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856118532026737 09/01/22-00:04:05.861618
                    SID:2026737
                    Source Port:56118
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849583532829500 09/01/22-00:03:11.058420
                    SID:2829500
                    Source Port:49583
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850565532829500 09/01/22-00:04:04.955935
                    SID:2829500
                    Source Port:50565
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859300532829500 09/01/22-00:04:07.513788
                    SID:2829500
                    Source Port:59300
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856692532026737 09/01/22-00:02:34.840093
                    SID:2026737
                    Source Port:56692
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860911532026737 09/01/22-00:03:28.331020
                    SID:2026737
                    Source Port:60911
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849584532829500 09/01/22-00:03:11.078564
                    SID:2829500
                    Source Port:49584
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853431532026737 09/01/22-00:03:47.111713
                    SID:2026737
                    Source Port:53431
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858874532829500 09/01/22-00:03:38.011985
                    SID:2829500
                    Source Port:58874
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850082532829500 09/01/22-00:03:34.671276
                    SID:2829500
                    Source Port:50082
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862062532829500 09/01/22-00:03:32.918939
                    SID:2829500
                    Source Port:62062
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855596532026737 09/01/22-00:04:09.918088
                    SID:2026737
                    Source Port:55596
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849962532026737 09/01/22-00:03:35.689392
                    SID:2026737
                    Source Port:49962
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858583532829498 09/01/22-00:02:31.210676
                    SID:2829498
                    Source Port:58583
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863941532026737 09/01/22-00:03:52.370596
                    SID:2026737
                    Source Port:63941
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855611532829498 09/01/22-00:03:36.403141
                    SID:2829498
                    Source Port:55611
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855614532829498 09/01/22-00:03:36.468326
                    SID:2829498
                    Source Port:55614
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861346532829498 09/01/22-00:02:38.490397
                    SID:2829498
                    Source Port:61346
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850091532829500 09/01/22-00:03:18.513860
                    SID:2829500
                    Source Port:50091
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860298532026737 09/01/22-00:03:33.383268
                    SID:2026737
                    Source Port:60298
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852896532026737 09/01/22-00:03:39.114275
                    SID:2026737
                    Source Port:52896
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864313532829498 09/01/22-00:03:58.875073
                    SID:2829498
                    Source Port:64313
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849726532829498 09/01/22-00:02:01.372827
                    SID:2829498
                    Source Port:49726
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860288532026737 09/01/22-00:02:53.105768
                    SID:2026737
                    Source Port:60288
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851726532829500 09/01/22-00:03:55.342624
                    SID:2829500
                    Source Port:51726
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850079532829500 09/01/22-00:03:34.606965
                    SID:2829500
                    Source Port:50079
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856753532026737 09/01/22-00:02:14.812380
                    SID:2026737
                    Source Port:56753
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862663532026737 09/01/22-00:02:25.489629
                    SID:2026737
                    Source Port:62663
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861019532829498 09/01/22-00:04:06.677904
                    SID:2829498
                    Source Port:61019
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861455532829500 09/01/22-00:02:03.672879
                    SID:2829500
                    Source Port:61455
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853977532829500 09/01/22-00:02:39.698321
                    SID:2829500
                    Source Port:53977
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865496532829500 09/01/22-00:03:29.520510
                    SID:2829500
                    Source Port:65496
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856685532829498 09/01/22-00:02:21.613022
                    SID:2829498
                    Source Port:56685
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864937532026737 09/01/22-00:02:42.055156
                    SID:2026737
                    Source Port:64937
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854369532026737 09/01/22-00:04:03.762307
                    SID:2026737
                    Source Port:54369
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865516532829500 09/01/22-00:02:32.934243
                    SID:2829500
                    Source Port:65516
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849266532829500 09/01/22-00:04:00.982711
                    SID:2829500
                    Source Port:49266
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858534532829500 09/01/22-00:02:23.120247
                    SID:2829500
                    Source Port:58534
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859585532829498 09/01/22-00:04:04.074500
                    SID:2829498
                    Source Port:59585
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850447532829498 09/01/22-00:03:53.986780
                    SID:2829498
                    Source Port:50447
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850906532829500 09/01/22-00:02:58.094801
                    SID:2829500
                    Source Port:50906
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852190532026737 09/01/22-00:03:21.145887
                    SID:2026737
                    Source Port:52190
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858877532829500 09/01/22-00:03:38.072921
                    SID:2829500
                    Source Port:58877
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861298532829498 09/01/22-00:03:15.537246
                    SID:2829498
                    Source Port:61298
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863449532829500 09/01/22-00:02:12.647016
                    SID:2829500
                    Source Port:63449
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853825532026737 09/01/22-00:03:02.730691
                    SID:2026737
                    Source Port:53825
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862937532026737 09/01/22-00:03:42.718178
                    SID:2026737
                    Source Port:62937
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864498532026737 09/01/22-00:03:56.346913
                    SID:2026737
                    Source Port:64498
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864314532829498 09/01/22-00:03:59.395837
                    SID:2829498
                    Source Port:64314
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855730532829500 09/01/22-00:03:44.550258
                    SID:2829500
                    Source Port:55730
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865118532829498 09/01/22-00:04:10.725130
                    SID:2829498
                    Source Port:65118
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856686532829498 09/01/22-00:02:21.631696
                    SID:2829498
                    Source Port:56686
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862661532026737 09/01/22-00:02:25.448208
                    SID:2026737
                    Source Port:62661
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850905532829500 09/01/22-00:02:58.072382
                    SID:2829500
                    Source Port:50905
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860023532829498 09/01/22-00:02:55.231073
                    SID:2829498
                    Source Port:60023
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849964532026737 09/01/22-00:03:35.733293
                    SID:2026737
                    Source Port:49964
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865332532829498 09/01/22-00:03:39.649023
                    SID:2829498
                    Source Port:65332
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860182532829498 09/01/22-00:03:48.263650
                    SID:2829498
                    Source Port:60182
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863731532829498 09/01/22-00:03:33.997566
                    SID:2829498
                    Source Port:63731
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858625532829498 09/01/22-00:03:28.850497
                    SID:2829498
                    Source Port:58625
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852102532829500 09/01/22-00:03:27.668953
                    SID:2829500
                    Source Port:52102
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865495532829500 09/01/22-00:03:29.499361
                    SID:2829500
                    Source Port:65495
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854588532829498 09/01/22-00:03:23.146755
                    SID:2829498
                    Source Port:54588
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855071532026737 09/01/22-00:02:20.380296
                    SID:2026737
                    Source Port:55071
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853429532026737 09/01/22-00:03:47.068211
                    SID:2026737
                    Source Port:53429
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863942532026737 09/01/22-00:03:52.388948
                    SID:2026737
                    Source Port:63942
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853974532829500 09/01/22-00:02:39.626606
                    SID:2829500
                    Source Port:53974
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854372532026737 09/01/22-00:04:03.823257
                    SID:2026737
                    Source Port:54372
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849263532829500 09/01/22-00:04:00.923809
                    SID:2829500
                    Source Port:49263
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853432532026737 09/01/22-00:03:47.130970
                    SID:2026737
                    Source Port:53432
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864934532026737 09/01/22-00:02:41.995822
                    SID:2026737
                    Source Port:64934
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852897532026737 09/01/22-00:03:39.132619
                    SID:2026737
                    Source Port:52897
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862939532026737 09/01/22-00:03:42.757239
                    SID:2026737
                    Source Port:62939
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861295532829498 09/01/22-00:03:15.476530
                    SID:2829498
                    Source Port:61295
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857485532026737 09/01/22-00:03:30.537077
                    SID:2026737
                    Source Port:57485
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859588532829498 09/01/22-00:04:04.134905
                    SID:2829498
                    Source Port:59588
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859223532829500 09/01/22-00:02:18.950858
                    SID:2829500
                    Source Port:59223
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853828532026737 09/01/22-00:03:02.797461
                    SID:2026737
                    Source Port:53828
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857382532829500 09/01/22-00:03:50.398087
                    SID:2829500
                    Source Port:57382
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860977532829498 09/01/22-00:02:16.533431
                    SID:2829498
                    Source Port:60977
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861349532829498 09/01/22-00:02:38.549773
                    SID:2829498
                    Source Port:61349
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858475532829498 09/01/22-00:02:46.486527
                    SID:2829498
                    Source Port:58475
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860287532026737 09/01/22-00:02:53.081721
                    SID:2026737
                    Source Port:60287
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861297532829498 09/01/22-00:03:15.516933
                    SID:2829498
                    Source Port:61297
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850088532829500 09/01/22-00:03:18.446546
                    SID:2829500
                    Source Port:50088
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859586532829498 09/01/22-00:04:04.094596
                    SID:2829498
                    Source Port:59586
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859299532829500 09/01/22-00:04:07.496000
                    SID:2829500
                    Source Port:59299
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852100532829498 09/01/22-00:03:32.267998
                    SID:2829498
                    Source Port:52100
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860184532829498 09/01/22-00:03:48.305240
                    SID:2829498
                    Source Port:60184
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860980532829498 09/01/22-00:02:16.604526
                    SID:2829498
                    Source Port:60980
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853976532829500 09/01/22-00:02:39.666430
                    SID:2829500
                    Source Port:53976
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865497532829500 09/01/22-00:03:29.542703
                    SID:2829500
                    Source Port:65497
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857379532829500 09/01/22-00:03:50.318564
                    SID:2829500
                    Source Port:57379
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861454532829500 09/01/22-00:02:03.654444
                    SID:2829500
                    Source Port:61454
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853560532026737 09/01/22-00:03:13.225920
                    SID:2026737
                    Source Port:53560
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852104532829500 09/01/22-00:03:27.710044
                    SID:2829500
                    Source Port:52104
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858445532829498 09/01/22-00:03:43.903621
                    SID:2829498
                    Source Port:58445
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856756532026737 09/01/22-00:02:14.874396
                    SID:2026737
                    Source Port:56756
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856684532829498 09/01/22-00:02:21.592544
                    SID:2829498
                    Source Port:56684
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853826532026737 09/01/22-00:03:02.751283
                    SID:2026737
                    Source Port:53826
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858586532829498 09/01/22-00:02:31.279996
                    SID:2829498
                    Source Port:58586
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849771532829498 09/01/22-00:03:05.189017
                    SID:2829498
                    Source Port:49771
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865334532829498 09/01/22-00:03:39.691657
                    SID:2829498
                    Source Port:65334
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861347532829498 09/01/22-00:02:38.510793
                    SID:2829498
                    Source Port:61347
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860021532829498 09/01/22-00:02:55.191369
                    SID:2829498
                    Source Port:60021
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855729532829500 09/01/22-00:03:44.527150
                    SID:2829500
                    Source Port:55729
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850907532829500 09/01/22-00:02:58.117260
                    SID:2829500
                    Source Port:50907
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859807532829500 09/01/22-00:03:55.275052
                    SID:2829500
                    Source Port:59807
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861021532829498 09/01/22-00:04:06.718974
                    SID:2829498
                    Source Port:61021
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859225532829500 09/01/22-00:02:19.007298
                    SID:2829500
                    Source Port:59225
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865326532026737 09/01/22-00:02:04.899187
                    SID:2026737
                    Source Port:65326
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860297532026737 09/01/22-00:03:33.363249
                    SID:2026737
                    Source Port:60297
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863733532829498 09/01/22-00:03:34.037884
                    SID:2829498
                    Source Port:63733
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849774532829498 09/01/22-00:03:05.512260
                    SID:2829498
                    Source Port:49774
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860289532026737 09/01/22-00:02:53.129672
                    SID:2026737
                    Source Port:60289
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.853557532026737 09/01/22-00:03:13.152000
                    SID:2026737
                    Source Port:53557
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858876532829500 09/01/22-00:03:38.053463
                    SID:2829500
                    Source Port:58876
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850081532829500 09/01/22-00:03:34.650981
                    SID:2829500
                    Source Port:50081
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852976532829500 09/01/22-00:03:40.199013
                    SID:2829500
                    Source Port:52976
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862664532026737 09/01/22-00:02:25.509064
                    SID:2026737
                    Source Port:62664
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864312532829498 09/01/22-00:03:58.856410
                    SID:2829498
                    Source Port:64312
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857487532026737 09/01/22-00:03:30.582629
                    SID:2026737
                    Source Port:57487
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856117532026737 09/01/22-00:04:05.841041
                    SID:2026737
                    Source Port:56117
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865517532829500 09/01/22-00:02:32.956296
                    SID:2829500
                    Source Port:65517
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852895532026737 09/01/22-00:03:39.091614
                    SID:2026737
                    Source Port:52895
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851724532829500 09/01/22-00:03:55.294608
                    SID:2829500
                    Source Port:51724
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860299532026737 09/01/22-00:03:33.401260
                    SID:2026737
                    Source Port:60299
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852098532829498 09/01/22-00:03:32.229187
                    SID:2829498
                    Source Port:52098
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849961532026737 09/01/22-00:03:35.669538
                    SID:2026737
                    Source Port:49961
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849265532829500 09/01/22-00:04:00.962398
                    SID:2829500
                    Source Port:49265
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860979532829498 09/01/22-00:02:16.584622
                    SID:2829498
                    Source Port:60979
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858477532829498 09/01/22-00:02:46.531265
                    SID:2829498
                    Source Port:58477
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857380532829500 09/01/22-00:03:50.340625
                    SID:2829500
                    Source Port:57380
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855613532829498 09/01/22-00:03:36.446288
                    SID:2829498
                    Source Port:55613
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862936532026737 09/01/22-00:03:42.697375
                    SID:2026737
                    Source Port:62936
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861020532829498 09/01/22-00:04:06.699436
                    SID:2829498
                    Source Port:61020
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861456532829500 09/01/22-00:02:03.693126
                    SID:2829500
                    Source Port:61456
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865498532829500 09/01/22-00:03:29.567003
                    SID:2829500
                    Source Port:65498
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850080532829500 09/01/22-00:03:34.627091
                    SID:2829500
                    Source Port:50080
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864936532026737 09/01/22-00:02:42.036797
                    SID:2026737
                    Source Port:64936
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859222532829500 09/01/22-00:02:18.931529
                    SID:2829500
                    Source Port:59222
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855612532829498 09/01/22-00:03:36.425992
                    SID:2829498
                    Source Port:55612
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857381532829500 09/01/22-00:03:50.368405
                    SID:2829500
                    Source Port:57381
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858536532829500 09/01/22-00:02:23.164990
                    SID:2829500
                    Source Port:58536
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862060532829500 09/01/22-00:03:32.873172
                    SID:2829500
                    Source Port:62060
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860179532829500 09/01/22-00:02:50.481998
                    SID:2829500
                    Source Port:60179
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.859298532829500 09/01/22-00:04:07.476417
                    SID:2829500
                    Source Port:59298
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860978532829498 09/01/22-00:02:16.558773
                    SID:2829498
                    Source Port:60978
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864496532026737 09/01/22-00:03:56.305340
                    SID:2026737
                    Source Port:64496
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863940532026737 09/01/22-00:03:52.350223
                    SID:2026737
                    Source Port:63940
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850090532829500 09/01/22-00:03:18.489552
                    SID:2829500
                    Source Port:50090
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850564532829500 09/01/22-00:04:04.937269
                    SID:2829500
                    Source Port:50564
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861018532829498 09/01/22-00:04:06.657229
                    SID:2829498
                    Source Port:61018
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849264532829500 09/01/22-00:04:00.944094
                    SID:2829500
                    Source Port:49264
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849772532829498 09/01/22-00:03:05.233383
                    SID:2829498
                    Source Port:49772
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865518532829500 09/01/22-00:02:32.980619
                    SID:2829500
                    Source Port:65518
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851725532829500 09/01/22-00:03:55.314556
                    SID:2829500
                    Source Port:51725
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.862061532829500 09/01/22-00:03:32.897217
                    SID:2829500
                    Source Port:62061
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852192532026737 09/01/22-00:03:21.187862
                    SID:2026737
                    Source Port:52192
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.864935532026737 09/01/22-00:02:42.016020
                    SID:2026737
                    Source Port:64935
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858875532829500 09/01/22-00:03:38.032851
                    SID:2829500
                    Source Port:58875
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863732532829498 09/01/22-00:03:34.017665
                    SID:2829498
                    Source Port:63732
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.861457532829500 09/01/22-00:02:03.713490
                    SID:2829500
                    Source Port:61457
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850449532829498 09/01/22-00:03:54.035960
                    SID:2829498
                    Source Port:50449
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856691532026737 09/01/22-00:02:34.816978
                    SID:2026737
                    Source Port:56691
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855731532829500 09/01/22-00:03:44.568358
                    SID:2829500
                    Source Port:55731
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849582532829500 09/01/22-00:03:11.038348
                    SID:2829500
                    Source Port:49582
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856687532829498 09/01/22-00:02:21.652316
                    SID:2829498
                    Source Port:56687
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.854370532026737 09/01/22-00:04:03.782854
                    SID:2026737
                    Source Port:54370
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852099532829498 09/01/22-00:03:32.248418
                    SID:2829498
                    Source Port:52099
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.857486532026737 09/01/22-00:03:30.561309
                    SID:2026737
                    Source Port:57486
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860022532829498 09/01/22-00:02:55.212194
                    SID:2829498
                    Source Port:60022
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852894532026737 09/01/22-00:03:39.072653
                    SID:2026737
                    Source Port:52894
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858627532829498 09/01/22-00:03:28.892335
                    SID:2829498
                    Source Port:58627
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.849728532829498 09/01/22-00:02:01.412620
                    SID:2829498
                    Source Port:49728
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860913532026737 09/01/22-00:03:28.369056
                    SID:2026737
                    Source Port:60913
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855073532026737 09/01/22-00:02:20.420031
                    SID:2026737
                    Source Port:55073
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855594532026737 09/01/22-00:04:09.880111
                    SID:2026737
                    Source Port:55594
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.856755532026737 09/01/22-00:02:14.854023
                    SID:2026737
                    Source Port:56755
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860181532829500 09/01/22-00:02:50.523251
                    SID:2829500
                    Source Port:60181
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.852977532829500 09/01/22-00:03:40.217833
                    SID:2829500
                    Source Port:52977
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863450532829500 09/01/22-00:02:12.666416
                    SID:2829500
                    Source Port:63450
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865335532829498 09/01/22-00:03:39.713005
                    SID:2829498
                    Source Port:65335
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.858585532829498 09/01/22-00:02:31.250178
                    SID:2829498
                    Source Port:58585
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.851488532829498 09/01/22-00:02:06.132219
                    SID:2829498
                    Source Port:51488
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.855728532829500 09/01/22-00:03:44.508575
                    SID:2829500
                    Source Port:55728
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.863943532026737 09/01/22-00:03:52.415647
                    SID:2026737
                    Source Port:63943
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.860296532026737 09/01/22-00:03:33.345251
                    SID:2026737
                    Source Port:60296
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.865327532026737 09/01/22-00:02:04.922757
                    SID:2026737
                    Source Port:65327
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected
                    Timestamp:192.168.2.58.8.8.850567532829500 09/01/22-00:04:04.998120
                    SID:2829500
                    Source Port:50567
                    Destination Port:53
                    Protocol:UDP
                    Classtype:A Network Trojan was detected

