paladin316

Exes_2dd02ccf7a6df802b1324389ea4906e5_exe_2019-07-25_07_30.txt

Jul 25th, 2019
2,143
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 38.14 KB | None | 0 0
  1.  
  2. * MalFamily: "sysxfwr"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_2dd02ccf7a6df802b1324389ea4906e5.exe"
  7. * File Size: 327680
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "d29deb9d361f4cae9aed1fd87448ed683cc3418defa20bc84946581bb02ef309"
  10. * MD5: "2dd02ccf7a6df802b1324389ea4906e5"
  11. * SHA1: "3a0c5200f2141fabde18ee56b5a86b23fd5399a9"
  12. * SHA512: "295b56536cf8aef5d1025c79886d17b1bdbb4211acb26acaa919921f68ee5ab4abfe228ba97f98186df09f02083c41ea306b56b06f4e85d292627962ec254a26"
  13. * CRC32: "F0136211"
  14. * SSDEEP: "6144:g4KsCYthSgTwEXat/el4l00CTR4HjvmwOM1:g4tCYHqEXY/e3VQx1"
  15.  
  16. * Process Execution:
  17. "Exes_2dd02ccf7a6df802b1324389ea4906e5.exe",
  18. "sysxfwr.exe",
  19. "10665.exe",
  20. "22593.exe",
  21. "10145.exe",
  22. "27113.exe",
  23. "21492.exe",
  24. "39779.exe"
  25.  
  26.  
  27. * Executed Commands:
  28. "C:\\Windows\\54854690\\sysxfwr.exe",
  29. "C:\\Users\\user\\AppData\\Local\\Temp\\10665.exe",
  30. "C:\\Users\\user\\AppData\\Local\\Temp\\29992.exe",
  31. "C:\\Users\\user\\AppData\\Local\\Temp\\22593.exe",
  32. "C:\\Users\\user\\AppData\\Local\\Temp\\10145.exe",
  33. "C:\\Users\\user\\AppData\\Local\\Temp\\27113.exe",
  34. "C:\\Users\\user\\AppData\\Local\\Temp\\21492.exe",
  35. "C:\\Users\\user\\AppData\\Local\\Temp\\39779.exe"
  36.  
  37.  
  38. * Signatures Detected:
  39.  
  40. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  41. "Details":
  42.  
  43. "IP": "67.195.228.110:25"
  44.  
  45.  
  46.  
  47.  
  48. "Description": "Creates RWX memory",
  49. "Details":
  50.  
  51.  
  52. "Description": "Possible date expiration check, exits too soon after checking local time",
  53. "Details":
  54.  
  55. "process": "22593.exe, PID 1288"
  56.  
  57.  
  58.  
  59.  
  60. "Description": "A process attempted to delay the analysis task.",
  61. "Details":
  62.  
  63. "Process": "sysxfwr.exe tried to sleep 553 seconds, actually delayed analysis time by 0 seconds"
  64.  
  65.  
  66.  
  67.  
  68. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  69. "Details":
  70.  
  71.  
  72. "Description": "File has been identified by 4 Antiviruses on VirusTotal as malicious",
  73. "Details":
  74.  
  75. "FireEye": "Generic.mg.2dd02ccf7a6df802"
  76.  
  77.  
  78. "Trapmine": "suspicious.low.ml.score"
  79.  
  80.  
  81. "Cylance": "Unsafe"
  82.  
  83.  
  84. "SentinelOne": "DFI - Malicious PE"
  85.  
  86.  
  87.  
  88.  
  89. "Description": "Drops a binary and executes it",
  90. "Details":
  91.  
  92. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\10145.exe"
  93.  
  94.  
  95. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\39779.exe"
  96.  
  97.  
  98. "binary": "C:\\Windows\\54854690\\sysxfwr.exe"
  99.  
  100.  
  101. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\22593.exe"
  102.  
  103.  
  104. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\27113.exe"
  105.  
  106.  
  107. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\21492.exe"
  108.  
  109.  
  110. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\10665.exe"
  111.  
  112.  
  113.  
  114.  
  115. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  116. "Details":
  117.  
  118. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  119.  
  120.  
  121. "suspicious_request": "http://193.32.161.73/t.php?new=1"
  122.  
  123.  
  124. "suspicious_request": "http://193.32.161.73/1"
  125.  
  126.  
  127. "suspicious_request": "http://193.32.161.73/2"
  128.  
  129.  
  130. "suspicious_request": "http://193.32.161.73/3"
  131.  
  132.  
  133. "suspicious_request": "http://193.32.161.73/4"
  134.  
  135.  
  136. "suspicious_request": "http://193.32.161.73/5"
  137.  
  138.  
  139. "suspicious_request": "http://193.32.161.73/6"
  140.  
  141.  
  142. "suspicious_request": "http://193.32.161.73/7"
  143.  
  144.  
  145. "suspicious_request": "http://193.32.161.73/8"
  146.  
  147.  
  148.  
  149.  
  150. "Description": "Performs some HTTP requests",
  151. "Details":
  152.  
  153. "url": "http://193.32.161.73/t.php?new=1"
  154.  
  155.  
  156. "url": "http://193.32.161.73/1"
  157.  
  158.  
  159. "url": "http://193.32.161.73/2"
  160.  