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: 2fiDcmkaZY.exeReversingLabs: Detection: 100%
                    Source: 2fiDcmkaZY.exeAvira: detected
                    Source: http://gdcbghvjyqy7jclk.onion.casa/2d028d577a0eb038Avira URL Cloud: Label: malware
                    Source: http://gdcbghvjyqy7jclk.onion.top/2d028d577a0eb038Avira URL Cloud: Label: phishing
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeAvira: detection malicious, Label: TR/FileCoder.oytet
                    Source: 2fiDcmkaZY.exeJoe Sandbox ML: detected
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeJoe Sandbox ML: detected
                    Source: 20.0.tdicrr.exe.c70000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 20.2.tdicrr.exe.c70000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 13.0.tdicrr.exe.c70000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 0.2.2fiDcmkaZY.exe.a60000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 13.2.tdicrr.exe.c70000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: 0.0.2fiDcmkaZY.exe.a60000.0.unpackAvira: Label: TR/Crypt.XPACK.Gen3
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A648A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67DB0 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A65D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A65750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A66000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A65540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A65050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C748A0 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C75D80 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C77DB0 VirtualAlloc,CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C75540 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenW,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C75750 VirtualAlloc,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrcatW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,_memset,lstrlenA,lstrlenA,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C75050 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,_memset,lstrlenA,lstrlenA,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,MultiByteToWideChar,GetLastError,VirtualAlloc,VirtualFree,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C77C60 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C76000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: 2fiDcmkaZY.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 2fiDcmkaZY.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: z:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: x:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: v:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: t:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: r:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: p:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: n:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: l:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: j:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: h:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: f:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: b:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: y:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: w:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: u:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: s:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: q:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: o:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: m:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: k:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: i:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: g:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: e:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile opened: a:
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A664A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A666F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C766F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C764A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,

                    Networking

                    barindex
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49726 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49727 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49728 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49729 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:61454 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:61455 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:61456 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:61457 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:65325 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:65326 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:65327 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:65328 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:51486 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:51487 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:51488 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:51489 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:63448 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:63449 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:63450 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:63451 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56753 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56754 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56755 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56756 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60977 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60978 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60979 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60980 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59222 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59223 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59224 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59225 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55070 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55071 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55072 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55073 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:56684 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:56685 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:56686 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:56687 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58534 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58535 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58536 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58537 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62661 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62662 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62663 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62664 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58583 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58584 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58585 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58586 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65515 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65516 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65517 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65518 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56689 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56690 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56691 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56692 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61346 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61347 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61348 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61349 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:53974 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:53975 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:53976 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:53977 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64934 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64935 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64936 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64937 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58474 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58475 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58476 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58477 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:60179 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:60180 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:60181 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:60182 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60286 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60287 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60288 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60289 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60021 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60022 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60023 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60024 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50904 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50905 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50906 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50907 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53825 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53826 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53827 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53828 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49771 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49772 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49773 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:49774 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49581 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49582 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49583 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49584 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53557 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53558 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53559 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53560 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61295 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61296 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61297 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61298 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50088 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50089 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50090 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50091 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52190 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52191 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52192 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52193 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:54587 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:54588 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:54589 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:54590 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52102 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52103 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52104 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52105 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60910 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60911 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60912 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60913 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58625 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58626 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58627 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58628 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65495 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65496 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65497 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:65498 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:57484 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:57485 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:57486 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:57487 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:52098 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:52099 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:52100 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:52101 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:62059 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:62060 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:62061 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:62062 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60296 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60297 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60298 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:60299 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:63730 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:63731 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:63732 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:63733 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50079 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50080 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50081 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50082 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:49961 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:49962 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:49963 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:49964 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:55611 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:55612 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:55613 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:55614 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58874 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58875 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58876 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:58877 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52894 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52895 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52896 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:52897 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65332 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65333 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65334 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65335 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52975 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52976 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52977 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:52978 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62936 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62937 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62938 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:62939 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58443 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58444 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58445 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:58446 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:55728 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:55729 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:55730 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:55731 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53429 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53430 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53431 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:53432 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60181 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60182 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60183 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:60184 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:57379 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:57380 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:57381 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:57382 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:63940 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:63941 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:63942 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:63943 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:50446 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:50447 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:50448 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:50449 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59807 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:51724 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:51725 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:51726 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64496 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64497 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64498 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:64499 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:64312 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:64313 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:64314 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:64315 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49263 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49264 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49265 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:49266 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:54369 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:54370 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:54371 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:54372 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:59585 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:59586 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:59587 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:59588 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50564 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50565 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50566 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:50567 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56116 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56117 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56118 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:56119 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61018 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61019 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61020 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:61021 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59298 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59299 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59300 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829500 ETPRO TROJAN GandCrab DNS Lookup 3 192.168.2.5:59301 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55594 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55595 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55596 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2026737 ET TROJAN Observed GandCrab Domain (gandcrab .bit) 192.168.2.5:55597 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65117 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65118 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65119 -> 8.8.8.8:53
                    Source: TrafficSnort IDS: 2829498 ETPRO TROJAN GandCrab DNS Lookup 1 192.168.2.5:65120 -> 8.8.8.8:53
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A668F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A668F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C768F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C768F0 VirtualAlloc,VirtualAlloc,lstrlenW,lstrlenA,wsprintfW,VirtualFree,InternetCloseHandle, ipv4bot.whatismyipaddress.com
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 4. Open link in tor browser: http://gdcbghvjyqy7jclk.onion/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 1. http://gdcbghvjyqy7jclk.onion.top/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 2. http://gdcbghvjyqy7jclk.onion.casa/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 3. http://gdcbghvjyqy7jclk.onion.guide/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 4. http://gdcbghvjyqy7jclk.onion.rip/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: 5. http://gdcbghvjyqy7jclk.onion.plus/2d028d577a0eb038
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeDNS query: name: ipv4bot.whatismyipaddress.com
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://gdcbghvjyqy7jclk.onion.casa/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://gdcbghvjyqy7jclk.onion.guide/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://gdcbghvjyqy7jclk.onion.plus/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://gdcbghvjyqy7jclk.onion.rip/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://gdcbghvjyqy7jclk.onion.top/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: http://gdcbghvjyqy7jclk.onion/2d028d577a0eb038
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.599059548.000000000120A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ipv4bot.whatismyipaddress.com/
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.599059548.000000000120A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ipv4bot.whatismyipaddress.com/n
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.torproject.org/
                    Source: unknownDNS traffic detected: queries for: ipv4bot.whatismyipaddress.com
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67A00 lstrcatW,InternetCloseHandle,InternetConnectW,VirtualAlloc,wsprintfW,HttpOpenRequestW,HttpAddRequestHeadersW,HttpSendRequestW,InternetReadFile,InternetReadFile,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,VirtualFree,
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.599059548.000000000120A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>

                    Spam, unwanted Advertisements and Ransom Demands

                    barindex
                    Source: Yara matchFile source: 2fiDcmkaZY.exe, type: SAMPLE
                    Source: Yara matchFile source: 13.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 20.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.0.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 20.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 13.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0000000D.00000000.343462206.0000000000C79000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                    Source: Yara matchFile source: 0000000D.00000002.346586335.0000000000C79000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000014.00000002.363374033.0000000000C79000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000000.304343043.0000000000A69000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000014.00000000.360474661.0000000000C79000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: 2fiDcmkaZY.exe PID: 6752, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: tdicrr.exe PID: 1476, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: tdicrr.exe PID: 5864, type: MEMORYSTR
                    Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, type: DROPPED
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A66000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C76000 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection,
                    Source: nslookup.exeProcess created: 56

                    System Summary

                    barindex
                    Source: 2fiDcmkaZY.exe, type: SAMPLEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 13.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 20.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 0.0.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 20.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 13.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 0.2.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, type: DROPPEDMatched rule: Gandcrab Payload Author: kevoreilly
                    Source: 2fiDcmkaZY.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 2fiDcmkaZY.exe, type: SAMPLEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 2fiDcmkaZY.exe, type: SAMPLEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 13.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 13.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 20.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 0.0.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 20.0.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 0.0.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 20.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 20.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 13.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 13.2.tdicrr.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: 0.2.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPEMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: 0.2.2fiDcmkaZY.exe.a60000.0.unpack, type: UNPACKEDPEMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, type: DROPPEDMatched rule: SUSP_RANSOMWARE_Indicator_Jul20 date = 2020-07-28, hash3 = 6cb9afff8166976bd62bb29b12ed617784d6e74b110afcf8955477573594f306, hash2 = 5e78475d10418c6938723f6cfefb89d5e9de61e45ecf374bb435c1c99dd4a473, author = Florian Roth, description = Detects ransomware indicator, score = 52888b5f881f4941ae7a8f4d84de27fc502413861f96ee58ee560c09c11880d6, reference = https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, type: DROPPEDMatched rule: Gandcrab author = kevoreilly, description = Gandcrab Payload, cape_type = Gandcrab Payload
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67EE0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C77EE0
                    Source: 2fiDcmkaZY.exeReversingLabs: Detection: 100%
                    Source: 2fiDcmkaZY.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
                    Source: unknownProcess created: C:\Users\user\Desktop\2fiDcmkaZY.exe "C:\Users\user\Desktop\2fiDcmkaZY.exe"
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe "C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe"
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe "C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe"
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Windows\SysWOW64\nslookup.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeJump to behavior
                    Source: classification engineClassification label: mal100.rans.troj.evad.winEXE@128/2@436/1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A66D90 VirtualAlloc,VirtualAlloc,GetUserNameW,VirtualAlloc,GetComputerNameW,wsprintfW,VirtualAlloc,wsprintfW,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,VirtualFree,VirtualAlloc,VirtualAlloc,wsprintfW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrcmpiW,wsprintfW,wsprintfW,VirtualFree,VirtualAlloc,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,wsprintfW,GetNativeSystemInfo,VirtualAlloc,wsprintfW,VirtualAlloc,VirtualAlloc,GetWindowsDirectoryW,GetVolumeInformationW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrlenW,wsprintfW,lstrcatW,lstrcatW,GetModuleHandleW,GetProcAddress,lstrlenW,VirtualFree,lstrcatW,VirtualAlloc,GetDriveTypeW,lstrcatW,lstrcatW,lstrcatW,GetDiskFreeSpaceW,lstrlenW,wsprintfW,wsprintfW,lstrlenW,lstrlenW,wsprintfW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67520 wsprintfW,VirtualAlloc,VirtualAlloc,VirtualAlloc,VirtualAlloc,CreateToolhelp32Snapshot,VirtualFree,Process32FirstW,lstrcmpiW,lstrcpyW,lstrcatW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,Process32NextW,GetLastError,lstrlenW,VirtualFree,VirtualFree,FindCloseChangeNotification,VirtualFree,
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5040:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6568:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6636:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6964:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2992:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7040:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6036:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7036:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6524:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6920:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5836:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7152:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5320:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5808:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5892:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5888:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6588:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5944:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5684:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:712:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6028:120:WilError_01
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeMutant created: \Sessions\1\BaseNamedObjects\Global\pc_group=WORKGROUP&ransom_id=2d028d577a0eb038
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6912:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6076:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6460:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6788:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7092:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6980:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6092:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6844:120:WilError_01
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: C:\Windows\SysWOW64\nslookup.exeFile read: C:\Windows\System32\drivers\etc\hosts
                    Source: Window RecorderWindow detected: More than 3 window changes detected
                    Source: 2fiDcmkaZY.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67DB0 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeJump to dropped file
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce tbmdhshhgozJump to behavior
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce tbmdhshhgozJump to behavior
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce tbmdhshhgozJump to behavior
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce tbmdhshhgozJump to behavior