  161.  
  162. "url": "http://193.32.161.73/3"
  163.  
  164.  
  165. "url": "http://193.32.161.73/4"
  166.  
  167.  
  168. "url": "http://193.32.161.73/5"
  169.  
  170.  
  171. "url": "http://193.32.161.73/6"
  172.  
  173.  
  174. "url": "http://193.32.161.73/7"
  175.  
  176.  
  177. "url": "http://193.32.161.73/8"
  178.  
  179.  
  180.  
  181.  
  182. "Description": "Detects Sandboxie through the presence of a library",
  183. "Details":
  184.  
  185.  
  186. "Description": "Detects SunBelt Sandbox through the presence of a library",
  187. "Details":
  188.  
  189.  
  190. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  191. "Details":
  192.  
  193. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_2dd02ccf7a6df802b1324389ea4906e5.exe:Zone.Identifier"
  194.  
  195.  
  196.  
  197.  
  198. "Description": "Installs itself for autorun at Windows startup",
  199. "Details":
  200.  
  201. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver"
  202.  
  203.  
  204. "data": "C:\\Windows\\54854690\\sysxfwr.exe"
  205.  
  206.  
  207. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver"
  208.  
  209.  
  210. "data": "C:\\Windows\\54854690\\sysxfwr.exe"
  211.  
  212.  
  213.  
  214.  
  215. "Description": "Creates a hidden or system file",
  216. "Details":
  217.  
  218. "file": "C:\\Windows\\54854690"
  219.  
  220.  
  221. "file": "C:\\Windows\\54854690\\sysxfwr.exe"
  222.  
  223.  
  224. "file": "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt"
  225.  
  226.  
  227. "file": "C:\\Users\\user\\AppData\\Roaming\\8080808.txt"
  228.  
  229.  
  230.  
  231.  
  232. "Description": "Checks for the presence of known devices from debuggers and forensic tools",
  233. "Details":
  234.  
  235.  
  236. "Description": "Operates on local firewall's policies and settings",
  237. "Details":
  238.  
  239.  
  240. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  241. "Details":
  242.  
  243.  
  244.  
  245.  
  246.  
  247. "dropped": "clamav:Win.Packed.addsub-6963063-0, sha256:2614bbb7dceb6c09bf59c2648fcb78db354ac28d94eb790c7a79f0d4bbd6ea20 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\21492.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  248.  
  249.  
  250. "dropped": "clamav:Win.Packed.addsub-6963063-0, sha256:662ff8145cbcda07b8de4f91173735b84f8dbbd6df467e5be40a2ea3966e6709 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\10145.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  251.  
  252.  
  253. "dropped": "clamav:Win.Packed.addsub-6963063-0, sha256:bd4886a0a1a0a8bc16bf62447b780f03524ff6067a0d61435b716c3a8501337b , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\39779.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  254.  
  255.  
  256. "dropped": "clamav:Win.Packed.addsub-6963063-0, sha256:469b1d3e72d78b4d2b92457f2915192fda33f760d694dee0729489a12232a422 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\22593.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  257.  
  258.  
  259. "dropped": "clamav:Win.Packed.addsub-6963063-0, sha256:e8ef0af324cc2ca582c89a27d82fa24eca122af7dde16b65acadfaa62043fff5 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\27113.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  260.  
  261.  
  262.  
  263.  
  264. "Description": "Creates a copy of itself",
  265. "Details":
  266.  
  267. "copy": "C:\\Windows\\54854690\\sysxfwr.exe"
  268.  
  269.  
  270.  
  271.  
  272. "Description": "Attempts to disable System Restore",
  273. "Details":
  274.  
  275.  
  276. "Description": "Attempts to modify or disable Security Center warnings",
  277. "Details":
  278.  
  279.  
  280. "Description": "Likely use of Domain Generation Algorithm (DGA)",
  281. "Details":
  282.  
  283.  
  284. "Description": "Anomalous binary characteristics",
  285. "Details":
  286.  
  287. "anomaly": "Actual checksum does not match that reported in PE header"
  288.  
  289.  
  290.  
  291.  
  292. "Description": "Created network traffic indicative of malicious activity",
  293. "Details":
  294.  
  295. "signature": "ET DNS Query for .su TLD (Soviet Union) Often Malware Related"
  296.  
  297.  
  298.  
  299.  
  300.  
  301. * Started Service:
  302.  
  303. * Mutexes:
  304. "60797040",
  305. "49485699",
  306. "4868468",
  307. "5949400",
  308. "74295060"
  309.  
  310.  