                    Malware Analysis System Evasion

                    barindex
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeEvasive API call chain: CreateMutex,DecisionNodes,ExitProcess
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeEvasive API call chain: CreateMutex,DecisionNodes,ExitProcess
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exe TID: 6756Thread sleep count: 65 > 30
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exe TID: 6756Thread sleep time: -650000s >= -30000s
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeEvaded block: after key decision
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: EnumDeviceDrivers,K32EnumDeviceDrivers,VirtualAlloc,K32EnumDeviceDrivers,K32GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: EnumDeviceDrivers,EnumDeviceDrivers,VirtualAlloc,EnumDeviceDrivers,GetDeviceDriverBaseNameW,lstrcmpiW,VirtualFree,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A664A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A666F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C766F0 lstrlenW,lstrcatW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcatW,lstrcatW,lstrcatW,FindNextFileW,FindClose,
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeCode function: 13_2_00C764A0 lstrlenW,lstrcatW,FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpW,lstrcatW,lstrlenW,lstrcmpW,CreateFileW,GetFileSize,VirtualAlloc,ReadFile,lstrlenA,VirtualFree,CloseHandle,lstrcmpW,FindNextFileW,FindClose,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeSystem information queried: ModuleInformation
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeAPI call chain: ExitProcess graph end node
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeAPI call chain: ExitProcess graph end node
                    Source: 2fiDcmkaZY.exe, 00000000.00000002.599105239.0000000001244000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll"
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A67DB0 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A639B0 GetProcessHeap,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup emsisoft.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup gandcrab.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\SysWOW64\nslookup.exe nslookup nomoreransom.bit dns1.soprodns.ru
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeProcess created: unknown unknown
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A63A60 AllocateAndInitializeSid,GetModuleHandleA,GetProcAddress,FreeSid,
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeQueries volume information: C:\ VolumeInformation
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A68BC0 cpuid
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
                    Source: C:\Users\user\Desktop\2fiDcmkaZY.exeCode function: 0_2_00A66D90 VirtualAlloc,VirtualAlloc,GetUserNameW,VirtualAlloc,GetComputerNameW,wsprintfW,VirtualAlloc,wsprintfW,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,VirtualFree,VirtualAlloc,VirtualAlloc,wsprintfW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrcmpiW,wsprintfW,wsprintfW,VirtualFree,VirtualAlloc,VirtualAlloc,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,wsprintfW,GetNativeSystemInfo,VirtualAlloc,wsprintfW,VirtualAlloc,VirtualAlloc,GetWindowsDirectoryW,GetVolumeInformationW,RegOpenKeyExW,RegQueryValueExW,GetLastError,RegCloseKey,lstrlenW,wsprintfW,lstrcatW,lstrcatW,GetModuleHandleW,GetProcAddress,lstrlenW,VirtualFree,lstrcatW,VirtualAlloc,GetDriveTypeW,lstrcatW,lstrcatW,lstrcatW,GetDiskFreeSpaceW,lstrlenW,wsprintfW,wsprintfW,lstrlenW,lstrlenW,wsprintfW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,lstrlenW,VirtualAlloc,VirtualFree,
                    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                    1
                    Replication Through Removable Media
                    12
                    Native API
                    1
                    Registry Run Keys / Startup Folder
                    11
                    Process Injection
                    1
                    Software Packing
                    1
                    Input Capture
                    11
                    Peripheral Device Discovery
                    1
                    Replication Through Removable Media
                    11
                    Archive Collected Data
                    Exfiltration Over Other Network Medium1
                    Ingress Tool Transfer
                    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
                    Data Encrypted for Impact
                    Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                    Registry Run Keys / Startup Folder
                    1
                    Masquerading
                    LSASS Memory1
                    Account Discovery
                    Remote Desktop Protocol1
                    Input Capture
                    Exfiltration Over Bluetooth2
                    Encrypted Channel
                    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
                    Virtualization/Sandbox Evasion
                    Security Account Manager1
                    System Network Connections Discovery
                    SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
                    Non-Application Layer Protocol
                    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)11
                    Process Injection
                    NTDS1
                    File and Directory Discovery
                    Distributed Component Object ModelInput CaptureScheduled Transfer1
                    Application Layer Protocol
                    SIM Card SwapCarrier Billing Fraud
                    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets44
                    System Information Discovery
                    SSHKeyloggingData Transfer Size Limits1
                    Proxy
                    Manipulate Device CommunicationManipulate App Store Rankings or Ratings
                    Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain Credentials11
                    Security Software Discovery
                    VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                    External Remote ServicesScheduled TaskStartup ItemsStartup ItemsCompile After DeliveryDCSync1
                    Virtualization/Sandbox Evasion
                    Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                    Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
                    Process Discovery
                    Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                    Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Masquerading/etc/passwd and /etc/shadow1
                    System Owner/User Discovery
                    Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
                    Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)Invalid Code SignatureNetwork Sniffing1
                    Remote System Discovery
                    Taint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
                    Compromise Software Dependencies and Development ToolsWindows Command ShellCronCronRight-to-Left OverrideInput Capture2
                    System Network Configuration Discovery
                    Replication Through Removable MediaRemote Data StagingExfiltration Over Physical MediumMail ProtocolsService Stop
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet
                    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 694570 Sample: 2fiDcmkaZY.exe Startdate: 01/09/2022 Architecture: WINDOWS Score: 100 57 nomoreransom.bit 2->57 59 gandcrab.bit 2->59 61 3 other IPs or domains 2->61 65 Snort IDS alert for network traffic 2->65 67 Malicious sample detected (through community Yara rule) 2->67 69 Antivirus detection for URL or domain 2->69 71 5 other signatures 2->71 8 2fiDcmkaZY.exe 1 28 2->8         started        13 tdicrr.exe 2->13         started        15 tdicrr.exe 2->15         started        signatures3 process4 dnsIp5 63 ipv4bot.whatismyipaddress.com 8->63 40 C:\Users\user\AppData\Roaming\...\tdicrr.exe, PE32 8->40 dropped 73 Found evasive API chain (may stop execution after checking mutex) 8->73 75 Contains functionality to determine the online IP of the system 8->75 77 May check the online IP address of the machine 8->77 79 Uses nslookup.exe to query domains 8->79 17 nslookup.exe 1 8->17         started        20 nslookup.exe 1 8->20         started        22 nslookup.exe 1 8->22         started        24 26 other processes 8->24 81 Antivirus detection for dropped file 13->81 83 Machine Learning detection for dropped file 13->83 file6 signatures7 process8 dnsIp9 42 dns1.soprodns.ru 17->42 45 nomoreransom.bit 17->45 47 8.8.8.8.in-addr.arpa 17->47 26 conhost.exe 17->26         started        51 3 other IPs or domains 20->51 28 conhost.exe 20->28         started        53 3 other IPs or domains 22->53 30 conhost.exe 22->30         started        49 nomoreransom.bit 24->49 55 78 other IPs or domains 24->55 32 conhost.exe 24->32         started        34 conhost.exe 24->34         started        36 conhost.exe 24->36         started        38 23 other processes 24->38 signatures10 85 May check the online IP address of the machine 42->85 process11