  311. * Modified Files:
  312. "C:\\Windows\\54854690\\sysxfwr.exe",
  313. "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt",
  314. "C:\\Users\\user\\AppData\\Local\\Temp\\10665.exe",
  315. "C:\\Users\\user\\AppData\\Local\\Temp\\29992.exe",
  316. "C:\\Users\\user\\AppData\\Local\\Temp\\22593.exe",
  317. "C:\\Users\\user\\AppData\\Local\\Temp\\10145.exe",
  318. "C:\\Users\\user\\AppData\\Local\\Temp\\27113.exe",
  319. "C:\\Users\\user\\AppData\\Local\\Temp\\21492.exe",
  320. "C:\\Users\\user\\AppData\\Local\\Temp\\39779.exe",
  321. "C:\\Users\\user\\AppData\\Roaming\\8080808.txt",
  322. "C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\ose.exe",
  323. "C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\setup.exe",
  324. "C:\\Program Files\\Internet Explorer\\en-US\\ieinstal.exe.mui",
  325. "C:\\Program Files\\Internet Explorer\\en-US\\ielowutil.exe.mui",
  326. "C:\\Program Files\\Internet Explorer\\en-US\\iexplore.exe.mui",
  327. "C:\\Program Files\\Internet Explorer\\ieinstal.exe",
  328. "C:\\Program Files\\Internet Explorer\\ielowutil.exe",
  329. "C:\\Program Files\\Internet Explorer\\iexplore.exe",
  330. "C:\\Program Files\\Notepad++\\notepad++.exe",
  331. "C:\\Program Files\\Notepad++\\uninstall.exe",
  332. "C:\\Program Files\\Notepad++\\updater\\GUP.exe",
  333. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\acrobroker.exe",
  334. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe",
  335. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroLayoutRecognizer\\acrolayoutrecognizer.exe",
  336. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe",
  337. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\acrord32info.exe",
  338. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\acrotextextractor.exe",
  339. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\ADelRCP.exe",
  340. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\adobecollabsync.exe",
  341. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\arh.exe",
  342. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\wcchromenativemessaginghost.exe",
  343. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe",
  344. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\fulltrustnotifier.exe",
  345. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\logtransport2.exe",
  346. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\32bitmapibroker.exe",
  347. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\64bitmapibroker.exe",
  348. "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe",
  349. "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\adobearmhelper.exe",
  350. "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe",
  351. "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jaureg.exe",
  352. "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe",
  353. "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe",
  354. "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath_target_9168828\\java.exe",
  355. "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath_target_9168828\\javaw.exe",
  356. "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath_target_9168828\\javaws.exe",
  357. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\chrome.exe.sig",
  358. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\chrmstp.exe",
  359. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\setup.exe",
  360. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
  361. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome_proxy.exe",
  362. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googlecrashhandler.exe",
  363. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googlecrashhandler64.exe",
  364. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googledisabledupdatebroker.exe",
  365. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googledisabledupdatecomregistershell64.exe",
  366. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googledisabledupdatecore.exe",
  367. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googledisabledupdateondemand.exe",
  368. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googledisabledupdatesetup.exe",
  369. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\googledisabledupdatewebplugin.exe",
  370. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\google_disabledupdate.exe",
  371. "C:\\Program Files (x86)\\Google\\Update\\Download\\430FD4D0-B729-4F61-AA34-91526481799D\\1.3.34.11\\googleupdatesetup.exe",
  372. "C:\\Program Files (x86)\\Google\\Update\\Download\\8A69D345-D564-463C-AFF1-A69D9E530F96\\74.0.3729.169\\74.0.3729.169_73.0.3683.86_chrome_updater.exe",
  373. "C:\\Program Files (x86)\\Google\\Update\\google_disabled_update.exe",
  374. "C:\\Program Files (x86)\\Google\\Update\\Install\\A01675F1-1F84-4945-B8A9-4E1FDEB013B2\\74.0.3729.169_73.0.3683.86_chrome_updater.exe",
  375. "C:\\Program Files (x86)\\Internet Explorer\\en-US\\ieinstal.exe.mui",
  376. "C:\\Program Files (x86)\\Internet Explorer\\en-US\\ielowutil.exe.mui",
  377. "C:\\Program Files (x86)\\Internet Explorer\\en-US\\iexplore.exe.mui",
  378. "C:\\Program Files (x86)\\Internet Explorer\\extexport.exe",
  379. "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe",
  380. "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe",
  381. "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
  382. "C:\\ProgramData\\Adobe\\Setup\\AC76BA86-7AD7-1033-7B44-AC0F074E4100\\setup.exe",
  383. "C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\googleupdatesetup.exe",
  384. "C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\manifests\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab.cdf-ms",
  385. "C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\manifests\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab.manifest",
  386. "C:\\Users\\user\\AppData\\Local\\Package Cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe",
  387. "C:\\Users\\user\\AppData\\Local\\Temp\\exes_2dd02ccf7a6df802b1324389ea4906e5.exe",
  388. "C:\\Users\\user\\AppData\\Local\\Temp\\ose00000.exe",
  389. "C:\\Users\\user\\AppData\\Local\\Temp\\E9E68605-DE3F-4B4C-871B-FEB06DC5D167\\installplugin_29_0_0_171.exe",
  390. "C:\\Users\\user\\devmanview.exe",
  391. "C:\\Users\\user\\Volumeid.exe"
  392.  
  393.  
  394. * Deleted Files:
  395. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_2dd02ccf7a6df802b1324389ea4906e5.exe:Zone.Identifier",
  396. "C:\\Windows\\54854690\\sysxfwr.exe:Zone.Identifier",
  397. "C:\\Users\\user\\AppData\\Local\\Temp\\10665.exe:Zone.Identifier",
  398. "C:\\Users\\user\\AppData\\Local\\Temp\\29992.exe:Zone.Identifier",
  399. "C:\\Users\\user\\AppData\\Local\\Temp\\22593.exe:Zone.Identifier",
  400. "C:\\Users\\user\\AppData\\Local\\Temp\\10145.exe:Zone.Identifier",
  401. "C:\\Users\\user\\AppData\\Local\\Temp\\27113.exe:Zone.Identifier",
  402. "C:\\Users\\user\\AppData\\Local\\Temp\\21492.exe:Zone.Identifier",
  403. "C:\\Users\\user\\AppData\\Local\\Temp\\39779.exe:Zone.Identifier"
  404.  