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    2fiDcmkaZY.exe100%ReversingLabsWin32.Ransomware.GandCrab
                    2fiDcmkaZY.exe100%AviraTR/FileCoder.oytet
                    2fiDcmkaZY.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLink
                    C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe100%AviraTR/FileCoder.oytet
                    C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe100%Joe Sandbox ML
                    SourceDetectionScannerLabelLinkDownload
                    20.0.tdicrr.exe.c70000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    20.2.tdicrr.exe.c70000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    13.0.tdicrr.exe.c70000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    0.2.2fiDcmkaZY.exe.a60000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    13.2.tdicrr.exe.c70000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    0.0.2fiDcmkaZY.exe.a60000.0.unpack100%AviraTR/Crypt.XPACK.Gen3Download File
                    No Antivirus matches
                    SourceDetectionScannerLabelLink
                    http://gdcbghvjyqy7jclk.onion.casa/2d028d577a0eb038100%Avira URL Cloudmalware
                    http://gdcbghvjyqy7jclk.onion/2d028d577a0eb0380%Avira URL Cloudsafe
                    http://gdcbghvjyqy7jclk.onion.top/2d028d577a0eb038100%Avira URL Cloudphishing
                    NameIPActiveMaliciousAntivirus DetectionReputation
                    emsisoft.bit
                    unknown
                    unknowntrue
                      unknown
                      ipv4bot.whatismyipaddress.com
                      unknown
                      unknownfalse
                        high
                        nomoreransom.bit
                        unknown
                        unknowntrue
                          unknown
                          gandcrab.bit
                          unknown
                          unknowntrue
                            unknown
                            dns1.soprodns.ru
                            unknown
                            unknowntrue
                              unknown
                              8.8.8.8.in-addr.arpa
                              unknown
                              unknownfalse
                                unknown
                                NameSourceMaliciousAntivirus DetectionReputation
                                http://gdcbghvjyqy7jclk.onion.casa/2d028d577a0eb0382fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmptrue
                                • Avira URL Cloud: malware
                                unknown
                                http://gdcbghvjyqy7jclk.onion.plus/2d028d577a0eb0382fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpfalse
                                  high
                                  http://gdcbghvjyqy7jclk.onion.rip/2d028d577a0eb0382fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpfalse
                                    high
                                    http://gdcbghvjyqy7jclk.onion/2d028d577a0eb0382fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmptrue
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://www.torproject.org/2fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpfalse
                                      high
                                      http://gdcbghvjyqy7jclk.onion.top/2d028d577a0eb0382fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmptrue
                                      • Avira URL Cloud: phishing
                                      unknown
                                      http://gdcbghvjyqy7jclk.onion.guide/2d028d577a0eb0382fiDcmkaZY.exe, 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmpfalse
                                        high
                                        http://ipv4bot.whatismyipaddress.com/2fiDcmkaZY.exe, 00000000.00000002.599059548.000000000120A000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          http://ipv4bot.whatismyipaddress.com/n2fiDcmkaZY.exe, 00000000.00000002.599059548.000000000120A000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            • No. of IPs < 25%
                                            • 25% < No. of IPs < 50%
                                            • 50% < No. of IPs < 75%
                                            • 75% < No. of IPs
                                            IPDomainCountryFlagASNASN NameMalicious
                                            IP
                                            192.168.2.1
                                            Joe Sandbox Version:35.0.0 Citrine
                                            Analysis ID:694570
                                            Start date and time:2022-09-01 00:00:54 +02:00
                                            Joe Sandbox Product:CloudBasic
                                            Overall analysis duration:0h 7m 56s
                                            Hypervisor based Inspection enabled:false
                                            Report type:light
                                            Sample file name:2fiDcmkaZY.exe
                                            Cookbook file name:default.jbs
                                            Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                            Number of analysed new started processes analysed:70
                                            Number of new started drivers analysed:0
                                            Number of existing processes analysed:0
                                            Number of existing drivers analysed:0
                                            Number of injected processes analysed:0
                                            Technologies:
                                            • HCA enabled
                                            • EGA enabled
                                            • HDC enabled
                                            • AMSI enabled
                                            Analysis Mode:default
                                            Analysis stop reason:Timeout
                                            Detection:MAL
                                            Classification:mal100.rans.troj.evad.winEXE@128/2@436/1
                                            EGA Information:
                                            • Successful, ratio: 100%
                                            HDC Information:
                                            • Successful, ratio: 100% (good quality ratio 78.1%)
                                            • Quality average: 67.4%
                                            • Quality standard deviation: 38.8%
                                            HCA Information:
                                            • Successful, ratio: 99%
                                            • Number of executed functions: 0
                                            • Number of non-executed functions: 0
                                            Cookbook Comments:
                                            • Found application associated with file extension: .exe
                                            • Adjust boot time
                                            • Enable AMSI
                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                                            • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, eudb.ris.api.iris.microsoft.com, ctldl.windowsupdate.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
                                            • Not all processes where analyzed, report is missing behavior information
                                            • Report size exceeded maximum capacity and may have missing behavior information.
                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                            • VT rate limit hit for: 2fiDcmkaZY.exe
                                            TimeTypeDescription
                                            00:01:59AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce tbmdhshhgoz "C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe"
                                            00:02:00API Interceptor66x Sleep call for process: 2fiDcmkaZY.exe modified
                                            00:02:09AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\RunOnce tbmdhshhgoz "C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe"
                                            No context
                                            No context
                                            No context
                                            No context
                                            No context
                                            Process:C:\Users\user\Desktop\2fiDcmkaZY.exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):2219
                                            Entropy (8bit):0.0
                                            Encrypted:false
                                            SSDEEP:3::
                                            MD5:9B515CE290886100F8C5F7C3AD0CB6A0
                                            SHA1:CF57023D314B0BAD4BCC41D552A31EC88FA56395
                                            SHA-256:186674F8434D142FE3E22F9A51A70FBE1F5161984D6A4B9EDE27B997C28D66EB
                                            SHA-512:5C7838FAEAC049C90E7AB1CED964CA7ED7F753894FBB7B270D5989631CCB3F40AE50F9579EC691DBB25A996F6ACCD66F2749952D3AEE793A3A83C54CF6BAA90F
                                            Malicious:false
                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                            Process:C:\Users\user\Desktop\2fiDcmkaZY.exe
                                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                            Category:dropped
                                            Size (bytes):75264
                                            Entropy (8bit):6.459228563179094
                                            Encrypted:false
                                            SSDEEP:1536:G55u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5rJ:sMSjOnrmBTMqqDL2/mr3IdE8we0Avu5h
                                            MD5:D2E112FDFFC314778285E837BC0BED47
                                            SHA1:80902F2799D88F88DD99312023EF7086EE476566
                                            SHA-256:A49438E4A242B678CCFC5E8AB0B1A1082F107B2D043C245BC968954511AEF830
                                            SHA-512:CF8870AC369723A36D6363E6F28E24B443AADE41A464B3181AC73FDE654E0BEB137312F6819E8A82D3175B8DEF0FB466B61E04DC01C82C111E9DBB11CE2CB169
                                            Malicious:true
                                            Yara Hits:
                                            • Rule: SUSP_RANSOMWARE_Indicator_Jul20, Description: Detects ransomware indicator, Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, Author: Florian Roth
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, Author: Joe Security
                                            • Rule: Gandcrab, Description: Gandcrab Payload, Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, Author: kevoreilly
                                            Antivirus:
                                            • Antivirus: Avira, Detection: 100%
                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                            Preview:MZ......................@...............................................!..L.!This +...tXm cannot be run in DOS mode....$.......AU@..4...4...4..Ce...4..Ce...4...f...4...4...4...L...4...4/.4...f...4...f...4...f...4..Rich.4..................PE..L...].vZ.............................J............@..........................`............@.................................p........@.......................P.......................................................................................text............................... ..`.rdata..............................@....data........ ......................@....CRT.........0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................................
                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                            Entropy (8bit):6.459199222303618
                                            TrID:
                                            • Win32 Executable (generic) a (10002005/4) 99.96%
                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                            • DOS Executable Generic (2002/1) 0.02%
                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                            File name:2fiDcmkaZY.exe
                                            File size:75264
                                            MD5:a8ac57500de5dadf8c4db19959ddf2ec
                                            SHA1:202baa4b862222951619adc032fd2883562113b2
                                            SHA256:fcc7cc8f57d5a2a525d8026e81f69318262ca4e9036a726e26b1e3406f6f52d5
                                            SHA512:52ac5555cd39250903965ef6b30dbafcbe73e5f33b7d07a443cc3678e77ee3ce0736e2a70881f23c2002318b9dfba59d482cd724e5f8fdcf8084b2f6e6f826e8
                                            SSDEEP:1536:055u555555555pmgSeGDjtQhnwmmB0ybMqqU+2bbbAV2/S2mr3IdE8mne0Avu5rJ:mMSjOnrmBTMqqDL2/mr3IdE8we0Avu5h
                                            TLSH:4373391429D08233F6E3F977F5B47DE548397E9817883AEF10A254FA28251D24D39B8E
                                            File Content Preview:MZ......................@...............................................!..L.!This ...l!sm cannot be run in DOS mode....$.......AU@..4...4...4..Ce...4..Ce...4...f...4...4...4...L...4...4/..4...f...4...f...4...f...4..Rich.4..................PE..L...].vZ...
                                            Icon Hash:00828e8e8686b000
                                            Entrypoint:0x404af0
                                            Entrypoint Section:.text
                                            Digitally signed:false
                                            Imagebase:0x400000
                                            Subsystem:windows gui
                                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                            Time Stamp:0x5A76065D [Sat Feb 3 18:58:37 2018 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:
                                            OS Version Major:5
                                            OS Version Minor:1
                                            File Version Major:5
                                            File Version Minor:1
                                            Subsystem Version Major:5
                                            Subsystem Version Minor:1
                                            Import Hash:40306b615af659fc1f93cfb121cc38d9
                                            Instruction
                                            push ebp
                                            mov ebp, esp
                                            call 00007F4374BA6EFDh
                                            push 00000000h
                                            call dword ptr [00409168h]
                                            pop ebp
                                            ret
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            push ebp
                                            mov ebp, esp
                                            sub esp, 5Ch
                                            push esi
                                            push 00000044h
                                            lea eax, dword ptr [ebp-58h]
                                            xorps xmm0, xmm0
                                            push 00000000h
                                            push eax
                                            mov esi, ecx
                                            movdqu dqword ptr [ebp-10h], xmm0
                                            call 00007F4374BAB157h
                                            mov eax, dword ptr [00412B0Ch]
                                            add esp, 0Ch
                                            mov dword ptr [ebp-18h], eax
                                            mov dword ptr [ebp-1Ch], eax
                                            mov eax, dword ptr [00412B08h]
                                            or dword ptr [ebp-2Ch], 00000101h
                                            mov dword ptr [ebp-20h], eax
                                            xor eax, eax
                                            mov word ptr [ebp-28h], ax
                                            lea eax, dword ptr [ebp-10h]
                                            push eax
                                            lea eax, dword ptr [ebp-58h]
                                            mov dword ptr [ebp-58h], 00000044h
                                            push eax
                                            push 00000000h
                                            push 00000000h
                                            push 00000000h
                                            push 00000001h
                                            push 00000000h
                                            push 00000000h
                                            push esi
                                            push 00000000h
                                            call dword ptr [00409164h]
                                            test eax, eax
                                            jne 00007F4374BA715Dh
                                            call dword ptr [00409064h]
                                            pop esi
                                            mov esp, ebp
                                            pop ebp
                                            ret
                                            push dword ptr [ebp-10h]
                                            mov esi, dword ptr [0040910Ch]
                                            call esi
                                            push dword ptr [ebp-0Ch]
                                            call esi
                                            pop esi
                                            mov esp, ebp
                                            pop ebp
                                            ret
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            int3
                                            push ebp
                                            mov ebp, esp
                                            sub esp, 10h
                                            movq xmm0, qword ptr [0040FF2Ch]
                                            mov al, byte ptr [0040FF34h]
                                            push ebx
                                            mov ebx, dword ptr [ebp+08h]
                                            Programming Language:
                                            • [ C ] VS2013 build 21005
                                            • [IMP] VS2008 SP1 build 30729
                                            • [RES] VS2013 build 21005
                                            • [LNK] VS2013 build 21005
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x109700xb4.rdata
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x140000x1e0.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x150000xab0.reloc
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x10000x80000x8000False0.448028564453125data6.296861858288883IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                            .rdata0x90000x90000x8600False0.45848880597014924data6.1322099086141595IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .data0x120000x10000xc00False0.25390625data3.450195070880191IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .CRT0x130000x10000x200False0.03125UTF-8 Unicode text, with no line terminators0.06116285224115448IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .rsrc0x140000x10000x200False0.52734375data4.710061382693063IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .reloc0x150000x10000xc00False0.7750651041666666data6.434410350416442IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountry
                                            RT_MANIFEST0x140600x17dXML 1.0 document textEnglishUnited States
                                            DLLImport
                                            KERNEL32.dllSetFilePointer, GetFileAttributesW, ReadFile, GetLastError, MoveFileW, lstrcpyW, SetFileAttributesW, CreateMutexW, GetDriveTypeW, VerSetConditionMask, WaitForSingleObject, GetTickCount, InitializeCriticalSection, OpenProcess, GetSystemDirectoryW, TerminateThread, Sleep, TerminateProcess, VerifyVersionInfoW, WaitForMultipleObjects, DeleteCriticalSection, ExpandEnvironmentStringsW, lstrlenW, SetHandleInformation, lstrcatA, MultiByteToWideChar, CreatePipe, lstrcmpiA, Process32NextW, CreateToolhelp32Snapshot, LeaveCriticalSection, EnterCriticalSection, FindFirstFileW, lstrcmpW, FindClose, FindNextFileW, GetNativeSystemInfo, GetComputerNameW, GetDiskFreeSpaceW, GetWindowsDirectoryW, GetVolumeInformationW, LoadLibraryA, lstrcmpiW, VirtualFree, CreateThread, CloseHandle, lstrcatW, CreateFileMappingW, ExitThread, CreateFileW, GetModuleFileNameW, WriteFile, GetModuleHandleW, UnmapViewOfFile, MapViewOfFile, GetFileSize, GetEnvironmentVariableW, lstrcpyA, GetModuleHandleA, VirtualAlloc, Process32FirstW, GetTempPathW, GetProcAddress, GetProcessHeap, HeapFree, HeapAlloc, lstrlenA, CreateProcessW, ExitProcess, IsProcessorFeaturePresent
                                            USER32.dllwsprintfW, TranslateMessage, RegisterClassExW, LoadIconW, SetWindowLongW, EndPaint, BeginPaint, LoadCursorW, GetMessageW, ShowWindow, CreateWindowExW, SendMessageW, DispatchMessageW, DefWindowProcW, UpdateWindow, GetForegroundWindow, DestroyWindow
                                            GDI32.dllTextOutW
                                            ADVAPI32.dllCryptExportKey, AllocateAndInitializeSid, RegSetValueExW, RegCreateKeyExW, RegCloseKey, CryptAcquireContextW, CryptGetKeyParam, CryptReleaseContext, CryptImportKey, CryptEncrypt, CryptGenKey, CryptDestroyKey, GetUserNameW, RegQueryValueExW, RegOpenKeyExW, FreeSid
                                            SHELL32.dllSHGetSpecialFolderPathW, ShellExecuteExW, ShellExecuteW
                                            CRYPT32.dllCryptStringToBinaryA, CryptBinaryToStringA
                                            WININET.dllInternetCloseHandle, HttpAddRequestHeadersW, HttpSendRequestW, InternetConnectW, HttpOpenRequestW, InternetOpenW, InternetReadFile
                                            PSAPI.DLLEnumDeviceDrivers, GetDeviceDriverBaseNameW
                                            Language of compilation systemCountry where language is spokenMap
                                            EnglishUnited States
                                            TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                            192.168.2.58.8.8.860180532829500 09/01/22-00:02:50.502751UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36018053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854371532026737 09/01/22-00:04:03.802921UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5437153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858474532829498 09/01/22-00:02:46.409357UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15847453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856690532026737 09/01/22-00:02:34.794476UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5669053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852975532829500 09/01/22-00:03:40.177431UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35297553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859224532829500 09/01/22-00:02:18.976716UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35922453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853975532829500 09/01/22-00:02:39.645914UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35397553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861348532829498 09/01/22-00:02:38.530362UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16134853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860024532829498 09/01/22-00:02:55.250291UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16002453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853827532026737 09/01/22-00:03:02.774286UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5382753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860910532026737 09/01/22-00:03:28.310952UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6091053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863730532829498 09/01/22-00:03:33.977550UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16373053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860183532829498 09/01/22-00:03:48.283959UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16018353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854587532829498 09/01/22-00:03:23.124735UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15458753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850904532829500 09/01/22-00:02:58.051616UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35090453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855070532026737 09/01/22-00:02:20.361607UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5507053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850089532829500 09/01/22-00:03:18.466985UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35008953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859587532829498 09/01/22-00:04:04.114751UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15958753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855597532026737 09/01/22-00:04:09.936181UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5559753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865325532026737 09/01/22-00:02:04.877624UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862662532026737 09/01/22-00:02:25.469721UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6266253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865120532829498 09/01/22-00:04:10.763289UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16512053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861296532829498 09/01/22-00:03:15.496749UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16129653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857484532026737 09/01/22-00:03:30.517521UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5748453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858446532829498 09/01/22-00:03:43.925486UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15844653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864315532829498 09/01/22-00:03:59.415810UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16431553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865333532829498 09/01/22-00:03:39.670910UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16533353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852193532026737 09/01/22-00:03:21.210468UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5219353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852103532829500 09/01/22-00:03:27.689357UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35210353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865119532829498 09/01/22-00:04:10.743391UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16511953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850566532829500 09/01/22-00:04:04.976212UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35056653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863448532829500 09/01/22-00:02:12.612834UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36344853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862059532829500 09/01/22-00:03:32.850991UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36205953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858476532829498 09/01/22-00:02:46.511401UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15847653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862938532026737 09/01/22-00:03:42.736982UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6293853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860181532829498 09/01/22-00:03:48.237956UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16018153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858626532829498 09/01/22-00:03:28.872267UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15862653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865328532026737 09/01/22-00:02:04.942715UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864497532026737 09/01/22-00:03:56.326355UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6449753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860286532026737 09/01/22-00:02:53.057441UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6028653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853559532026737 09/01/22-00:03:13.202744UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5355953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850446532829498 09/01/22-00:03:53.963216UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15044653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856116532026737 09/01/22-00:04:05.801650UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5611653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849729532829498 09/01/22-00:02:01.433122UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14972953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863451532829500 09/01/22-00:02:12.684530UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36345153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858535532829500 09/01/22-00:02:23.142881UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35853553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850448532829498 09/01/22-00:03:54.015145UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15044853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864499532026737 09/01/22-00:03:56.365974UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6449953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851489532829498 09/01/22-00:02:06.151880UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15148953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865117532829498 09/01/22-00:04:10.704503UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16511753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852191532026737 09/01/22-00:03:21.167674UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5219153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856119532026737 09/01/22-00:04:05.881610UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5611953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856689532026737 09/01/22-00:02:34.772206UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5668953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858584532829498 09/01/22-00:02:31.231912UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15858453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849963532026737 09/01/22-00:03:35.711880UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4996353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860182532829500 09/01/22-00:02:50.545957UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36018253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854589532829498 09/01/22-00:03:23.168676UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15458953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865515532829500 09/01/22-00:02:32.912023UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855072532026737 09/01/22-00:02:20.399331UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5507253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858443532829498 09/01/22-00:03:43.862727UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15844353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854590532829498 09/01/22-00:03:23.192418UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15459053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849581532829500 09/01/22-00:03:11.014979UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34958153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856754532026737 09/01/22-00:02:14.833183UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5675453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849773532829498 09/01/22-00:03:05.323153UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14977353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858444532829498 09/01/22-00:03:43.882038UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15844453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853558532026737 09/01/22-00:03:13.174170UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5355853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852105532829500 09/01/22-00:03:27.730338UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35210553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849727532829498 09/01/22-00:02:01.394041UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14972753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859301532829500 09/01/22-00:04:07.531976UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35930153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858537532829500 09/01/22-00:02:23.186317UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35853753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852101532829498 09/01/22-00:03:32.288887UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15210153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853430532026737 09/01/22-00:03:47.092445UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5343053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855595532026737 09/01/22-00:04:09.898241UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5559553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852978532829500 09/01/22-00:03:40.236027UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35297853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860912532026737 09/01/22-00:03:28.349098UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6091253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851487532829498 09/01/22-00:02:06.112309UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15148753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858628532829498 09/01/22-00:03:28.916264UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15862853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851486532829498 09/01/22-00:02:06.080173UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15148653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856118532026737 09/01/22-00:04:05.861618UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5611853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849583532829500 09/01/22-00:03:11.058420UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34958353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850565532829500 09/01/22-00:04:04.955935UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35056553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859300532829500 09/01/22-00:04:07.513788UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35930053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856692532026737 09/01/22-00:02:34.840093UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5669253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860911532026737 09/01/22-00:03:28.331020UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6091153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849584532829500 09/01/22-00:03:11.078564UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34958453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853431532026737 09/01/22-00:03:47.111713UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5343153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858874532829500 09/01/22-00:03:38.011985UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35887453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850082532829500 09/01/22-00:03:34.671276UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35008253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862062532829500 09/01/22-00:03:32.918939UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36206253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855596532026737 09/01/22-00:04:09.918088UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5559653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849962532026737 09/01/22-00:03:35.689392UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4996253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858583532829498 09/01/22-00:02:31.210676UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15858353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863941532026737 09/01/22-00:03:52.370596UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6394153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855611532829498 09/01/22-00:03:36.403141UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15561153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855614532829498 09/01/22-00:03:36.468326UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15561453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861346532829498 09/01/22-00:02:38.490397UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16134653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850091532829500 09/01/22-00:03:18.513860UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35009153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860298532026737 09/01/22-00:03:33.383268UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6029853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852896532026737 09/01/22-00:03:39.114275UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5289653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864313532829498 09/01/22-00:03:58.875073UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16431353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849726532829498 09/01/22-00:02:01.372827UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14972653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860288532026737 09/01/22-00:02:53.105768UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6028853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851726532829500 09/01/22-00:03:55.342624UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35172653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850079532829500 09/01/22-00:03:34.606965UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35007953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856753532026737 09/01/22-00:02:14.812380UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5675353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862663532026737 09/01/22-00:02:25.489629UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6266353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861019532829498 09/01/22-00:04:06.677904UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16101953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861455532829500 09/01/22-00:02:03.672879UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36145553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853977532829500 09/01/22-00:02:39.698321UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35397753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865496532829500 09/01/22-00:03:29.520510UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36549653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856685532829498 09/01/22-00:02:21.613022UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15668553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864937532026737 09/01/22-00:02:42.055156UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6493753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854369532026737 09/01/22-00:04:03.762307UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5436953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865516532829500 09/01/22-00:02:32.934243UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849266532829500 09/01/22-00:04:00.982711UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34926653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858534532829500 09/01/22-00:02:23.120247UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35853453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859585532829498 09/01/22-00:04:04.074500UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15958553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850447532829498 09/01/22-00:03:53.986780UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15044753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850906532829500 09/01/22-00:02:58.094801UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35090653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852190532026737 09/01/22-00:03:21.145887UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5219053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858877532829500 09/01/22-00:03:38.072921UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35887753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861298532829498 09/01/22-00:03:15.537246UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16129853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863449532829500 09/01/22-00:02:12.647016UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36344953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853825532026737 09/01/22-00:03:02.730691UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5382553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862937532026737 09/01/22-00:03:42.718178UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6293753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864498532026737 09/01/22-00:03:56.346913UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6449853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864314532829498 09/01/22-00:03:59.395837UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16431453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855730532829500 09/01/22-00:03:44.550258UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35573053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865118532829498 09/01/22-00:04:10.725130UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16511853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856686532829498 09/01/22-00:02:21.631696UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15668653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862661532026737 09/01/22-00:02:25.448208UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6266153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850905532829500 09/01/22-00:02:58.072382UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35090553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860023532829498 09/01/22-00:02:55.231073UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16002353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849964532026737 09/01/22-00:03:35.733293UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4996453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865332532829498 09/01/22-00:03:39.649023UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16533253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860182532829498 09/01/22-00:03:48.263650UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16018253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863731532829498 09/01/22-00:03:33.997566UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16373153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858625532829498 09/01/22-00:03:28.850497UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15862553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852102532829500 09/01/22-00:03:27.668953UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35210253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865495532829500 09/01/22-00:03:29.499361UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36549553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854588532829498 09/01/22-00:03:23.146755UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15458853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855071532026737 09/01/22-00:02:20.380296UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5507153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853429532026737 09/01/22-00:03:47.068211UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5342953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863942532026737 09/01/22-00:03:52.388948UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6394253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853974532829500 09/01/22-00:02:39.626606UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35397453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854372532026737 09/01/22-00:04:03.823257UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5437253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849263532829500 09/01/22-00:04:00.923809UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34926353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853432532026737 09/01/22-00:03:47.130970UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5343253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864934532026737 09/01/22-00:02:41.995822UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6493453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852897532026737 09/01/22-00:03:39.132619UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5289753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862939532026737 09/01/22-00:03:42.757239UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6293953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861295532829498 09/01/22-00:03:15.476530UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16129553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857485532026737 09/01/22-00:03:30.537077UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5748553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859588532829498 09/01/22-00:04:04.134905UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15958853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859223532829500 09/01/22-00:02:18.950858UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35922353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853828532026737 09/01/22-00:03:02.797461UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5382853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857382532829500 09/01/22-00:03:50.398087UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35738253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860977532829498 09/01/22-00:02:16.533431UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16097753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861349532829498 09/01/22-00:02:38.549773UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16134953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858475532829498 09/01/22-00:02:46.486527UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15847553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860287532026737 09/01/22-00:02:53.081721UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6028753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861297532829498 09/01/22-00:03:15.516933UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16129753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850088532829500 09/01/22-00:03:18.446546UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35008853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859586532829498 09/01/22-00:04:04.094596UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15958653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859299532829500 09/01/22-00:04:07.496000UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35929953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852100532829498 09/01/22-00:03:32.267998UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15210053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860184532829498 09/01/22-00:03:48.305240UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16018453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860980532829498 09/01/22-00:02:16.604526UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16098053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853976532829500 09/01/22-00:02:39.666430UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35397653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865497532829500 09/01/22-00:03:29.542703UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36549753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857379532829500 09/01/22-00:03:50.318564UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35737953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861454532829500 09/01/22-00:02:03.654444UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36145453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853560532026737 09/01/22-00:03:13.225920UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5356053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852104532829500 09/01/22-00:03:27.710044UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35210453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858445532829498 09/01/22-00:03:43.903621UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15844553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856756532026737 09/01/22-00:02:14.874396UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5675653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856684532829498 09/01/22-00:02:21.592544UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15668453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853826532026737 09/01/22-00:03:02.751283UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5382653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858586532829498 09/01/22-00:02:31.279996UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15858653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849771532829498 09/01/22-00:03:05.189017UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14977153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865334532829498 09/01/22-00:03:39.691657UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16533453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861347532829498 09/01/22-00:02:38.510793UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16134753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860021532829498 09/01/22-00:02:55.191369UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16002153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855729532829500 09/01/22-00:03:44.527150UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35572953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850907532829500 09/01/22-00:02:58.117260UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35090753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859807532829500 09/01/22-00:03:55.275052UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35980753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861021532829498 09/01/22-00:04:06.718974UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16102153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859225532829500 09/01/22-00:02:19.007298UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35922553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865326532026737 09/01/22-00:02:04.899187UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860297532026737 09/01/22-00:03:33.363249UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6029753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863733532829498 09/01/22-00:03:34.037884UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16373353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849774532829498 09/01/22-00:03:05.512260UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14977453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860289532026737 09/01/22-00:02:53.129672UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6028953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.853557532026737 09/01/22-00:03:13.152000UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5355753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858876532829500 09/01/22-00:03:38.053463UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35887653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850081532829500 09/01/22-00:03:34.650981UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35008153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852976532829500 09/01/22-00:03:40.199013UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35297653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862664532026737 09/01/22-00:02:25.509064UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6266453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864312532829498 09/01/22-00:03:58.856410UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16431253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857487532026737 09/01/22-00:03:30.582629UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5748753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856117532026737 09/01/22-00:04:05.841041UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5611753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865517532829500 09/01/22-00:02:32.956296UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852895532026737 09/01/22-00:03:39.091614UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5289553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851724532829500 09/01/22-00:03:55.294608UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35172453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860299532026737 09/01/22-00:03:33.401260UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6029953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852098532829498 09/01/22-00:03:32.229187UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15209853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849961532026737 09/01/22-00:03:35.669538UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)4996153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849265532829500 09/01/22-00:04:00.962398UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34926553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860979532829498 09/01/22-00:02:16.584622UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16097953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858477532829498 09/01/22-00:02:46.531265UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15847753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857380532829500 09/01/22-00:03:50.340625UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35738053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855613532829498 09/01/22-00:03:36.446288UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15561353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862936532026737 09/01/22-00:03:42.697375UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6293653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861020532829498 09/01/22-00:04:06.699436UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16102053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861456532829500 09/01/22-00:02:03.693126UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36145653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865498532829500 09/01/22-00:03:29.567003UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36549853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850080532829500 09/01/22-00:03:34.627091UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35008053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864936532026737 09/01/22-00:02:42.036797UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6493653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859222532829500 09/01/22-00:02:18.931529UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35922253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855612532829498 09/01/22-00:03:36.425992UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15561253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857381532829500 09/01/22-00:03:50.368405UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35738153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858536532829500 09/01/22-00:02:23.164990UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35853653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862060532829500 09/01/22-00:03:32.873172UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36206053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860179532829500 09/01/22-00:02:50.481998UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36017953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.859298532829500 09/01/22-00:04:07.476417UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35929853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860978532829498 09/01/22-00:02:16.558773UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16097853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864496532026737 09/01/22-00:03:56.305340UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6449653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863940532026737 09/01/22-00:03:52.350223UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6394053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850090532829500 09/01/22-00:03:18.489552UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35009053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850564532829500 09/01/22-00:04:04.937269UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35056453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861018532829498 09/01/22-00:04:06.657229UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16101853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849264532829500 09/01/22-00:04:00.944094UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34926453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849772532829498 09/01/22-00:03:05.233383UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14977253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865518532829500 09/01/22-00:02:32.980619UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36551853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851725532829500 09/01/22-00:03:55.314556UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35172553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.862061532829500 09/01/22-00:03:32.897217UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36206153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852192532026737 09/01/22-00:03:21.187862UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5219253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.864935532026737 09/01/22-00:02:42.016020UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6493553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858875532829500 09/01/22-00:03:38.032851UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35887553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863732532829498 09/01/22-00:03:34.017665UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16373253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.861457532829500 09/01/22-00:02:03.713490UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36145753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850449532829498 09/01/22-00:03:54.035960UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15044953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856691532026737 09/01/22-00:02:34.816978UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5669153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855731532829500 09/01/22-00:03:44.568358UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35573153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849582532829500 09/01/22-00:03:11.038348UDP2829500ETPRO TROJAN GandCrab DNS Lookup 34958253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856687532829498 09/01/22-00:02:21.652316UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15668753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.854370532026737 09/01/22-00:04:03.782854UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5437053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852099532829498 09/01/22-00:03:32.248418UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15209953192.168.2.58.8.8.8
                                            192.168.2.58.8.8.857486532026737 09/01/22-00:03:30.561309UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5748653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860022532829498 09/01/22-00:02:55.212194UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16002253192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852894532026737 09/01/22-00:03:39.072653UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5289453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858627532829498 09/01/22-00:03:28.892335UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15862753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.849728532829498 09/01/22-00:02:01.412620UDP2829498ETPRO TROJAN GandCrab DNS Lookup 14972853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860913532026737 09/01/22-00:03:28.369056UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6091353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855073532026737 09/01/22-00:02:20.420031UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5507353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855594532026737 09/01/22-00:04:09.880111UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5559453192.168.2.58.8.8.8
                                            192.168.2.58.8.8.856755532026737 09/01/22-00:02:14.854023UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)5675553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860181532829500 09/01/22-00:02:50.523251UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36018153192.168.2.58.8.8.8
                                            192.168.2.58.8.8.852977532829500 09/01/22-00:03:40.217833UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35297753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863450532829500 09/01/22-00:02:12.666416UDP2829500ETPRO TROJAN GandCrab DNS Lookup 36345053192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865335532829498 09/01/22-00:03:39.713005UDP2829498ETPRO TROJAN GandCrab DNS Lookup 16533553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.858585532829498 09/01/22-00:02:31.250178UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15858553192.168.2.58.8.8.8
                                            192.168.2.58.8.8.851488532829498 09/01/22-00:02:06.132219UDP2829498ETPRO TROJAN GandCrab DNS Lookup 15148853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.855728532829500 09/01/22-00:03:44.508575UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35572853192.168.2.58.8.8.8
                                            192.168.2.58.8.8.863943532026737 09/01/22-00:03:52.415647UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6394353192.168.2.58.8.8.8
                                            192.168.2.58.8.8.860296532026737 09/01/22-00:03:33.345251UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6029653192.168.2.58.8.8.8
                                            192.168.2.58.8.8.865327532026737 09/01/22-00:02:04.922757UDP2026737ET TROJAN Observed GandCrab Domain (gandcrab .bit)6532753192.168.2.58.8.8.8
                                            192.168.2.58.8.8.850567532829500 09/01/22-00:04:04.998120UDP2829500ETPRO TROJAN GandCrab DNS Lookup 35056753192.168.2.58.8.8.8
                                            TimestampSource PortDest PortSource IPDest IP
                                            Sep 1, 2022 00:01:59.911590099 CEST4917753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:01:59.931437016 CEST53491778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:01.239926100 CEST4972453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:01.334580898 CEST53497248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:01.352194071 CEST4972553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:01.372085094 CEST53497258.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:01.372827053 CEST4972653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:01.393094063 CEST53497268.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:01.394041061 CEST4972753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:01.412072897 CEST53497278.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:01.412620068 CEST4972853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:01.432477951 CEST53497288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:01.433121920 CEST4972953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:01.453190088 CEST53497298.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:02.555277109 CEST6145253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.563941002 CEST6145253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.608334064 CEST53614528.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:03.633827925 CEST53614528.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:03.633877039 CEST6145353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.653230906 CEST53614538.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:03.654443979 CEST6145453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.672249079 CEST53614548.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:03.672878981 CEST6145553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.692581892 CEST53614558.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:03.693125963 CEST6145653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.712928057 CEST53614568.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:03.713490009 CEST6145753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:03.733714104 CEST53614578.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:04.721681118 CEST6532353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:04.834590912 CEST53653238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:04.856112003 CEST6532453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:04.876791954 CEST53653248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:04.877624035 CEST6532553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:04.898612976 CEST53653258.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:04.899187088 CEST6532653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:04.920192003 CEST53653268.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:04.922756910 CEST6532753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:04.941993952 CEST53653278.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:04.942714930 CEST6532853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:04.961915970 CEST53653288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:06.005309105 CEST5148453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:06.042258024 CEST53514848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:06.059837103 CEST5148553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:06.078336954 CEST53514858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:06.080173016 CEST5148653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:06.101386070 CEST53514868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:06.112308979 CEST5148753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:06.131583929 CEST53514878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:06.132219076 CEST5148853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:06.151202917 CEST53514888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:06.151880026 CEST5148953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:06.173470020 CEST53514898.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:11.007499933 CEST6344653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.022016048 CEST6344653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.567970991 CEST53634468.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:12.591213942 CEST6344753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.610974073 CEST53634478.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:12.612833977 CEST6344853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.632694960 CEST53634488.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:12.647016048 CEST6344953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.665808916 CEST53634498.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:12.666415930 CEST6345053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.684042931 CEST53634508.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:12.684530020 CEST6345153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:12.704040051 CEST53634518.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:13.709269047 CEST5675153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.739041090 CEST5675153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.775738955 CEST53567518.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:14.792093039 CEST5675253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.811539888 CEST53567528.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:14.812380075 CEST5675353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.832356930 CEST53567538.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:14.833183050 CEST5675453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.853168011 CEST53567548.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:14.854022980 CEST5675553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.873765945 CEST53567558.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:14.874396086 CEST5675653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:14.894181013 CEST53567568.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:15.249150038 CEST53567518.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:15.933274984 CEST5503953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:16.027390957 CEST53634468.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:16.471765041 CEST53550398.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:16.490912914 CEST6097653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:16.512093067 CEST53609768.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:16.533431053 CEST6097753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:16.554326057 CEST53609778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:16.558773041 CEST6097853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:16.580204964 CEST53609788.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:16.584621906 CEST6097953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:16.603900909 CEST53609798.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:16.604526043 CEST6098053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:16.625678062 CEST53609808.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:18.327372074 CEST5922053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:18.866029978 CEST53592208.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:18.912621975 CEST5922153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:18.930771112 CEST53592218.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:18.931529045 CEST5922253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:18.950180054 CEST53592228.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:18.950858116 CEST5922353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:18.971628904 CEST53592238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:18.976716042 CEST5922453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:18.997745991 CEST53592248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:19.007297993 CEST5922553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:19.028003931 CEST53592258.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:20.212028027 CEST5506853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:20.281924009 CEST53550688.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:20.343282938 CEST5506953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:20.360511065 CEST53550698.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:20.361607075 CEST5507053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:20.379569054 CEST53550708.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:20.380295992 CEST5507153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:20.398627043 CEST53550718.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:20.399331093 CEST5507253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:20.419385910 CEST53550728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:20.420031071 CEST5507353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:20.438457966 CEST53550738.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:21.510334015 CEST5668253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:21.547008991 CEST53566828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:21.570235014 CEST5668353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:21.589804888 CEST53566838.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:21.592544079 CEST5668453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:21.612307072 CEST53566848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:21.613022089 CEST5668553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:21.631066084 CEST53566858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:21.631695986 CEST5668653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:21.651690006 CEST53566868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:21.652316093 CEST5668753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:21.670263052 CEST53566878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:22.988415956 CEST5853253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:23.073178053 CEST53585328.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:23.090640068 CEST5853353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:23.108946085 CEST53585338.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:23.120246887 CEST5853453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:23.139523029 CEST53585348.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:23.142880917 CEST5853553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:23.164510012 CEST53585358.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:23.164989948 CEST5853653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:23.185849905 CEST53585368.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:23.186316967 CEST5853753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:23.208182096 CEST53585378.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:24.293374062 CEST6265953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.285326958 CEST6265953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.395417929 CEST53626598.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:25.416001081 CEST6266053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.436459064 CEST53626608.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:25.448208094 CEST6266153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.469156981 CEST53626618.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:25.469721079 CEST6266253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.489044905 CEST53626628.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:25.489629030 CEST6266353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.508452892 CEST53626638.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:25.509063959 CEST6266453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:25.530004978 CEST53626648.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:28.241271019 CEST53626598.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:30.590687990 CEST5858153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:31.166659117 CEST53585818.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:31.191478968 CEST5858253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:31.209889889 CEST53585828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:31.210675955 CEST5858353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:31.231199026 CEST53585838.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:31.231911898 CEST5858453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:31.249490976 CEST53585848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:31.250178099 CEST5858553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:31.269680977 CEST53585858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:31.279995918 CEST5858653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:31.300205946 CEST53585868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:32.336535931 CEST5626353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:32.866913080 CEST53562638.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:32.885988951 CEST6551453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:32.905796051 CEST53655148.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:32.912023067 CEST6551553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:32.933625937 CEST53655158.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:32.934242964 CEST6551653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:32.955260038 CEST53655168.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:32.956295967 CEST6551753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:32.979974985 CEST53655178.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:32.980618954 CEST6551853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:33.001955032 CEST53655188.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:34.142494917 CEST5668753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:34.717264891 CEST53566878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:34.743534088 CEST5668853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:34.764400959 CEST53566888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:34.772206068 CEST5668953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:34.793865919 CEST53566898.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:34.794476032 CEST5669053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:34.816371918 CEST53566908.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:34.816977978 CEST5669153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:34.839456081 CEST53566918.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:34.840092897 CEST5669253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:34.859596014 CEST53566928.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:35.871191025 CEST6441953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:36.910881996 CEST6441953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:37.964308977 CEST6441953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:38.451112986 CEST53644198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:38.469635963 CEST6134553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:38.489614010 CEST53613458.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:38.490396976 CEST6134653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:38.510234118 CEST53613468.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:38.510792971 CEST6134753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:38.529823065 CEST53613478.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:38.530361891 CEST6134853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:38.544522047 CEST53644198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:38.549093008 CEST53613488.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:38.549772978 CEST6134953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:38.569746971 CEST53613498.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.005251884 CEST53644198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.543435097 CEST5397253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:39.580847025 CEST53539728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.608720064 CEST5397353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:39.625894070 CEST53539738.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.626605988 CEST5397453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:39.645344973 CEST53539748.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.645914078 CEST5397553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:39.665539026 CEST53539758.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.666429996 CEST5397653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:39.686157942 CEST53539768.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:39.698321104 CEST5397753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:39.718056917 CEST53539778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:41.365394115 CEST6493253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:41.948688984 CEST53649328.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:41.974438906 CEST6493353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:41.993784904 CEST53649338.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:41.995821953 CEST6493453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:42.015419006 CEST53649348.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:42.016020060 CEST6493553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:42.035979033 CEST53649358.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:42.036797047 CEST6493653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:42.054507971 CEST53649368.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:42.055155993 CEST6493753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:42.075145006 CEST53649378.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:43.388982058 CEST5847253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:44.405422926 CEST5847253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:45.428538084 CEST5847253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:46.031758070 CEST53584728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:46.391263008 CEST5847353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:46.408472061 CEST53584738.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:46.409357071 CEST5847453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:46.428978920 CEST53584748.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:46.486526966 CEST5847553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:46.506362915 CEST53584758.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:46.511400938 CEST5847653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:46.529474020 CEST53584768.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:46.531265020 CEST5847753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:46.550900936 CEST53584778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:46.627775908 CEST53584728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:47.232079029 CEST53584728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:50.357605934 CEST6017753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:50.431725979 CEST53601778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:50.462135077 CEST6017853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:50.481153965 CEST53601788.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:50.481997967 CEST6017953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:50.502183914 CEST53601798.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:50.502751112 CEST6018053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:50.522468090 CEST53601808.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:50.523251057 CEST6018153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:50.545125961 CEST53601818.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:50.545957088 CEST6018253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:50.565229893 CEST53601828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:51.939711094 CEST6028453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:52.973716974 CEST6028453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:53.012386084 CEST53602848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:53.031869888 CEST6028553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:53.051094055 CEST53602858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:53.057440996 CEST6028653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:53.081031084 CEST53602868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:53.081721067 CEST6028753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:53.105006933 CEST53602878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:53.105767965 CEST6028853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:53.129003048 CEST53602888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:53.129672050 CEST6028953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:53.152440071 CEST53602898.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:54.129081964 CEST6001953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.115514040 CEST6001953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.143107891 CEST53600198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:55.169272900 CEST6002053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.190500021 CEST53600208.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:55.191369057 CEST6002153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.211363077 CEST53600218.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:55.212193966 CEST6002253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.230350971 CEST53600228.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:55.231072903 CEST6002353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.249286890 CEST53600238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:55.250291109 CEST6002453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:55.269426107 CEST53600248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:55.303771973 CEST53600198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:56.391621113 CEST5090253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:56.963818073 CEST53602848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:57.439699888 CEST5090253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:58.006582975 CEST53509028.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:58.030960083 CEST5090353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:58.050683022 CEST53509038.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:58.051615953 CEST5090453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:58.055273056 CEST53509028.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:58.071692944 CEST53509048.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:58.072381973 CEST5090553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:58.092132092 CEST53509058.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:58.094800949 CEST5090653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:58.112858057 CEST53509068.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:58.117259979 CEST5090753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:02:58.137913942 CEST53509078.8.8.8192.168.2.5
                                            Sep 1, 2022 00:02:59.546935081 CEST5382353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:00.539176941 CEST5382353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:01.593920946 CEST5382353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:02.673258066 CEST53538238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:02.707921982 CEST5382453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:02.728626013 CEST53538248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:02.730690956 CEST5382553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:02.749336004 CEST53538258.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:02.751282930 CEST5382653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:02.772249937 CEST53538268.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:02.774286032 CEST5382753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:02.794682980 CEST53538278.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:02.797461033 CEST5382853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:02.818588018 CEST53538288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:03.269387960 CEST53538238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:04.074176073 CEST4976953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:04.564574957 CEST53538238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:05.102104902 CEST4976953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:05.140230894 CEST53497698.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:05.167689085 CEST4977053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:05.186117887 CEST53497708.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:05.189017057 CEST4977153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:05.209920883 CEST53497718.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:05.233382940 CEST4977253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:05.252963066 CEST53497728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:05.323153019 CEST4977353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:05.340817928 CEST53497738.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:05.512259960 CEST4977453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:05.533775091 CEST53497748.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:09.094862938 CEST53497698.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:10.430033922 CEST4957953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:10.970557928 CEST53495798.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:10.994596958 CEST4958053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:11.013236046 CEST53495808.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:11.014978886 CEST4958153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:11.036653042 CEST53495818.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:11.038347960 CEST4958253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:11.057737112 CEST53495828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:11.058419943 CEST4958353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:11.077819109 CEST53495838.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:11.078563929 CEST4958453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:11.099826097 CEST53495848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:12.533488035 CEST5355553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:13.112035036 CEST53535558.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:13.129920006 CEST5355653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:13.151115894 CEST53535568.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:13.151999950 CEST5355753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:13.173320055 CEST53535578.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:13.174170017 CEST5355853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:13.196038961 CEST53535588.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:13.202744007 CEST5355953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:13.224518061 CEST53535598.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:13.225919962 CEST5356053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:13.246552944 CEST53535608.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:14.898765087 CEST6129353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:15.436304092 CEST53612938.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:15.455348969 CEST6129453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:15.474445105 CEST53612948.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:15.476530075 CEST6129553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:15.496115923 CEST53612958.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:15.496748924 CEST6129653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:15.516382933 CEST53612968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:15.516932964 CEST6129753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:15.536484003 CEST53612978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:15.537245989 CEST6129853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:15.554661036 CEST53612988.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:17.268368959 CEST5008653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.259387016 CEST5008653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.395138979 CEST53500868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:18.425247908 CEST5008753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.445703030 CEST53500878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:18.446546078 CEST5008853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.466348886 CEST53500888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:18.466984987 CEST5008953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.488691092 CEST53500898.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:18.489552021 CEST5009053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.510843992 CEST53500908.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:18.513859987 CEST5009153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:18.533323050 CEST53500918.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:19.081789970 CEST5218853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:19.943706036 CEST53500868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:20.074146986 CEST5218853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.087065935 CEST5218853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.117666960 CEST53521888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:21.124485970 CEST5218953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.145231009 CEST53521898.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:21.145886898 CEST5219053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.167120934 CEST53521908.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:21.167674065 CEST5219153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.187253952 CEST53521918.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:21.187861919 CEST5219253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.209659100 CEST53521928.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:21.210468054 CEST5219353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:21.230139017 CEST53521938.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:21.243673086 CEST53521888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:22.047276020 CEST5458553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:22.152108908 CEST53521888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:23.055248976 CEST5458553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:23.089651108 CEST53545858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:23.098977089 CEST5458653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:23.118304968 CEST53545868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:23.124735117 CEST5458753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:23.144418001 CEST53545878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:23.146754980 CEST5458853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:23.165380955 CEST53545888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:23.168675900 CEST5458953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:23.188942909 CEST53545898.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:23.192418098 CEST5459053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:23.213639021 CEST53545908.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:25.939043045 CEST5210053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.282510996 CEST5210053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.609777927 CEST53521008.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:27.648454905 CEST5210153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.668226004 CEST53521018.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:27.668952942 CEST5210253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.688935995 CEST53521028.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:27.689357042 CEST5210353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.709584951 CEST53521038.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:27.710043907 CEST5210453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.729931116 CEST53521048.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:27.730338097 CEST5210553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:27.748384953 CEST53521058.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:27.819541931 CEST53521008.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.075316906 CEST53545858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.205267906 CEST6090853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.274440050 CEST53609088.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.293237925 CEST6090953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.310379982 CEST53609098.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.310951948 CEST6091053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.330352068 CEST53609108.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.331020117 CEST6091153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.348592997 CEST53609118.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.349097967 CEST6091253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.368571997 CEST53609128.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.369055986 CEST6091353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.388623953 CEST53609138.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.783333063 CEST5862353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.819798946 CEST53586238.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.828504086 CEST5862453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.849626064 CEST53586248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.850497007 CEST5862553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.871601105 CEST53586258.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.872267008 CEST5862653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.891577005 CEST53586268.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.892334938 CEST5862753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.915539980 CEST53586278.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:28.916264057 CEST5862853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:28.937171936 CEST53586288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.413041115 CEST6549353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:29.466361046 CEST53654938.