  405.  
  406. * Modified Registry Keys:
  407. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver",
  408. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver",
  409. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusOverride",
  410. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesOverride",
  411. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallOverride",
  412. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusDisableNotify",
  413. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesDisableNotify",
  414. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AutoUpdateDisableNotify",
  415. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallDisableNotify",
  416. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR"
  417.  
  418.  
  419. * Deleted Registry Keys:
  420.  
  421. * DNS Communications:
  422.  
  423. "type": "A",
  424. "request": "gosurrhrguhr.cc",
  425. "answers":
  426.  
  427. "data": "",
  428. "type": "NXDOMAIN"
  429.  
  430.  
  431.  
  432.  
  433. "type": "A",
  434. "request": "goheufuhufdr.cc",
  435. "answers":
  436.  
  437. "data": "",
  438. "type": "NXDOMAIN"
  439.  
  440.  
  441.  
  442.  
  443. "type": "A",
  444. "request": "olruheuuruur.cc",
  445. "answers":
  446.  
  447. "data": "",
  448. "type": "NXDOMAIN"
  449.  
  450.  
  451.  
  452.  
  453. "type": "A",
  454. "request": "buaeabguguur.cc",
  455. "answers":
  456.  
  457. "data": "",
  458. "type": "NXDOMAIN"
  459.  
  460.  
  461.  
  462.  
  463. "type": "A",
  464. "request": "ebgiaueghuur.cc",
  465. "answers":
  466.  
  467. "data": "",
  468. "type": "NXDOMAIN"
  469.  
  470.  
  471.  
  472.  
  473. "type": "A",
  474. "request": "bfbaiefiheir.cc",
  475. "answers":
  476.  
  477. "data": "",
  478. "type": "NXDOMAIN"
  479.  
  480.  
  481.  
  482.  
  483. "type": "A",
  484. "request": "eeeieiieirdr.cc",
  485. "answers":
  486.  
  487. "data": "",
  488. "type": "NXDOMAIN"
  489.  
  490.  
  491.  
  492.  
  493. "type": "A",
  494. "request": "abfeiagihisr.cc",
  495. "answers":
  496.  
  497. "data": "",
  498. "type": "NXDOMAIN"
  499.  
  500.  
  501.  
  502.  
  503. "type": "A",
  504. "request": "nkoaefuhfuhr.cc",
  505. "answers":
  506.  
  507. "data": "",
  508. "type": "NXDOMAIN"
  509.  
  510.  
  511.  
  512.  
  513. "type": "A",
  514. "request": "ezaziiezfzgr.cc",
  515. "answers":
  516.  
  517. "data": "",
  518. "type": "NXDOMAIN"
  519.  
  520.  
  521.  
  522.  
  523. "type": "A",
  524. "request": "egaueuefuhgr.cc",
  525. "answers":
  526.  
  527. "data": "",
  528. "type": "NXDOMAIN"
  529.  
  530.  
  531.  
  532.  
  533. "type": "A",
  534. "request": "aoufauhuefur.cc",
  535. "answers":
  536.  
  537. "data": "",
  538. "type": "NXDOMAIN"
  539.  
  540.  
  541.  
  542.  
  543. "type": "A",
  544. "request": "aieiiieitter.cc",
  545. "answers":
  546.  
  547. "data": "",
  548. "type": "NXDOMAIN"
  549.  
  550.  
  551.  
  552.  
  553. "type": "A",
  554. "request": "miokpkaeofkr.cc",
  555. "answers":
  556.  
  557. "data": "",
  558. "type": "NXDOMAIN"
  559.  
  560.  
  561.  
  562.  
  563. "type": "A",
  564. "request": "rzauerzueutr.cc",
  565. "answers":
  566.  
  567. "data": "",
  568. "type": "NXDOMAIN"
  569.  
  570.  
  571.  
  572.  
  573. "type": "A",
  574. "request": "gosurrhrguho.co",
  575. "answers":
  576.  
  577. "data": "",
  578. "type": "NXDOMAIN"
  579.  
  580.  
  581.  
  582.  
  583. "type": "A",
  584. "request": "goheufuhufdo.co",
  585. "answers":
  586.  
  587. "data": "",
  588. "type": "NXDOMAIN"
  589.  
  590.  
  591.  
  592.  
  593. "type": "A",
  594. "request": "olruheuuruuo.co",
  595. "answers":
  596.  
  597. "data": "",
  598. "type": "NXDOMAIN"
  599.  
  600.  
  601.  
  602.  
  603. "type": "A",
  604. "request": "buaeabguguuo.co",
  605. "answers":
  606.  
  607. "data": "",
  608. "type": "NXDOMAIN"
  609.  
  610.  
  611.  
  612.  
  613. "type": "A",
  614. "request": "ebgiaueghuuo.co",
  615. "answers":
  616.  
  617. "data": "",
  618. "type": "NXDOMAIN"
  619.  
  620.  
  621.  
  622.  
  623. "type": "A",
  624. "request": "bfbaiefiheio.co",
  625. "answers":
  626.  
  627. "data": "",
  628. "type": "NXDOMAIN"
  629.  
  630.  
  631.  
  632.  
  633. "type": "A",
  634. "request": "eeeieiieirdo.co",
  635. "answers":
  636.  
  637. "data": "",
  638. "type": "NXDOMAIN"
  639.  
  640.  
  641.  
  642.  
  643. "type": "A",
  644. "request": "abfeiagihiso.co",
  645. "answers":
  646.  
  647. "data": "",
  648. "type": "NXDOMAIN"
  649.  
  650.  
  651.  
  652.  
  653. "type": "A",
  654. "request": "nkoaefuhfuho.co",
  655. "answers":
  656.  
  657. "data": "",
  658. "type": "NXDOMAIN"
  659.  
  660.  
  661.  
  662.  
  663. "type": "A",
  664. "request": "ezaziiezfzgo.co",
  665. "answers":
  666.  
  667. "data": "",
  668. "type": "NXDOMAIN"
  669.  
  670.  
  671.  
  672.  
  673. "type": "A",
  674. "request": "egaueuefuhgo.co",
  675. "answers":
  676.  
  677. "data": "",
  678. "type": "NXDOMAIN"
  679.  
  680.  
  681.  
  682.  
  683. "type": "A",
  684. "request": "aoufauhuefuo.co",
  685. "answers":
  686.  
  687. "data": "",
  688. "type": "NXDOMAIN"
  689.  
  690.  
  691.  
  692.  
  693. "type": "A",
  694. "request": "aieiiieitteo.co",
  695. "answers":
  696.  
  697. "data": "",
  698. "type": "NXDOMAIN"
  699.  
  700.  
  701.  
  702.  
  703. "type": "A",
  704. "request": "miokpkaeofko.co",
  705. "answers":
  706.  
  707. "data": "",
  708. "type": "NXDOMAIN"
  709.  
  710.  
  711.  
  712.  
  713. "type": "A",
  714. "request": "rzauerzueuto.co",
  715. "answers":
  716.  
  717. "data": "",
  718. "type": "NXDOMAIN"
  719.  
  720.  
  721.  
  722.  
  723. "type": "A",
  724. "request": "gosurrhrguhp.io",
  725. "answers":
  726.  
  727. "data": "",
  728. "type": "NXDOMAIN"
  729.  
  730.  
  731.  
  732.  
  733. "type": "A",
  734. "request": "goheufuhufdp.io",
  735. "answers":
  736.  
  737. "data": "",
  738. "type": "NXDOMAIN"
  739.  
  740.  
  741.  
  742.  
  743. "type": "A",
  744. "request": "olruheuuruup.io",
  745. "answers":
  746.  
  747. "data": "",
  748. "type": "NXDOMAIN"
  749.  
  750.  
  751.  
  752.  
  753. "type": "A",
  754. "request": "buaeabguguup.io",
  755. "answers":
  756.  
  757. "data": "",
  758. "type": "NXDOMAIN"
  759.  
  760.  
  761.  
  762.  
  763. "type": "A",
  764. "request": "ebgiaueghuup.io",
  765. "answers":
  766.  
  767. "data": "",
  768. "type": "NXDOMAIN"
  769.  
  770.  
  771.  
  772.  
  773. "type": "A",
  774. "request": "bfbaiefiheip.io",
  775. "answers":
  776.  
  777. "data": "",
  778. "type": "NXDOMAIN"
  779.  
  780.  
  781.  
  782.  
  783. "type": "A",
  784. "request": "eeeieiieirdp.io",
  785. "answers":
  786.  
  787. "data": "",
  788. "type": "NXDOMAIN"
  789.  
  790.  
  791.  
  792.  
  793. "type": "A",
  794. "request": "abfeiagihisp.io",
  795. "answers":
  796.  
  797. "data": "",
  798. "type": "NXDOMAIN"
  799.  
  800.  
  801.  
  802.  
  803. "type": "A",
  804. "request": "nkoaefuhfuhp.io",
  805. "answers":
  806.  
  807. "data": "",
  808. "type": "NXDOMAIN"
  809.  
  810.  
  811.  
  812.  
  813. "type": "A",
  814. "request": "ezaziiezfzgp.io",
  815. "answers":
  816.  
  817. "data": "",
  818. "type": "NXDOMAIN"
  819.  
  820.  
  821.  
  822.  
  823. "type": "A",
  824. "request": "egaueuefuhgp.io",
  825. "answers":
  826.  
  827. "data": "",
  828. "type": "NXDOMAIN"
  829.  
  830.  
  831.  
  832.  
  833. "type": "A",
  834. "request": "aoufauhuefup.io",
  835. "answers":
  836.  
  837. "data": "",
  838. "type": "NXDOMAIN"
  839.  
  840.  
  841.  
  842.  
  843. "type": "A",
  844. "request": "aieiiieittep.io",
  845. "answers":
  846.  
  847. "data": "",
  848. "type": "NXDOMAIN"
  849.  
  850.  