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.475575924 CEST6549453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:29.496511936 CEST53654948.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.499361038 CEST6549553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:29.516742945 CEST53654958.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.520509958 CEST6549653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:29.542265892 CEST53654968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.542702913 CEST6549753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:29.564232111 CEST53654978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.567003012 CEST6549853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:29.586312056 CEST53654988.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:29.950607061 CEST5748253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:30.487483025 CEST53574828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:30.496217012 CEST5748353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:30.516846895 CEST53574838.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:30.517520905 CEST5748453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:30.536672115 CEST53574848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:30.537076950 CEST5748553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:30.559077978 CEST53574858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:30.561309099 CEST5748653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:30.580718040 CEST53574868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:30.582628965 CEST5748753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:30.603596926 CEST53574878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:31.118854046 CEST5209653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.118266106 CEST5209653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.197714090 CEST53520968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.206779957 CEST5209753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.226025105 CEST53520978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.229187012 CEST5209853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.247734070 CEST53520988.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.248418093 CEST5209953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.259257078 CEST53520968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.267229080 CEST53520998.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.267997980 CEST5210053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.288376093 CEST53521008.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.288887024 CEST5210153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.309899092 CEST53521018.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.741540909 CEST6205753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.809542894 CEST53620578.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.826855898 CEST6205853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.847543955 CEST53620588.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.850991011 CEST6205953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.872570038 CEST53620598.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.873172045 CEST6206053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.894160032 CEST53620608.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.897217035 CEST6206153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.918351889 CEST53620618.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:32.918939114 CEST6206253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:32.940099001 CEST53620628.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.285465002 CEST6029453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.313813925 CEST53602948.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.323398113 CEST6029553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.340472937 CEST53602958.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.345251083 CEST6029653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.362754107 CEST53602968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.363249063 CEST6029753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.382714987 CEST53602978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.383268118 CEST6029853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.400686026 CEST53602988.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.401259899 CEST6029953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.420860052 CEST53602998.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.877412081 CEST6372853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.947339058 CEST53637288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.957496881 CEST6372953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.976629972 CEST53637298.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.977550030 CEST6373053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:33.997020960 CEST53637308.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:33.997565985 CEST6373153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.017164946 CEST53637318.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.017664909 CEST6373253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.037424088 CEST53637328.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.037883997 CEST6373353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.055460930 CEST53637338.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.510437965 CEST5007753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.579391003 CEST53500778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.589109898 CEST5007853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.606172085 CEST53500788.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.606965065 CEST5007953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.626548052 CEST53500798.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.627090931 CEST5008053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.645029068 CEST53500808.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.650980949 CEST5008153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.670808077 CEST53500818.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:34.671276093 CEST5008253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:34.691076040 CEST53500828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:35.101633072 CEST4995953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:35.637387991 CEST53499598.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:35.647269011 CEST4996053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:35.667938948 CEST53499608.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:35.669538021 CEST4996153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:35.688895941 CEST53499618.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:35.689392090 CEST4996253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:35.711240053 CEST53499628.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:35.711879969 CEST4996353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:35.732723951 CEST53499638.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:35.733293056 CEST4996453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:35.755530119 CEST53499648.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.301939011 CEST5560953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:36.375839949 CEST53556098.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.383898020 CEST5561053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:36.402359009 CEST53556108.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.403141022 CEST5561153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:36.424987078 CEST53556118.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.425992012 CEST5561253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:36.445525885 CEST53556128.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.446288109 CEST5561353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:36.467850924 CEST53556138.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.468326092 CEST5561453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:36.489662886 CEST53556148.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:36.851623058 CEST5887253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:37.856156111 CEST5887253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:37.983706951 CEST53588728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:37.990816116 CEST5887353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:38.011287928 CEST53588738.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:38.011985064 CEST5887453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:38.032377958 CEST53588748.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:38.032850981 CEST5887553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:38.052937031 CEST53588758.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:38.053462982 CEST5887653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:38.072388887 CEST53588768.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:38.072921038 CEST5887753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:38.090707064 CEST53588778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:38.425242901 CEST5289253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:38.996529102 CEST53528928.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.052143097 CEST5289353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.071681023 CEST53528938.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.072653055 CEST5289453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.091151953 CEST53528948.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.091614008 CEST5289553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.110236883 CEST53528958.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.114274979 CEST5289653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.132061005 CEST53528968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.132618904 CEST5289753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.151518106 CEST53528978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.482498884 CEST53588728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.587059021 CEST6533053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.615535975 CEST53653308.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.627641916 CEST6533153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.646815062 CEST53653318.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.649023056 CEST6533253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.666840076 CEST53653328.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.670909882 CEST6533353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.691112995 CEST53653338.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.691657066 CEST6533453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.711394072 CEST53653348.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:39.713005066 CEST6533553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:39.733046055 CEST53653358.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.106767893 CEST5297353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:40.144674063 CEST53529738.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.155935049 CEST5297453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:40.176877022 CEST53529748.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.177431107 CEST5297553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:40.198590040 CEST53529758.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.199012995 CEST5297653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:40.217324018 CEST53529768.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.217833042 CEST5297753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:40.235502958 CEST53529778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.236027002 CEST5297853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:40.253726959 CEST53529788.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:40.812171936 CEST5000553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:41.821934938 CEST5000553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:42.581233025 CEST53500058.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:42.678219080 CEST6293553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:42.695910931 CEST53629358.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:42.697375059 CEST6293653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:42.717495918 CEST53629368.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:42.718178034 CEST6293753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:42.736381054 CEST53629378.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:42.736982107 CEST6293853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:42.756829023 CEST53629388.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:42.757239103 CEST6293953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:42.774645090 CEST53629398.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:43.304724932 CEST5986253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:43.834578991 CEST53598628.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:43.843754053 CEST5844253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:43.862184048 CEST53584428.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:43.862726927 CEST5844353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:43.881683111 CEST53584438.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:43.882038116 CEST5844453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:43.903206110 CEST53584448.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:43.903620958 CEST5844553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:43.924917936 CEST53584458.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:43.925486088 CEST5844653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:43.945391893 CEST53584468.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.445437908 CEST5572653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:44.472067118 CEST53557268.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.482812881 CEST5572753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:44.500081062 CEST53557278.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.508574963 CEST5572853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:44.526537895 CEST53557288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.527149916 CEST5572953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:44.546730042 CEST53557298.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.550257921 CEST5573053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:44.567960024 CEST53557308.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.568357944 CEST5573153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:44.588005066 CEST53557318.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:44.976836920 CEST6192853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:45.831124067 CEST53500058.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:45.962614059 CEST6192853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:46.981189013 CEST6192853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:47.038166046 CEST53619288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.047594070 CEST5342853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:47.067724943 CEST53534288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.068211079 CEST5342953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:47.089193106 CEST53534298.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.092444897 CEST5343053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:47.111303091 CEST53534308.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.111712933 CEST5343153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:47.130348921 CEST53534318.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.130970001 CEST5343253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:47.152026892 CEST53534328.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.509731054 CEST53619288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:47.627257109 CEST6017953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:48.198370934 CEST53601798.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:48.218760967 CEST6018053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:48.237399101 CEST53601808.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:48.237956047 CEST6018153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:48.258917093 CEST53601818.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:48.263649940 CEST6018253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:48.283209085 CEST53601828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:48.283958912 CEST6018353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:48.304694891 CEST53601838.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:48.305239916 CEST6018453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:48.325745106 CEST53601848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:48.691673040 CEST5737753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:49.241806030 CEST53619288.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:49.697010994 CEST5737753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:50.281771898 CEST53573778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.300674915 CEST5737853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:50.307605028 CEST53573778.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.317943096 CEST53573788.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.318563938 CEST5737953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:50.338493109 CEST53573798.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.340625048 CEST5738053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:50.358608961 CEST53573808.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.368405104 CEST5738153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:50.388493061 CEST53573818.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.398087025 CEST5738253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:50.416033030 CEST53573828.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:50.775196075 CEST6393853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:51.779573917 CEST6393853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:52.316684961 CEST53639388.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:52.325777054 CEST6393953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:52.345062017 CEST53639398.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:52.350223064 CEST6394053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:52.370079041 CEST53639408.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:52.370595932 CEST6394153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:52.388272047 CEST53639418.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:52.388947964 CEST6394253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:52.412725925 CEST53639428.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:52.415647030 CEST6394353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:52.435429096 CEST53639438.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:52.890666008 CEST5044453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:53.896193027 CEST5044453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:53.933697939 CEST53504448.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:53.943182945 CEST5044553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:53.962321997 CEST53504458.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:53.963216066 CEST5044653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:53.984399080 CEST53504468.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:53.986779928 CEST5044753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:54.007458925 CEST53504478.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:54.015145063 CEST5044853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:54.026586056 CEST53504448.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:54.035367012 CEST53504488.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:54.035959959 CEST5044953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:54.055593014 CEST53504498.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:54.669785023 CEST5980553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.239881992 CEST53598058.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:55.253882885 CEST5980653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.274434090 CEST53598068.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:55.275052071 CEST5980753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.294156075 CEST53598078.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:55.294608116 CEST5172453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.313684940 CEST53517248.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:55.314555883 CEST5172553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.336025953 CEST53517258.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:55.342623949 CEST5172653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.364104986 CEST53517268.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:55.731010914 CEST6449453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:55.794974089 CEST53639388.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.268456936 CEST53644948.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.282052040 CEST6449553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:56.301691055 CEST53644958.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.305340052 CEST6449653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:56.325932980 CEST53644968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.326354980 CEST6449753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:56.346476078 CEST53644978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.346913099 CEST6449853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:56.365498066 CEST53644988.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.365973949 CEST6449953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:56.386655092 CEST53644998.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:56.795289993 CEST6431053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:57.797553062 CEST6431053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:58.797333002 CEST6431053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:58.825668097 CEST53643108.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:58.836684942 CEST6431153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:58.855791092 CEST53643118.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:58.856410027 CEST6431253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:58.874407053 CEST53643128.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:58.875072956 CEST6431353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:58.893013000 CEST53643138.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:59.395837069 CEST6431453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:59.415303946 CEST53643148.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:59.415810108 CEST6431553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:03:59.437519073 CEST53643158.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:59.477504015 CEST53643108.8.8.8192.168.2.5
                                            Sep 1, 2022 00:03:59.624346018 CEST4926153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:00.200125933 CEST53492618.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:00.706511974 CEST53643108.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:00.905369997 CEST4926253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:00.922754049 CEST53492628.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:00.923809052 CEST4926353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:00.943747044 CEST53492638.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:00.944093943 CEST4926453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:00.962049007 CEST53492648.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:00.962398052 CEST4926553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:00.982321024 CEST53492658.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:00.982711077 CEST4926653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:01.002304077 CEST53492668.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:01.164730072 CEST5436753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:02.157042980 CEST5436753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.156949043 CEST5436753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.734221935 CEST53543678.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:03.742338896 CEST5436853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.761651039 CEST53543688.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:03.762306929 CEST5436953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.782330036 CEST53543698.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:03.782854080 CEST5437053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.802499056 CEST53543708.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:03.802921057 CEST5437153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.822778940 CEST53543718.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:03.823256969 CEST5437253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:03.842823982 CEST53543728.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.020246983 CEST5958353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.048010111 CEST53595838.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.054968119 CEST5958453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.074004889 CEST53595848.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.074500084 CEST5958553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.094161987 CEST53595858.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.094595909 CEST5958653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.114377975 CEST53595868.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.114751101 CEST5958753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.134500980 CEST53595878.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.134905100 CEST5958853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.154583931 CEST53595888.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.195255041 CEST53543678.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.339045048 CEST5056253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.913227081 CEST53505628.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.919328928 CEST5056353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.936587095 CEST53505638.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.937268972 CEST5056453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.955105066 CEST53505648.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.955935001 CEST5056553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.975845098 CEST53505658.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.976212025 CEST5056653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:04.996162891 CEST53505668.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:04.998120070 CEST5056753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.017935991 CEST53505678.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.204899073 CEST5611453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.764825106 CEST53543678.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.773658037 CEST53561148.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.781946898 CEST5611553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.801095963 CEST53561158.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.801650047 CEST5611653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.840457916 CEST53561168.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.841041088 CEST5611753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.861089945 CEST53561178.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.861618042 CEST5611853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.881166935 CEST53561188.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:05.881609917 CEST5611953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:05.901103973 CEST53561198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.088465929 CEST6101653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:06.630609989 CEST53610168.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.636603117 CEST6101753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:06.656243086 CEST53610178.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.657228947 CEST6101853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:06.677496910 CEST53610188.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.677903891 CEST6101953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:06.698992968 CEST53610198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.699435949 CEST6102053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:06.718585014 CEST53610208.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.718974113 CEST6102153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:06.737366915 CEST53610218.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:06.913439989 CEST5929653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:07.451251030 CEST53592968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:07.458348036 CEST5929753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:07.475867033 CEST53592978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:07.476417065 CEST5929853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:07.495662928 CEST53592988.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:07.496000051 CEST5929953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:07.513513088 CEST53592998.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:07.513787985 CEST5930053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:07.531666040 CEST53593008.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:07.531975985 CEST5930153192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:07.552181005 CEST53593018.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:07.723758936 CEST5559253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:08.720289946 CEST5559253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.720633984 CEST5559253192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.852585077 CEST53555928.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:09.860241890 CEST5559353192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.861260891 CEST53555928.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:09.879578114 CEST53555938.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:09.880110979 CEST5559453192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.897767067 CEST53555948.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:09.898241043 CEST5559553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.917709112 CEST53555958.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:09.918087959 CEST5559653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.935751915 CEST53555968.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:09.936181068 CEST5559753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:09.956202984 CEST53555978.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.134829044 CEST6511553192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:10.284883022 CEST53555928.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.678015947 CEST53651158.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.686275959 CEST6511653192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:10.703870058 CEST53651168.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.704503059 CEST6511753192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:10.724714041 CEST53651178.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.725130081 CEST6511853192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:10.742995024 CEST53651188.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.743391037 CEST6511953192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:10.762958050 CEST53651198.8.8.8192.168.2.5
                                            Sep 1, 2022 00:04:10.763288975 CEST6512053192.168.2.58.8.8.8
                                            Sep 1, 2022 00:04:10.784327984 CEST53651208.8.8.8192.168.2.5
                                            TimestampSource IPDest IPChecksumCodeType
                                            Sep 1, 2022 00:02:03.633960009 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:15.249326944 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:28.241391897 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:38.546083927 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:46.627891064 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:55.305211067 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:56.963974953 CEST192.168.2.58.8.8.8cff5(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:02:58.055891037 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:03.269479036 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:04.564671040 CEST192.168.2.58.8.8.8cff5(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:09.094980001 CEST192.168.2.58.8.8.8cff5(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:19.943866014 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:21.243824959 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:22.152236938 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:27.819679022 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:32.259469986 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:39.482671976 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:45.831290960 CEST192.168.2.58.8.8.8cff5(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:47.510422945 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:49.242109060 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:50.310148954 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:54.026720047 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:55.795069933 CEST192.168.2.58.8.8.8cff5(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:03:59.477780104 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:04:00.706722975 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:04:04.195362091 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:04:05.764991999 CEST192.168.2.58.8.8.8cff5(Port unreachable)Destination Unreachable
                                            Sep 1, 2022 00:04:09.861358881 CEST192.168.2.58.8.8.8d032(Port unreachable)Destination Unreachable
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                            Sep 1, 2022 00:01:59.911590099 CEST192.168.2.58.8.8.80xb66eStandard query (0)ipv4bot.whatismyipaddress.comA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.239926100 CEST192.168.2.58.8.8.80xe0a0Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.352194071 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:01.372827053 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.394041061 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:01.412620068 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.433121920 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:02.555277109 CEST192.168.2.58.8.8.80xdfb2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.563941002 CEST192.168.2.58.8.8.80xdfb2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.633877039 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:03.654443979 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.672878981 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:03.693125963 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.713490009 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:04.721681118 CEST192.168.2.58.8.8.80x3cd5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:04.856112003 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:04.877624035 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:04.899187088 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:04.922756910 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:04.942714930 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:06.005309105 CEST192.168.2.58.8.8.80x27fdStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:06.059837103 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:06.080173016 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:06.112308979 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:06.132219076 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:06.151880026 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:11.007499933 CEST192.168.2.58.8.8.80x5f2aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.022016048 CEST192.168.2.58.8.8.80x5f2aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.591213942 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:12.612833977 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.647016048 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:12.666415930 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.684530020 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:13.709269047 CEST192.168.2.58.8.8.80xe32fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.739041090 CEST192.168.2.58.8.8.80xe32fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.792093039 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:14.812380075 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.833183050 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:14.854022980 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.874396086 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:15.933274984 CEST192.168.2.58.8.8.80x2c2fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.490912914 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:16.533431053 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.558773041 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:16.584621906 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.604526043 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:18.327372074 CEST192.168.2.58.8.8.80xb4aeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:18.912621975 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:18.931529045 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:18.950858116 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:18.976716042 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:19.007297993 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:20.212028027 CEST192.168.2.58.8.8.80x65f7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:20.343282938 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:20.361607075 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:20.380295992 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:20.399331093 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:20.420031071 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:21.510334015 CEST192.168.2.58.8.8.80x17a5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:21.570235014 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:21.592544079 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:21.613022089 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:21.631695986 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:21.652316093 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:22.988415956 CEST192.168.2.58.8.8.80xf0fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:23.090640068 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:23.120246887 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:23.142880917 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:23.164989948 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:23.186316967 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:24.293374062 CEST192.168.2.58.8.8.80x1940Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.285326958 CEST192.168.2.58.8.8.80x1940Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.416001081 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:25.448208094 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.469721079 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:25.489629030 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.509063959 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:30.590687990 CEST192.168.2.58.8.8.80x1450Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.191478968 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:31.210675955 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.231911898 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:31.250178099 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.279995918 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:32.336535931 CEST192.168.2.58.8.8.80x6c66Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:32.885988951 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:32.912023067 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:32.934242964 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:32.956295967 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:32.980618954 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:34.142494917 CEST192.168.2.58.8.8.80xda28Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:34.743534088 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:34.772206068 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:34.794476032 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:34.816977978 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:34.840092897 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:35.871191025 CEST192.168.2.58.8.8.80xfb8dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:36.910881996 CEST192.168.2.58.8.8.80xfb8dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:37.964308977 CEST192.168.2.58.8.8.80xfb8dStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.469635963 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:38.490396976 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.510792971 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:38.530361891 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.549772978 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:39.543435097 CEST192.168.2.58.8.8.80x374eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.608720064 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:39.626605988 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.645914078 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:39.666429996 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.698321104 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:41.365394115 CEST192.168.2.58.8.8.80xbde8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:41.974438906 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:41.995821953 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:42.016020060 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:42.036797047 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:42.055155993 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:43.388982058 CEST192.168.2.58.8.8.80x6fbdStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:44.405422926 CEST192.168.2.58.8.8.80x6fbdStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:45.428538084 CEST192.168.2.58.8.8.80x6fbdStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:46.391263008 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:46.409357071 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:46.486526966 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:46.511400938 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:46.531265020 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:50.357605934 CEST192.168.2.58.8.8.80xafd1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.462135077 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:50.481997967 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.502751112 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:50.523251057 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.545957088 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:51.939711094 CEST192.168.2.58.8.8.80xbfd8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:52.973716974 CEST192.168.2.58.8.8.80xbfd8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:53.031869888 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:53.057440996 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:53.081721067 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:53.105767965 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:53.129672050 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:54.129081964 CEST192.168.2.58.8.8.80xbfeeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.115514040 CEST192.168.2.58.8.8.80xbfeeStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.169272900 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:55.191369057 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.212193966 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:55.231072903 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.250291109 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:56.391621113 CEST192.168.2.58.8.8.80xa3e5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:57.439699888 CEST192.168.2.58.8.8.80xa3e5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.030960083 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:58.051615953 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.072381973 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:58.094800949 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.117259979 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:02:59.546935081 CEST192.168.2.58.8.8.80x8bd5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:00.539176941 CEST192.168.2.58.8.8.80x8bd5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:01.593920946 CEST192.168.2.58.8.8.80x8bd5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:02.707921982 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:02.730690956 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:02.751282930 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:02.774286032 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:02.797461033 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:04.074176073 CEST192.168.2.58.8.8.80xdae1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.102104902 CEST192.168.2.58.8.8.80xdae1Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.167689085 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:05.189017057 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.233382940 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:05.323153019 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.512259960 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:10.430033922 CEST192.168.2.58.8.8.80x82a2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:10.994596958 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:11.014978886 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:11.038347960 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:11.058419943 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:11.078563929 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:12.533488035 CEST192.168.2.58.8.8.80x4482Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:13.129920006 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:13.151999950 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:13.174170017 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:13.202744007 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:13.225919962 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:14.898765087 CEST192.168.2.58.8.8.80xe274Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:15.455348969 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:15.476530075 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:15.496748924 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:15.516932964 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:15.537245989 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:17.268368959 CEST192.168.2.58.8.8.80x55e4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.259387016 CEST192.168.2.58.8.8.80x55e4Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.425247908 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:18.446546078 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.466984987 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:18.489552021 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.513859987 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:19.081789970 CEST192.168.2.58.8.8.80x8b47Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:20.074146986 CEST192.168.2.58.8.8.80x8b47Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.087065935 CEST192.168.2.58.8.8.80x8b47Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.124485970 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:21.145886898 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.167674065 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:21.187861919 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.210468054 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:22.047276020 CEST192.168.2.58.8.8.80x560fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.055248976 CEST192.168.2.58.8.8.80x560fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.098977089 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:23.124735117 