  851.  
  852.  
  853. "type": "A",
  854. "request": "miokpkaeofkp.io",
  855. "answers":
  856.  
  857. "data": "",
  858. "type": "NXDOMAIN"
  859.  
  860.  
  861.  
  862.  
  863. "type": "A",
  864. "request": "rzauerzueutp.io",
  865. "answers":
  866.  
  867. "data": "",
  868. "type": "NXDOMAIN"
  869.  
  870.  
  871.  
  872.  
  873. "type": "A",
  874. "request": "gosurrhrguhl.su",
  875. "answers":
  876.  
  877. "data": "",
  878. "type": "NXDOMAIN"
  879.  
  880.  
  881.  
  882.  
  883. "type": "A",
  884. "request": "goheufuhufdl.su",
  885. "answers":
  886.  
  887. "data": "",
  888. "type": "NXDOMAIN"
  889.  
  890.  
  891.  
  892.  
  893. "type": "A",
  894. "request": "olruheuuruul.su",
  895. "answers":
  896.  
  897. "data": "",
  898. "type": "NXDOMAIN"
  899.  
  900.  
  901.  
  902.  
  903. "type": "A",
  904. "request": "buaeabguguul.su",
  905. "answers":
  906.  
  907. "data": "",
  908. "type": "NXDOMAIN"
  909.  
  910.  
  911.  
  912.  
  913. "type": "A",
  914. "request": "ebgiaueghuul.su",
  915. "answers":
  916.  
  917. "data": "",
  918. "type": "NXDOMAIN"
  919.  
  920.  
  921.  
  922.  
  923. "type": "A",
  924. "request": "bfbaiefiheil.su",
  925. "answers":
  926.  
  927. "data": "",
  928. "type": "NXDOMAIN"
  929.  
  930.  
  931.  
  932.  
  933. "type": "A",
  934. "request": "eeeieiieirdl.su",
  935. "answers":
  936.  
  937. "data": "",
  938. "type": "NXDOMAIN"
  939.  
  940.  
  941.  
  942.  
  943. "type": "A",
  944. "request": "abfeiagihisl.su",
  945. "answers":
  946.  
  947. "data": "",
  948. "type": "NXDOMAIN"
  949.  
  950.  
  951.  
  952.  
  953. "type": "A",
  954. "request": "nkoaefuhfuhl.su",
  955. "answers":
  956.  
  957. "data": "",
  958. "type": "NXDOMAIN"
  959.  
  960.  
  961.  
  962.  
  963. "type": "A",
  964. "request": "ezaziiezfzgl.su",
  965. "answers":
  966.  
  967. "data": "",
  968. "type": "NXDOMAIN"
  969.  
  970.  
  971.  
  972.  
  973. "type": "A",
  974. "request": "egaueuefuhgl.su",
  975. "answers":
  976.  
  977. "data": "",
  978. "type": "NXDOMAIN"
  979.  
  980.  
  981.  
  982.  
  983. "type": "A",
  984. "request": "aoufauhueful.su",
  985. "answers":
  986.  
  987. "data": "",
  988. "type": "NXDOMAIN"
  989.  
  990.  
  991.  
  992.  
  993. "type": "A",
  994. "request": "aieiiieittel.su",
  995. "answers":
  996.  
  997. "data": "",
  998. "type": "NXDOMAIN"
  999.  
  1000.  
  1001.  
  1002.  
  1003. "type": "A",
  1004. "request": "miokpkaeofkl.su",
  1005. "answers":
  1006.  
  1007. "data": "",
  1008. "type": "NXDOMAIN"
  1009.  
  1010.  
  1011.  
  1012.  
  1013. "type": "A",
  1014. "request": "rzauerzueutl.su",
  1015. "answers":
  1016.  
  1017. "data": "",
  1018. "type": "NXDOMAIN"
  1019.  
  1020.  
  1021.  
  1022.  
  1023. "type": "MX",
  1024. "request": "yahoo.com",
  1025. "answers":
  1026.  
  1027. "data": "mta5.am0.yahoodns.net",
  1028. "type": "MX"
  1029.  
  1030.  
  1031. "data": "mta7.am0.yahoodns.net",
  1032. "type": "MX"
  1033.  
  1034.  
  1035. "data": "mta6.am0.yahoodns.net",
  1036. "type": "MX"
  1037.  
  1038.  
  1039.  
  1040.  
  1041. "type": "A",
  1042. "request": "mta5.am0.yahoodns.net",
  1043. "answers":
  1044.  
  1045. "data": "67.195.228.94",
  1046. "type": "A"
  1047.  
  1048.  
  1049. "data": "74.6.137.64",
  1050. "type": "A"
  1051.  
  1052.  
  1053. "data": "67.195.228.109",
  1054. "type": "A"
  1055.  
  1056.  
  1057. "data": "98.137.159.26",
  1058. "type": "A"
  1059.  
  1060.  
  1061. "data": "98.137.159.24",
  1062. "type": "A"
  1063.  
  1064.  
  1065. "data": "74.6.137.63",
  1066. "type": "A"
  1067.  
  1068.  
  1069. "data": "66.218.85.52",
  1070. "type": "A"
  1071.  
  1072.  
  1073. "data": "67.195.228.110",
  1074. "type": "A"
  1075.  