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.146754980 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:23.168675900 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.192418098 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:25.939043045 CEST192.168.2.58.8.8.80x82c5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.282510996 CEST192.168.2.58.8.8.80x82c5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.648454905 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:27.668952942 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.689357042 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:27.710043907 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.730338097 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:28.205267906 CEST192.168.2.58.8.8.80xf281Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.293237925 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:28.310951948 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.331020117 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:28.349097967 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.369055986 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:28.783333063 CEST192.168.2.58.8.8.80xdac3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.828504086 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:28.850497007 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.872267008 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:28.892334938 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.916264057 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:29.413041115 CEST192.168.2.58.8.8.80x163aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:29.475575924 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:29.499361038 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:29.520509958 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:29.542702913 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:29.567003012 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:29.950607061 CEST192.168.2.58.8.8.80xadc5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:30.496217012 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:30.517520905 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:30.537076950 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:30.561309099 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:30.582628965 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:31.118854046 CEST192.168.2.58.8.8.80xe338Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.118266106 CEST192.168.2.58.8.8.80xe338Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.206779957 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:32.229187012 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.248418093 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:32.267997980 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.288887024 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:32.741540909 CEST192.168.2.58.8.8.80xa108Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.826855898 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:32.850991011 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.873172045 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:32.897217035 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.918939114 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:33.285465002 CEST192.168.2.58.8.8.80xe874Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.323398113 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:33.345251083 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.363249063 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:33.383268118 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.401259899 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:33.877412081 CEST192.168.2.58.8.8.80xca6eStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.957496881 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:33.977550030 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.997565985 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:34.017664909 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.037883997 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:34.510437965 CEST192.168.2.58.8.8.80x3d5aStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.589109898 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:34.606965065 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.627090931 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:34.650980949 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.671276093 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:35.101633072 CEST192.168.2.58.8.8.80xa2a9Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:35.647269011 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:35.669538021 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:35.689392090 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:35.711879969 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:35.733293056 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:36.301939011 CEST192.168.2.58.8.8.80xd67bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:36.383898020 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:36.403141022 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:36.425992012 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:36.446288109 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:36.468326092 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:36.851623058 CEST192.168.2.58.8.8.80xba9fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:37.856156111 CEST192.168.2.58.8.8.80xba9fStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:37.990816116 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:38.011985064 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:38.032850981 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:38.053462982 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:38.072921038 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:38.425242901 CEST192.168.2.58.8.8.80x5fe7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.052143097 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:39.072653055 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.091614008 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:39.114274979 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.132618904 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:39.587059021 CEST192.168.2.58.8.8.80x82c2Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.627641916 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:39.649023056 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.670909882 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:39.691657066 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.713005066 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:40.106767893 CEST192.168.2.58.8.8.80x2edfStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:40.155935049 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:40.177431107 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:40.199012995 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:40.217833042 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:40.236027002 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:40.812171936 CEST192.168.2.58.8.8.80x8ccStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:41.821934938 CEST192.168.2.58.8.8.80x8ccStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:42.678219080 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:42.697375059 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:42.718178034 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:42.736982107 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:42.757239103 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:43.304724932 CEST192.168.2.58.8.8.80x2679Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:43.843754053 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:43.862726927 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:43.882038116 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:43.903620958 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:43.925486088 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:44.445437908 CEST192.168.2.58.8.8.80x4cffStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:44.482812881 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:44.508574963 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:44.527149916 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:44.550257921 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:44.568357944 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:44.976836920 CEST192.168.2.58.8.8.80x6ec8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:45.962614059 CEST192.168.2.58.8.8.80x6ec8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:46.981189013 CEST192.168.2.58.8.8.80x6ec8Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.047594070 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:47.068211079 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.092444897 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:47.111712933 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.130970001 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:47.627257109 CEST192.168.2.58.8.8.80x8128Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.218760967 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:48.237956047 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.263649940 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:48.283958912 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.305239916 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:48.691673040 CEST192.168.2.58.8.8.80xab90Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:49.697010994 CEST192.168.2.58.8.8.80xab90Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.300674915 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:50.318563938 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.340625048 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:50.368405104 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.398087025 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:50.775196075 CEST192.168.2.58.8.8.80x7c25Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:51.779573917 CEST192.168.2.58.8.8.80x7c25Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:52.325777054 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:52.350223064 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:52.370595932 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:52.388947964 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:52.415647030 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:52.890666008 CEST192.168.2.58.8.8.80x5962Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:53.896193027 CEST192.168.2.58.8.8.80x5962Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:53.943182945 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:53.963216066 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:53.986779928 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:54.015145063 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:54.035959959 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:54.669785023 CEST192.168.2.58.8.8.80xc5e7Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:55.253882885 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:55.275052071 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:55.294608116 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:55.314555883 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:55.342623949 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:55.731010914 CEST192.168.2.58.8.8.80x2f3Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.282052040 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:56.305340052 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.326354980 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:56.346913099 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.365973949 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:56.795289993 CEST192.168.2.58.8.8.80xe61cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:57.797553062 CEST192.168.2.58.8.8.80xe61cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:58.797333002 CEST192.168.2.58.8.8.80xe61cStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:58.836684942 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:58.856410027 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:58.875072956 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:59.395837069 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:59.415810108 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:03:59.624346018 CEST192.168.2.58.8.8.80xdb8bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.905369997 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:00.923809052 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.944093943 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:00.962398052 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.982711077 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:01.164730072 CEST192.168.2.58.8.8.80xc850Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:02.157042980 CEST192.168.2.58.8.8.80xc850Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.156949043 CEST192.168.2.58.8.8.80xc850Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.742338896 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:03.762306929 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.782854080 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:03.802921057 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.823256969 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:04.020246983 CEST192.168.2.58.8.8.80x9e81Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.054968119 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:04.074500084 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.094595909 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:04.114751101 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.134905100 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:04.339045048 CEST192.168.2.58.8.8.80xed4bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.919328928 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:04.937268972 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.955935001 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:04.976212025 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.998120070 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:05.204899073 CEST192.168.2.58.8.8.80x647bStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.781946898 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:05.801650047 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.841041088 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:05.861618042 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.881609917 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:06.088465929 CEST192.168.2.58.8.8.80xedf0Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:06.636603117 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:06.657228947 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:06.677903891 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:06.699435949 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:06.718974113 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:06.913439989 CEST192.168.2.58.8.8.80x3852Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:07.458348036 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:07.476417065 CEST192.168.2.58.8.8.80x2Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:07.496000051 CEST192.168.2.58.8.8.80x3Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:07.513787985 CEST192.168.2.58.8.8.80x4Standard query (0)emsisoft.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:07.531975985 CEST192.168.2.58.8.8.80x5Standard query (0)emsisoft.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:07.723758936 CEST192.168.2.58.8.8.80x26baStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:08.720289946 CEST192.168.2.58.8.8.80x26baStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.720633984 CEST192.168.2.58.8.8.80x26baStandard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.860241890 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:09.880110979 CEST192.168.2.58.8.8.80x2Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.898241043 CEST192.168.2.58.8.8.80x3Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:09.918087959 CEST192.168.2.58.8.8.80x4Standard query (0)gandcrab.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.936181068 CEST192.168.2.58.8.8.80x5Standard query (0)gandcrab.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:10.134829044 CEST192.168.2.58.8.8.80x31f5Standard query (0)dns1.soprodns.ruA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.686275959 CEST192.168.2.58.8.8.80x1Standard query (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:10.704503059 CEST192.168.2.58.8.8.80x2Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.725130081 CEST192.168.2.58.8.8.80x3Standard query (0)nomoreransom.bit28IN (0x0001)
                                            Sep 1, 2022 00:04:10.743391037 CEST192.168.2.58.8.8.80x4Standard query (0)nomoreransom.bitA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.763288975 CEST192.168.2.58.8.8.80x5Standard query (0)nomoreransom.bit28IN (0x0001)
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                            Sep 1, 2022 00:02:01.334580898 CEST8.8.8.8192.168.2.50xe0a0Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.372085094 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:01.393094063 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.412072897 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:01.432477951 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:01.453190088 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:03.608334064 CEST8.8.8.8192.168.2.50xdfb2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.633827925 CEST8.8.8.8192.168.2.50xdfb2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.653230906 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:03.672249079 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.692581892 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:03.712928057 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:03.733714104 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:04.834590912 CEST8.8.8.8192.168.2.50x3cd5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:04.876791954 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:04.898612976 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:04.920192003 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:04.941993952 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:04.961915970 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:06.042258024 CEST8.8.8.8192.168.2.50x27fdName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:06.078336954 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:06.101386070 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:06.131583929 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:06.151202917 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:06.173470020 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:12.567970991 CEST8.8.8.8192.168.2.50x5f2aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.610974073 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:12.632694960 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.665808916 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:12.684042931 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:12.704040051 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:14.775738955 CEST8.8.8.8192.168.2.50xe32fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.811539888 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:14.832356930 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.853168011 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:14.873765945 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:14.894181013 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:15.249150038 CEST8.8.8.8192.168.2.50xe32fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.027390957 CEST8.8.8.8192.168.2.50x5f2aServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.471765041 CEST8.8.8.8192.168.2.50x2c2fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.512093067 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:16.554326057 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.580204964 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:16.603900909 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:16.625678062 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:18.866029978 CEST8.8.8.8192.168.2.50xb4aeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:18.930771112 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:18.950180054 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:18.971628904 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:18.997745991 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:19.028003931 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:20.281924009 CEST8.8.8.8192.168.2.50x65f7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:20.360511065 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:20.379569054 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:20.398627043 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:20.419385910 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:20.438457966 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:21.547008991 CEST8.8.8.8192.168.2.50x17a5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:21.589804888 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:21.612307072 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:21.631066084 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:21.651690006 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:21.670263052 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:23.073178053 CEST8.8.8.8192.168.2.50xf0fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:23.108946085 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:23.139523029 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:23.164510012 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:23.185849905 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:23.208182096 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:25.395417929 CEST8.8.8.8192.168.2.50x1940Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.436459064 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:25.469156981 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.489044905 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:25.508452892 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:25.530004978 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:28.241271019 CEST8.8.8.8192.168.2.50x1940Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.166659117 CEST8.8.8.8192.168.2.50x1450Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.209889889 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:31.231199026 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.249490976 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:31.269680977 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:31.300205946 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:32.866913080 CEST8.8.8.8192.168.2.50x6c66Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:32.905796051 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:32.933625937 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:32.955260038 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:32.979974985 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:33.001955032 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:34.717264891 CEST8.8.8.8192.168.2.50xda28Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:34.764400959 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:34.793865919 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:34.816371918 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:34.839456081 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:34.859596014 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:38.451112986 CEST8.8.8.8192.168.2.50xfb8dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.489614010 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:38.510234118 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.529823065 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:38.544522047 CEST8.8.8.8192.168.2.50xfb8dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.549093008 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:38.569746971 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:39.005251884 CEST8.8.8.8192.168.2.50xfb8dName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.580847025 CEST8.8.8.8192.168.2.50x374eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.625894070 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:39.645344973 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.665539026 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:39.686157942 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:39.718056917 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:41.948688984 CEST8.8.8.8192.168.2.50xbde8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:41.993784904 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:42.015419006 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:42.035979033 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:42.054507971 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:42.075145006 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:46.031758070 CEST8.8.8.8192.168.2.50x6fbdName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:46.408472061 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:46.428978920 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:46.506362915 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:46.529474020 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:46.550900936 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:46.627775908 CEST8.8.8.8192.168.2.50x6fbdName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:47.232079029 CEST8.8.8.8192.168.2.50x6fbdName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.431725979 CEST8.8.8.8192.168.2.50xafd1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.481153965 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:50.502183914 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.522468090 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:50.545125961 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:50.565229893 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:53.012386084 CEST8.8.8.8192.168.2.50xbfd8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:53.051094055 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:53.081031084 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:53.105006933 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:53.129003048 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:53.152440071 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:55.143107891 CEST8.8.8.8192.168.2.50xbfeeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.190500021 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:55.211363077 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.230350971 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:55.249286890 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:55.269426107 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:55.303771973 CEST8.8.8.8192.168.2.50xbfeeName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:56.963818073 CEST8.8.8.8192.168.2.50xbfd8Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.006582975 CEST8.8.8.8192.168.2.50xa3e5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.050683022 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:02:58.055273056 CEST8.8.8.8192.168.2.50xa3e5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.071692944 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.092132092 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:02:58.112858057 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:02:58.137913942 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:02.673258066 CEST8.8.8.8192.168.2.50x8bd5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:02.728626013 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:02.749336004 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:02.772249937 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:02.794682980 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:02.818588018 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:03.269387960 CEST8.8.8.8192.168.2.50x8bd5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:04.564574957 CEST8.8.8.8192.168.2.50x8bd5Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.140230894 CEST8.8.8.8192.168.2.50xdae1Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.186117887 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:05.209920883 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.252963066 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:05.340817928 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:05.533775091 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:09.094862938 CEST8.8.8.8192.168.2.50xdae1Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:10.970557928 CEST8.8.8.8192.168.2.50x82a2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:11.013236046 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:11.036653042 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:11.057737112 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:11.077819109 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:11.099826097 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:13.112035036 CEST8.8.8.8192.168.2.50x4482Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:13.151115894 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:13.173320055 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:13.196038961 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:13.224518061 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:13.246552944 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:15.436304092 CEST8.8.8.8192.168.2.50xe274Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:15.474445105 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:15.496115923 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:15.516382933 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:15.536484003 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:15.554661036 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:18.395138979 CEST8.8.8.8192.168.2.50x55e4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.445703030 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:18.466348886 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.488691092 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:18.510843992 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:18.533323050 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:19.943706036 CEST8.8.8.8192.168.2.50x55e4Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.117666960 CEST8.8.8.8192.168.2.50x8b47Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.145231009 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:21.167120934 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.187253952 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:21.209659100 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:21.230139017 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:21.243673086 CEST8.8.8.8192.168.2.50x8b47Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:22.152108908 CEST8.8.8.8192.168.2.50x8b47Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.089651108 CEST8.8.8.8192.168.2.50x560fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.118304968 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:23.144418001 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.165380955 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:23.188942909 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:23.213639021 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:27.609777927 CEST8.8.8.8192.168.2.50x82c5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.668226004 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:27.688935995 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.709584951 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:27.729931116 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:27.748384953 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:27.819541931 CEST8.8.8.8192.168.2.50x82c5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.075316906 CEST8.8.8.8192.168.2.50x560fServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.274440050 CEST8.8.8.8192.168.2.50xf281Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.310379982 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:28.330352068 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.348592997 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:28.368571997 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.388623953 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:28.819798946 CEST8.8.8.8192.168.2.50xdac3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.849626064 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:28.871601105 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.891577005 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:28.915539980 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:28.937171936 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:29.466361046 CEST8.8.8.8192.168.2.50x163aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:29.496511936 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:29.516742945 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:29.542265892 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:29.564232111 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:29.586312056 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:30.487483025 CEST8.8.8.8192.168.2.50xadc5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:30.516846895 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:30.536672115 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:30.559077978 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:30.580718040 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:30.603596926 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:32.197714090 CEST8.8.8.8192.168.2.50xe338Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.226025105 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:32.247734070 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.259257078 CEST8.8.8.8192.168.2.50xe338Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.267229080 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:32.288376093 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.309899092 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:32.809542894 CEST8.8.8.8192.168.2.50xa108Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.847543955 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:32.872570038 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.894160032 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:32.918351889 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:32.940099001 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:33.313813925 CEST8.8.8.8192.168.2.50xe874Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.340472937 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:33.362754107 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.382714987 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:33.400686026 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.420860052 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:33.947339058 CEST8.8.8.8192.168.2.50xca6eName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:33.976629972 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:33.997020960 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.017164946 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:34.037424088 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.055460930 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:34.579391003 CEST8.8.8.8192.168.2.50x3d5aName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.606172085 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:34.626548052 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.645029068 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:34.670808077 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:34.691076040 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:35.637387991 CEST8.8.8.8192.168.2.50xa2a9Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:35.667938948 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:35.688895941 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:35.711240053 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:35.732723951 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:35.755530119 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:36.375839949 CEST8.8.8.8192.168.2.50xd67bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:36.402359009 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:36.424987078 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:36.445525885 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:36.467850924 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:36.489662886 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:37.983706951 CEST8.8.8.8192.168.2.50xba9fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:38.011287928 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:38.032377958 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:38.052937031 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:38.072388887 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:38.090707064 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:38.996529102 CEST8.8.8.8192.168.2.50x5fe7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.071681023 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:39.091151953 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.110236883 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:39.132061005 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.151518106 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:39.482498884 CEST8.8.8.8192.168.2.50xba9fName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.615535975 CEST8.8.8.8192.168.2.50x82c2Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.646815062 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:39.666840076 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.691112995 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:39.711394072 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:39.733046055 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:40.144674063 CEST8.8.8.8192.168.2.50x2edfName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:40.176877022 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:40.198590040 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:40.217324018 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:40.235502958 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:40.253726959 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:42.581233025 CEST8.8.8.8192.168.2.50x8ccName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:42.695910931 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:42.717495918 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:42.736381054 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:42.756829023 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:42.774645090 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:43.834578991 CEST8.8.8.8192.168.2.50x2679Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:43.862184048 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:43.881683111 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:43.903206110 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:43.924917936 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:43.945391893 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:44.472067118 CEST8.8.8.8192.168.2.50x4cffName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:44.500081062 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:44.526537895 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:44.546730042 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:44.567960024 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:44.588005066 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:45.831124067 CEST8.8.8.8192.168.2.50x8ccServer failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.038166046 CEST8.8.8.8192.168.2.50x6ec8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.067724943 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:47.089193106 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.111303091 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:47.130348921 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:47.152026892 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:47.509731054 CEST8.8.8.8192.168.2.50x6ec8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.198370934 CEST8.8.8.8192.168.2.50x8128Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.237399101 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:48.258917093 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.283209085 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:48.304694891 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:48.325745106 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:49.241806030 CEST8.8.8.8192.168.2.50x6ec8Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.281771898 CEST8.8.8.8192.168.2.50xab90Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.307605028 CEST8.8.8.8192.168.2.50xab90Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.317943096 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:50.338493109 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.358608961 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:50.388493061 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:50.416033030 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:52.316684961 CEST8.8.8.8192.168.2.50x7c25Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:52.345062017 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:52.370079041 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:52.388272047 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:52.412725925 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:52.435429096 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:53.933697939 CEST8.8.8.8192.168.2.50x5962Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:53.962321997 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:53.984399080 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:54.007458925 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:54.026586056 CEST8.8.8.8192.168.2.50x5962Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:54.035367012 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:54.055593014 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:55.239881992 CEST8.8.8.8192.168.2.50xc5e7Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:55.274434090 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:55.294156075 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:55.313684940 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:55.336025953 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:55.364104986 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:55.794974089 CEST8.8.8.8192.168.2.50x7c25Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.268456936 CEST8.8.8.8192.168.2.50x2f3Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.301691055 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:56.325932980 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.346476078 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:56.365498066 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:56.386655092 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:58.825668097 CEST8.8.8.8192.168.2.50xe61cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:58.855791092 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:03:58.874407053 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:58.893013000 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:59.415303946 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:03:59.437519073 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:03:59.477504015 CEST8.8.8.8192.168.2.50xe61cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.200125933 CEST8.8.8.8192.168.2.50xdb8bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.706511974 CEST8.8.8.8192.168.2.50xe61cName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.922754049 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:00.943747044 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:00.962049007 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:00.982321024 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:01.002304077 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:03.734221935 CEST8.8.8.8192.168.2.50xc850Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.761651039 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:03.782330036 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.802499056 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:03.822778940 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:03.842823982 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:04.048010111 CEST8.8.8.8192.168.2.50x9e81Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.074004889 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:04.094161987 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.114377975 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:04.134500980 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.154583931 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:04.195255041 CEST8.8.8.8192.168.2.50xc850Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.913227081 CEST8.8.8.8192.168.2.50xed4bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.936587095 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:04.955105066 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:04.975845098 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:04.996162891 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.017935991 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:05.764825106 CEST8.8.8.8192.168.2.50xc850Server failure (2)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.773658037 CEST8.8.8.8192.168.2.50x647bName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.801095963 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:05.840457916 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.861089945 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:05.881166935 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:05.901103973 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:06.630609989 CEST8.8.8.8192.168.2.50xedf0Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:06.656243086 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:06.677496910 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:06.698992968 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:06.718585014 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:06.737366915 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:07.451251030 CEST8.8.8.8192.168.2.50x3852Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:07.475867033 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:07.495662928 CEST8.8.8.8192.168.2.50x2Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:07.513513088 CEST8.8.8.8192.168.2.50x3Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:07.531666040 CEST8.8.8.8192.168.2.50x4Name error (3)emsisoft.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:07.552181005 CEST8.8.8.8192.168.2.50x5Name error (3)emsisoft.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:09.852585077 CEST8.8.8.8192.168.2.50x26baName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.861260891 CEST8.8.8.8192.168.2.50x26baName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.879578114 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:09.897767067 CEST8.8.8.8192.168.2.50x2Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.917709112 CEST8.8.8.8192.168.2.50x3Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:09.935751915 CEST8.8.8.8192.168.2.50x4Name error (3)gandcrab.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:09.956202984 CEST8.8.8.8192.168.2.50x5Name error (3)gandcrab.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:10.284883022 CEST8.8.8.8192.168.2.50x26baName error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.678015947 CEST8.8.8.8192.168.2.50x31f5Name error (3)dns1.soprodns.runonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.703870058 CEST8.8.8.8192.168.2.50x1No error (0)8.8.8.8.in-addr.arpaPTR (Pointer record)IN (0x0001)
                                            Sep 1, 2022 00:04:10.724714041 CEST8.8.8.8192.168.2.50x2Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.742995024 CEST8.8.8.8192.168.2.50x3Name error (3)nomoreransom.bitnonenone28IN (0x0001)
                                            Sep 1, 2022 00:04:10.762958050 CEST8.8.8.8192.168.2.50x4Name error (3)nomoreransom.bitnonenoneA (IP address)IN (0x0001)
                                            Sep 1, 2022 00:04:10.784327984 CEST8.8.8.8192.168.2.50x5Name error (3)nomoreransom.bitnonenone28IN (0x0001)

                                            Click to jump to process

                                            Target ID:0
                                            Start time:00:01:51
                                            Start date:01/09/2022
                                            Path:C:\Users\user\Desktop\2fiDcmkaZY.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\Desktop\2fiDcmkaZY.exe"
                                            Imagebase:0xa60000
                                            File size:75264 bytes
                                            MD5 hash:A8AC57500DE5DADF8C4DB19959DDF2EC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000000.00000000.304343043.0000000000A69000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000000.00000002.598939067.0000000000A69000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                                            Reputation:low

                                            Target ID:2
                                            Start time:00:01:59
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate

                                            Target ID:3
                                            Start time:00:02:00
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high

                                            Target ID:4
                                            Start time:00:02:00
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate

                                            Target ID:5
                                            Start time:00:02:01
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high

                                            Target ID:6
                                            Start time:00:02:03
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate

                                            Target ID:7
                                            Start time:00:02:03
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high

                                            Target ID:8
                                            Start time:00:02:04
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate

                                            Target ID:9
                                            Start time:00:02:04
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high

                                            Target ID:10
                                            Start time:00:02:06
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:moderate

                                            Target ID:11
                                            Start time:00:02:07
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:13
                                            Start time:00:02:09
                                            Start date:01/09/2022
                                            Path:C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe"
                                            Imagebase:0xc70000
                                            File size:75264 bytes
                                            MD5 hash:D2E112FDFFC314778285E837BC0BED47
                                            Has elevated privileges:false
                                            Has administrator privileges:false
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000D.00000000.343462206.0000000000C79000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 0000000D.00000002.346586335.0000000000C79000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                                            • Rule: SUSP_RANSOMWARE_Indicator_Jul20, Description: Detects ransomware indicator, Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, Author: Florian Roth
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, Author: Joe Security
                                            • Rule: Gandcrab, Description: Gandcrab Payload, Source: C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe, Author: kevoreilly
                                            Antivirus matches:
                                            • Detection: 100%, Avira
                                            • Detection: 100%, Joe Sandbox ML

                                            Target ID:14
                                            Start time:00:02:12
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:15
                                            Start time:00:02:12
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:16
                                            Start time:00:02:14
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:17
                                            Start time:00:02:14
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:18
                                            Start time:00:02:16
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:19
                                            Start time:00:02:16
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:20
                                            Start time:00:02:17
                                            Start date:01/09/2022
                                            Path:C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\AppData\Roaming\Microsoft\tdicrr.exe"
                                            Imagebase:0xc70000
                                            File size:75264 bytes
                                            MD5 hash:D2E112FDFFC314778285E837BC0BED47
                                            Has elevated privileges:false
                                            Has administrator privileges:false
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000014.00000002.363374033.0000000000C79000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Gandcrab, Description: Yara detected Gandcrab, Source: 00000014.00000000.360474661.0000000000C79000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security

                                            Target ID:21
                                            Start time:00:02:18
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:22
                                            Start time:00:02:18
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:23
                                            Start time:00:02:19
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:24
                                            Start time:00:02:20
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:26
                                            Start time:00:02:21
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:27
                                            Start time:00:02:21
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:28
                                            Start time:00:02:22
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:29
                                            Start time:00:02:23
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:31
                                            Start time:00:02:25
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:32
                                            Start time:00:02:27
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:33
                                            Start time:00:02:30
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:34
                                            Start time:00:02:31
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:35
                                            Start time:00:02:32
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:36
                                            Start time:00:02:32
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:37
                                            Start time:00:02:34
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:38
                                            Start time:00:02:34
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:39
                                            Start time:00:02:37
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:40
                                            Start time:00:02:38
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:41
                                            Start time:00:02:39
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:42
                                            Start time:00:02:39
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:43
                                            Start time:00:02:41
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:45
                                            Start time:00:02:41
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:49
                                            Start time:00:02:45
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:50
                                            Start time:00:02:48
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:51
                                            Start time:00:02:49
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:52
                                            Start time:00:02:50
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:53
                                            Start time:00:02:52
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:54
                                            Start time:00:02:52
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:55
                                            Start time:00:02:54
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:56
                                            Start time:00:02:55
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:58
                                            Start time:00:02:57
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:59
                                            Start time:00:02:57
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:60
                                            Start time:00:03:02
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:61
                                            Start time:00:03:02
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:62
                                            Start time:00:03:05
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:63
                                            Start time:00:03:08
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:64
                                            Start time:00:03:10
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup gandcrab.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:65
                                            Start time:00:03:11
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:66
                                            Start time:00:03:12
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup nomoreransom.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:67
                                            Start time:00:03:13
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:68
                                            Start time:00:03:15
                                            Start date:01/09/2022
                                            Path:C:\Windows\SysWOW64\nslookup.exe
                                            Wow64 process (32bit):true
                                            Commandline:nslookup emsisoft.bit dns1.soprodns.ru
                                            Imagebase:0xcd0000
                                            File size:78336 bytes
                                            MD5 hash:8E82529D1475D67615ADCB4E1B8F4EEC
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            Target ID:69
                                            Start time:00:03:15
                                            Start date:01/09/2022
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7fcd70000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language

                                            No disassembly