  1076.  
  1077.  
  1078.  
  1079.  
  1080. * Domains:
  1081.  
  1082. "ip": "",
  1083. "domain": "gosurrhrguhp.io"
  1084.  
  1085.  
  1086. "ip": "",
  1087. "domain": "rzauerzueutp.io"
  1088.  
  1089.  
  1090. "ip": "",
  1091. "domain": "abfeiagihiso.co"
  1092.  
  1093.  
  1094. "ip": "",
  1095. "domain": "buaeabguguuo.co"
  1096.  
  1097.  
  1098. "ip": "",
  1099. "domain": "rzauerzueutl.su"
  1100.  
  1101.  
  1102. "ip": "",
  1103. "domain": "nkoaefuhfuhl.su"
  1104.  
  1105.  
  1106. "ip": "",
  1107. "domain": "gosurrhrguhr.cc"
  1108.  
  1109.  
  1110. "ip": "",
  1111. "domain": "nkoaefuhfuho.co"
  1112.  
  1113.  
  1114. "ip": "",
  1115. "domain": "eeeieiieirdp.io"
  1116.  
  1117.  
  1118. "ip": "",
  1119. "domain": "miokpkaeofko.co"
  1120.  
  1121.  
  1122. "ip": "",
  1123. "domain": "egaueuefuhgp.io"
  1124.  
  1125.  
  1126. "ip": "",
  1127. "domain": "aieiiieitter.cc"
  1128.  
  1129.  
  1130. "ip": "",
  1131. "domain": "aoufauhueful.su"
  1132.  
  1133.  
  1134. "ip": "",
  1135. "domain": "eeeieiieirdl.su"
  1136.  
  1137.  
  1138. "ip": "",
  1139. "domain": "abfeiagihisl.su"
  1140.  
  1141.  
  1142. "ip": "",
  1143. "domain": "egaueuefuhgl.su"
  1144.  
  1145.  
  1146. "ip": "",
  1147. "domain": "buaeabguguup.io"
  1148.  
  1149.  
  1150. "ip": "",
  1151. "domain": "goheufuhufdl.su"
  1152.  
  1153.  
  1154. "ip": "",
  1155. "domain": "miokpkaeofkr.cc"
  1156.  
  1157.  
  1158. "ip": "",
  1159. "domain": "olruheuuruur.cc"
  1160.  
  1161.  
  1162. "ip": "",
  1163. "domain": "egaueuefuhgo.co"
  1164.  
  1165.  
  1166. "ip": "",
  1167. "domain": "olruheuuruup.io"
  1168.  
  1169.  
  1170. "ip": "",
  1171. "domain": "abfeiagihisr.cc"
  1172.  
  1173.  
  1174. "ip": "",
  1175. "domain": "eeeieiieirdo.co"
  1176.  
  1177.  
  1178. "ip": "",
  1179. "domain": "bfbaiefiheir.cc"
  1180.  
  1181.  
  1182. "ip": "",
  1183. "domain": "ebgiaueghuur.cc"
  1184.  
  1185.  
  1186. "ip": "",
  1187. "domain": "goheufuhufdp.io"
  1188.  
  1189.  
  1190. "ip": "",
  1191. "domain": "bfbaiefiheil.su"
  1192.  
  1193.  
  1194. "ip": "",
  1195. "domain": "abfeiagihisp.io"
  1196.  
  1197.  
  1198. "ip": "",
  1199. "domain": "ezaziiezfzgr.cc"
  1200.  
  1201.  
  1202. "ip": "",
  1203. "domain": "aoufauhuefuo.co"
  1204.  
  1205.  
  1206. "ip": "",
  1207. "domain": "buaeabguguur.cc"
  1208.  
  1209.  
  1210. "ip": "",
  1211. "domain": "ezaziiezfzgp.io"
  1212.  
  1213.  
  1214. "ip": "",
  1215. "domain": "ebgiaueghuup.io"
  1216.  
  1217.  
  1218. "ip": "",
  1219. "domain": "miokpkaeofkp.io"
  1220.  
  1221.  
  1222. "ip": "",
  1223. "domain": "aieiiieitteo.co"
  1224.  
  1225.  
  1226. "ip": "",
  1227. "domain": "bfbaiefiheip.io"
  1228.  
  1229.  
  1230. "ip": "",
  1231. "domain": "bfbaiefiheio.co"
  1232.  
  1233.  
  1234. "ip": "98.137.246.8",
  1235. "domain": "yahoo.com"
  1236.  
  1237.  
  1238. "ip": "98.137.159.24",
  1239. "domain": "mta5.am0.yahoodns.net"
  1240.  
  1241.  
  1242. "ip": "",
  1243. "domain": "ebgiaueghuuo.co"
  1244.  
  1245.  
  1246. "ip": "",
  1247. "domain": "olruheuuruul.su"
  1248.  
  1249.  
  1250. "ip": "",
  1251. "domain": "ezaziiezfzgl.su"
  1252.  
  1253.  
  1254. "ip": "",
  1255. "domain": "nkoaefuhfuhp.io"
  1256.  
  1257.  
  1258. "ip": "",
  1259. "domain": "olruheuuruuo.co"
  1260.  
  1261.  
  1262. "ip": "",
  1263. "domain": "miokpkaeofkl.su"
  1264.  
  1265.  
  1266. "ip": "",
  1267. "domain": "buaeabguguul.su"
  1268.  
  1269.  
  1270. "ip": "",
  1271. "domain": "goheufuhufdo.co"
  1272.  
  1273.  
  1274. "ip": "",
  1275. "domain": "nkoaefuhfuhr.cc"
  1276.  
  1277.  
  1278. "ip": "",
  1279. "domain": "goheufuhufdr.cc"
  1280.  
  1281.  
  1282. "ip": "",
  1283. "domain": "gosurrhrguhl.su"
  1284.  
  1285.  
  1286. "ip": "",
  1287. "domain": "aoufauhuefur.cc"
  1288.  
  1289.  
  1290. "ip": "",
  1291. "domain": "gosurrhrguho.co"
  1292.  
  1293.  
  1294. "ip": "",
  1295. "domain": "aieiiieittep.io"
  1296.  
  1297.  
  1298. "ip": "",
  1299. "domain": "ebgiaueghuul.su"
  1300.  
  1301.  
  1302. "ip": "",
  1303. "domain": "rzauerzueuto.co"
  1304.  
  1305.  
  1306. "ip": "",
  1307. "domain": "aieiiieittel.su"
  1308.  
  1309.  
  1310. "ip": "",
  1311. "domain": "ezaziiezfzgo.co"
  1312.  
  1313.  
  1314. "ip": "",
  1315. "domain": "rzauerzueutr.cc"
  1316.  
  1317.  
  1318. "ip": "",
  1319. "domain": "egaueuefuhgr.cc"
  1320.  
  1321.  
  1322. "ip": "",
  1323. "domain": "aoufauhuefup.io"
  1324.  
  1325.  
  1326. "ip": "",
  1327. "domain": "eeeieiieirdr.cc"
  1328.  
  1329.  
  1330.  
  1331. * Network Communication - ICMP:
  1332.  
  1333. * Network Communication - HTTP:
  1334.  
  1335. "count": 1,
  1336. "body": "",
  1337. "uri": "http://193.32.161.73/t.php?new=1",
  1338. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1339. "method": "GET",
  1340. "host": "193.32.161.73",
  1341. "version": "1.1",
  1342. "path": "/t.php?new=1",
  1343. "data": "GET /t.php?new=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1344. "port": 80
  1345.  
  1346.  
  1347. "count": 2,
  1348. "body": "",
  1349. "uri": "http://193.32.161.73/1",
  1350. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1351. "method": "GET",
  1352. "host": "193.32.161.73",
  1353. "version": "1.1",
  1354. "path": "/1",
  1355. "data": "GET /1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1356. "port": 80
  1357.  
  1358.  
  1359. "count": 2,
  1360. "body": "",
  1361. "uri": "http://193.32.161.73/2",
  1362. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1363. "method": "GET",
  1364. "host": "193.32.161.73",
  1365. "version": "1.1",
  1366. "path": "/2",
  1367. "data": "GET /2 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1368. "port": 80
  1369.  
  1370.  
  1371. "count": 2,
  1372. "body": "",
  1373. "uri": "http://193.32.161.73/3",
  1374. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1375. "method": "GET",
  1376. "host": "193.32.161.73",
  1377. "version": "1.1",
  1378. "path": "/3",
  1379. "data": "GET /3 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1380. "port": 80
  1381.  
  1382.  
  1383. "count": 2,
  1384. "body": "",
  1385. "uri": "http://193.32.161.73/4",
  1386. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1387. "method": "GET",
  1388. "host": "193.32.161.73",
  1389. "version": "1.1",
  1390. "path": "/4",
  1391. "data": "GET /4 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1392. "port": 80
  1393.  
  1394.  
  1395. "count": 2,
  1396. "body": "",
  1397. "uri": "http://193.32.161.73/5",
  1398. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1399. "method": "GET",
  1400. "host": "193.32.161.73",
  1401. "version": "1.1",
  1402. "path": "/5",
  1403. "data": "GET /5 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1404. "port": 80
  1405.  
  1406.  
  1407. "count": 2,
  1408. "body": "",
  1409. "uri": "http://193.32.161.73/6",
  1410. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1411. "method": "GET",
  1412. "host": "193.32.161.73",
  1413. "version": "1.1",
  1414. "path": "/6",
  1415. "data": "GET /6 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1416. "port": 80
  1417.  
  1418.  
  1419. "count": 2,
  1420. "body": "",
  1421. "uri": "http://193.32.161.73/7",
  1422. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1423. "method": "GET",
  1424. "host": "193.32.161.73",
  1425. "version": "1.1",
  1426. "path": "/7",
  1427. "data": "GET /7 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1428. "port": 80
  1429.  
  1430.  
  1431. "count": 1,
  1432. "body": "",
  1433. "uri": "http://193.32.161.73/8",
  1434. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1435. "method": "GET",
  1436. "host": "193.32.161.73",
  1437. "version": "1.1",
  1438. "path": "/8",
  1439. "data": "GET /8 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1440. "port": 80
  1441.  
  1442.  
  1443.  
  1444. * Network Communication - SMTP:
  1445.  
  1446. * Network Communication - Hosts:
  1447.  
  1448. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment