paladin316

Gozi_616cbb4e11a548edd591c2616e6f013f_exe_2019-07-18_20_30.txt

Jul 18th, 2019
2,144
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 55.38 KB | None | 0 0
  1.  
  2. * MalFamily: "Gozi"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Gozi_616cbb4e11a548edd591c2616e6f013f.exe"
  7. * File Size: 226304
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "1903054965db85227c9324e88928a00e36890de4e0dec8961abf68520b48e3f3"
  10. * MD5: "616cbb4e11a548edd591c2616e6f013f"
  11. * SHA1: "f44f8aff3f97f40f245e66cb3567b86d4a54233b"
  12. * SHA512: "b8d4be20f1966d95647c7e210c3f980f1672625df24f097e9b139071ed42ec6ac02dc1f33ac96f0b65d159821a5353b839d2d9522c6f85b2aa51b655adb0256f"
  13. * CRC32: "455A7EAD"
  14. * SSDEEP: "3072:6b5luOp7O8qqImu2yvIB+RBNyBNKKh2XKqxWBNUx+kL+ERNvUfb/XzV4XS83DhQi:QsO2ths6UwhXxWWRL+fD/Xzu19Qi"
  15.  
  16. * Process Execution:
  17. "Gozi_616cbb4e11a548edd591c2616e6f013f.exe",
  18. "svchost.exe",
  19. "WmiPrvSE.exe",
  20. "iexplore.exe",
  21. "iexplore.exe",
  22. "iexplore.exe",
  23. "iexplore.exe",
  24. "iexplore.exe",
  25. "iexplore.exe",
  26. "iexplore.exe",
  27. "iexplore.exe",
  28. "iexplore.exe",
  29. "iexplore.exe",
  30. "iexplore.exe",
  31. "iexplore.exe",
  32. "iexplore.exe",
  33. "iexplore.exe",
  34. "iexplore.exe",
  35. "iexplore.exe",
  36. "iexplore.exe",
  37. "iexplore.exe"
  38.  
  39.  
  40. * Executed Commands:
  41. "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -secured -Embedding",
  42. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" -Embedding",
  43. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1644 CREDAT:79873",
  44. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2256 CREDAT:79873",
  45. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1640 CREDAT:79873",
  46. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1356 CREDAT:79873",
  47. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:992 CREDAT:79873",
  48. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2396 CREDAT:79873",
  49. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1456 CREDAT:79873",
  50. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2496 CREDAT:79873",
  51. "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2408 CREDAT:79873"
  52.  
  53.  
  54. * Signatures Detected:
  55.  
  56. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  57. "Details":
  58.  
  59. "IP": "204.79.197.200:80"
  60.  
  61.  
  62. "IP": "47.91.73.174:80"
  63.  
  64.  
  65.  
  66.  
  67. "Description": "Creates RWX memory",
  68. "Details":
  69.  
  70.  
  71. "Description": "A process attempted to delay the analysis task.",
  72. "Details":
  73.  
  74. "Process": "Gozi_616cbb4e11a548edd591c2616e6f013f.exe tried to sleep 1514 seconds, actually delayed analysis time by 0 seconds"
  75.  
  76.  
  77. "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "Performs some HTTP requests",
  83. "Details":
  84.  
  85. "url": "http://www.bing.com/favicon.ico"
  86.  
  87.  
  88. "url": "http://x1.narutik.at/webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V"
  89.  
  90.  
  91. "url": "http://cdn5.narutik.at/webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1"
  92.  
  93.  
  94. "url": "http://cd.pranahat.at/webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1"
  95.  
  96.  
  97. "url": "http://x1.narutik.at/webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy"
  98.  
  99.  
  100. "url": "http://cdn5.narutik.at/webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8"
  101.  
  102.  
  103. "url": "http://cd.pranahat.at/webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T"
  104.  
  105.  
  106. "url": "http://x1.narutik.at/webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu"
  107.  
  108.  
  109. "url": "http://cdn5.narutik.at/webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d"
  110.  
  111.  
  112. "url": "http://cd.pranahat.at/webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG"
  113.  
  114.  
  115.  
  116.  
  117. "Description": "Crashed cuckoomon during analysis. Report this error to the Github repo.",
  118. "Details":
  119.  
  120. "pid": 1532
  121.  
  122.  
  123. "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x2fd0c4 from hook RtlDispatchException"
  124.  
  125.  
  126. "pid": 1532
  127.  
  128.  
  129. "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  130.  
  131.  
  132. "pid": 1532
  133.  
  134.  
  135. "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x2fd0c8 from hook RtlDispatchException"
  136.  
  137.  
  138. "pid": 1532
  139.  
  140.  
  141. "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  142.  
  143.  
  144. "pid": 1532
  145.  
  146.  
  147. "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x2fd0c0 from hook RtlDispatchException"
  148.  
  149.  
  150. "pid": 1532
  151.  
  152.  
  153. "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  154.  
  155.  
  156. "pid": 1532
  157.  
  158.  
  159. "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x2fd0bc from hook RtlDispatchException"
  160.  
  161.  
  162. "pid": 1532
  163.  
  164.  
  165. "message": "Exception reported at offset 0x19689 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  166.  
  167.  
  168. "pid": 1532
  169.  
  170.  
  171. "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x2fd0cc from hook RtlDispatchException"
  172.  
  173.  
  174. "pid": 1532
  175.  
  176.  
  177. "message": "Exception reported at offset 0x1969b in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  178.  
  179.  
  180. "pid": 1532
  181.  
  182.  
  183. "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x2fd0d0 from hook RtlDispatchException"
  184.  
  185.  
  186. "pid": 1532
  187.  
  188.  
  189. "message": "Exception reported at offset 0x196a2 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  190.  
  191.  
  192. "pid": 1532
  193.  
  194.  
  195. "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x2fd0d4 from hook RtlDispatchException"
  196.  
  197.  
  198. "pid": 1532
  199.  
  200.  
  201. "message": "Exception reported at offset 0x196ad in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  202.  
  203.  
  204. "pid": 1532
  205.  
  206.  
  207. "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x2fd0d8 from hook RtlDispatchException"
  208.  
  209.  
  210. "pid": 1532
  211.  
  212.  
  213. "message": "Exception reported at offset 0x196c0 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  214.  
  215.  
  216. "pid": 1532
  217.  
  218.  
  219. "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x2fd0bc from hook RtlDispatchException"
  220.  
  221.  
  222. "pid": 1532
  223.  
  224.  
  225. "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  226.  
  227.  
  228. "pid": 1532
  229.  
  230.  
  231. "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x2fd0c0 from hook RtlDispatchException"
  232.  
  233.  
  234. "pid": 1532
  235.  
  236.  
  237. "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  238.  
  239.  
  240. "pid": 1532
  241.  
  242.  
  243. "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x2fd0c4 from hook RtlDispatchException"
  244.  
  245.  
  246. "pid": 1532
  247.  
  248.  
  249. "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  250.  
  251.  
  252. "pid": 1532
  253.  
  254.  
  255. "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x2fd0c8 from hook RtlDispatchException"
  256.  
  257.  
  258. "pid": 1532
  259.  
  260.  
  261. "message": "Exception reported at offset 0x19c07 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
  262.  
  263.  
  264. "pid": 1532
  265.  
  266.  
  267. "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x2fd030 from hook RtlDispatchException"
  268.  
  269.  
  270. "pid": 1532
  271.  
  272.  
  273. "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x2fd034 from hook RtlDispatchException"
  274.  
  275.  
  276. "pid": 1532
  277.  
  278.  
  279. "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x2fd02c from hook RtlDispatchException"
  280.  
  281.  
  282. "pid": 1532
  283.  
  284.  
  285. "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x2fd028 from hook RtlDispatchException"
  286.  
  287.  
  288. "pid": 1532
  289.  
  290.  
  291. "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x2fd048 from hook RtlDispatchException"
  292.  
  293.  
  294. "pid": 1532
  295.  
  296.  
  297. "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x2fd04c from hook RtlDispatchException"
  298.  
  299.  
  300. "pid": 1532
  301.  
  302.  
  303. "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x2fd050 from hook RtlDispatchException"
  304.  
  305.  
  306. "pid": 1532
  307.  
  308.  
  309. "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x2fd054 from hook RtlDispatchException"
  310.  
  311.  
  312. "pid": 1532
  313.  
  314.  
  315. "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x2fd028 from hook RtlDispatchException"
  316.  
  317.  
  318. "pid": 1532
  319.  
  320.  
  321. "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x2fd02c from hook RtlDispatchException"
  322.  
  323.  
  324. "pid": 1532
  325.  
  326.  
  327. "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x2fd030 from hook RtlDispatchException"
  328.  
  329.  
  330. "pid": 1532
  331.  
  332.  
  333. "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x2fd034 from hook RtlDispatchException"
  334.  
  335.  
  336.  
  337.  
  338. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  339. "Details":
  340.  
  341. "Spam": "Gozi_616cbb4e11a548edd591c2616e6f013f.exe (1532) called API GlobalMemoryStatus 416539 times"
  342.  
  343.  
  344. "Spam": "Gozi_616cbb4e11a548edd591c2616e6f013f.exe (1532) called API NtOpenFile 15951 times"
  345.  
  346.  
  347.  
  348.  
  349. "Description": "Creates a hidden or system file",
  350. "Details":
  351.  
  352. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\IETldCache\\Low"
  353.  
  354.  
  355. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf09f9c.TMP"
  356.  
  357.  
  358. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf10e73.TMP"
  359.  
  360.  
  361. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf17c30.TMP"
  362.  
  363.  
  364. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf1eed0.TMP"
  365.  
  366.  
  367. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf24ee2.TMP"
  368.  
  369.  
  370. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf2b2ad.TMP"
  371.  
  372.  
  373. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3138a.TMP"
  374.  
  375.  
  376. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf370ad.TMP"
  377.  
  378.  
  379. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3cfd5.TMP"
  380.  
  381.  
  382.  
  383.  
  384. "Description": "File has been identified by 21 Antiviruses on VirusTotal as malicious",
  385. "Details":
  386.  
  387. "FireEye": "Generic.mg.616cbb4e11a548ed"
  388.  
  389.  
  390. "McAfee": "Artemis!616CBB4E11A5"
  391.  
  392.  
  393. "SUPERAntiSpyware": "Trojan.Agent/Gen-Dropper"
  394.  
  395.  
  396. "CrowdStrike": "win/malicious_confidence_80% (W)"
  397.  
  398.  
  399. "Symantec": "Packed.Generic.516"
  400.  
  401.  
  402. "APEX": "Malicious"
  403.  
  404.  
  405. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  406.  
  407.  
  408. "Paloalto": "generic.ml"
  409.  
  410.  
  411. "AegisLab": "Trojan.Win32.Generic.4!c"
  412.  
  413.  
  414. "Endgame": "malicious (high confidence)"
  415.  
  416.  
  417. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.dh"
  418.  
  419.  
  420. "SentinelOne": "DFI - Suspicious PE"
  421.  
  422.  
  423. "Webroot": "W32.Adware.Gen"
  424.  
  425.  
  426. "Microsoft": "Trojan:Win32/Gandcrab.AF"
  427.  
  428.  
  429. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  430.  
  431.  
  432. "Acronis": "suspicious"
  433.  
  434.  
  435. "Malwarebytes": "Trojan.MalPack.GS"
  436.  
  437.  
  438. "Rising": "[email protected] (RDML:CDbyE720pcsJMvVEQZia/Q)"
  439.  
  440.  
  441. "AVG": "FileRepMalware"
  442.  
  443.  
  444. "Cybereason": "malicious.f3f97f"
  445.  
  446.  
  447. "Qihoo-360": "HEUR/QVM10.1.9C35.Malware.Gen"
  448.  
  449.  
  450.  
  451.  
  452. "Description": "Attempts to modify proxy settings",
  453. "Details":
  454.  
  455.  
  456. "Description": "Anomalous binary characteristics",
  457. "Details":
  458.  
  459. "anomaly": "Found duplicated section names"
  460.  
  461.  
  462.  
  463.  
  464.  
  465. * Started Service:
  466.  
  467. * Mutexes:
  468. "Local\\_!MSFTHISTORY!_",
  469. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  470. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  471. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  472. "Local\\WininetStartupMutex",
  473. "Local\\WininetConnectionMutex",
  474. "Local\\WininetProxyRegistryMutex",
  475. "Local\\!IETld!Mutex",
  476. "Local\\!BrowserEmulation!SharedMemory!Mutex",
  477. "Local\\ZoneAttributeCacheCounterMutex",
  478. "Local\\ZonesCacheCounterMutex",
  479. "Local\\ZonesLockedCacheCounterMutex",
  480. "ConnHashTable<1644>_HashTable_Mutex",
  481. "Local\\ZonesCounterMutex",
  482. "Local\\RSS Eventing Connection Database Mutex 0000066c",
  483. "Local\\Feed Eventing Shared Memory Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
  484. "Local\\c:!users!user!appdata!local!microsoft!feeds cache!",
  485. "ConnHashTable<2256>_HashTable_Mutex",
  486. "Local\\RSS Eventing Connection Database Mutex 000008d0",
  487. "ConnHashTable<1640>_HashTable_Mutex",
  488. "Local\\RSS Eventing Connection Database Mutex 00000668",
  489. "ConnHashTable<1356>_HashTable_Mutex",
  490. "Local\\RSS Eventing Connection Database Mutex 0000054c",
  491. "ConnHashTable<992>_HashTable_Mutex",
  492. "Local\\RSS Eventing Connection Database Mutex 000003e0",
  493. "ConnHashTable<2396>_HashTable_Mutex",
  494. "Local\\RSS Eventing Connection Database Mutex 0000095c",
  495. "ConnHashTable<1456>_HashTable_Mutex",
  496. "Local\\RSS Eventing Connection Database Mutex 000005b0",
  497. "ConnHashTable<2496>_HashTable_Mutex",
  498. "Local\\RSS Eventing Connection Database Mutex 000009c0",
  499. "ConnHashTable<2408>_HashTable_Mutex",
  500. "Local\\RSS Eventing Connection Database Mutex 00000968"
  501.  
  502.  
  503. * Modified Files:
  504. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  505. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  506. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  507. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  508. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.25BA224F-A995-11E9-8070-18C086CD4729.dat",
  509. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4CB658832126F78B.TMP",
  510. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\25BA2250-A995-11E9-8070-18C086CD4729.dat",
  511. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF771D0FE00087E115.TMP",
  512. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon1.ico",
  513. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon2.ico",
  514. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon3.ico",
  515. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon4.ico",
  516. "\\??\\pipe\\MsFteWds",
  517. "\\??\\PIPE\\samr",
  518. "\\??\\PIPE\\srvsvc",
  519. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\S5Q2QB7LJANAQUUXHFRB.temp",
  520. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf09f9c.TMP",
  521. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds Cache\\index.dat",
  522. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.3462D7AB-A995-11E9-8070-18C086CD4729.dat",
  523. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4EEE15E52243545E.TMP",
  524. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\3462D7AC-A995-11E9-8070-18C086CD4729.dat",
  525. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA9FFEC90889FD04F.TMP",
  526. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon1.ico",
  527. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon2.ico",
  528. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon3.ico",
  529. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon4.ico",
  530. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\KHMCHWKQSXWA3B7NHSXT.temp",
  531. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf10e73.TMP",
  532. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.457C3523-A995-11E9-8070-18C086CD4729.dat",
  533. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF7A2A3A382E5327C2.TMP",
  534. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\457C3524-A995-11E9-8070-18C086CD4729.dat",
  535. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB693E65D5CAD2BA9.TMP",
  536. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favicon1.ico",
  537. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\V7WL281QD4CX6XVK2PRY.temp",
  538. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf17c30.TMP",
  539. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.5608E7DD-A995-11E9-8070-18C086CD4729.dat",
  540. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF2C468E59BDEF8E2D.TMP",
  541. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\5608E7DE-A995-11E9-8070-18C086CD4729.dat",
  542. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC03A8B944C00F2CB.TMP",
  543. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon1.ico",
  544. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon2.ico",
  545. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CSJD2B4DGSXPYZF6IDF2.temp",
  546. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf1eed0.TMP",
  547. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.67165993-A995-11E9-8070-18C086CD4729.dat",
  548. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF81468470E478850A.TMP",
  549. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\67165994-A995-11E9-8070-18C086CD4729.dat",
  550. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF150ED1A06B650CD0.TMP",
  551. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\S8QRRJ6CW490MMY0SQAR.temp",
  552. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf24ee2.TMP",
  553. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.76101EE3-A995-11E9-8070-18C086CD4729.dat",
  554. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFFA902DC4111A16BE.TMP",
  555. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\76101EE4-A995-11E9-8070-18C086CD4729.dat",
  556. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF25A86B062B7234F5.TMP",
  557. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\J0D9J9ROQLIXBTAYPXYC.temp",
  558. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf2b2ad.TMP",
  559. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.85621B35-A995-11E9-8070-18C086CD4729.dat",
  560. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDBBAC43DD383C568.TMP",
  561. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\85621B36-A995-11E9-8070-18C086CD4729.dat",
  562. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5D9ACA9646BCCB6A.TMP",
  563. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WH8QDSDR23E8JIUGJN4Z.temp",
  564. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3138a.TMP",
  565. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.93F2F90D-A995-11E9-8070-18C086CD4729.dat",
  566. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3CF6E8E3D115DEAC.TMP",
  567. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\93F2F90E-A995-11E9-8070-18C086CD4729.dat",
  568. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFF9B0A06F17D1FB62.TMP",
  569. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\8O5FOB0CD3ECIXEIP0L8.temp",
  570. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf370ad.TMP",
  571. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.A2699D07-A995-11E9-8070-18C086CD4729.dat",
  572. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB1F4A52FBEBB0A47.TMP",
  573. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\A2699D08-A995-11E9-8070-18C086CD4729.dat",
  574. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF000EB570925D5184.TMP",
  575. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CM9RX93WG6SWXU3K1MA8.temp",
  576. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3cfd5.TMP"
  577.  
  578.  
  579. * Deleted Files:
  580. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\Internet Explorer\\Services\\search_0633EE93-D776-472f-A0FF-E1416B8B2E3A.ico",
  581. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf09f9c.TMP",
  582. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\25BA2250-A995-11E9-8070-18C086CD4729.dat",
  583. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.25BA224F-A995-11E9-8070-18C086CD4729.dat",
  584. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf10e73.TMP",
  585. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\3462D7AC-A995-11E9-8070-18C086CD4729.dat",
  586. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.3462D7AB-A995-11E9-8070-18C086CD4729.dat",
  587. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf17c30.TMP",
  588. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\457C3524-A995-11E9-8070-18C086CD4729.dat",
  589. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.457C3523-A995-11E9-8070-18C086CD4729.dat",
  590. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf1eed0.TMP",
  591. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\5608E7DE-A995-11E9-8070-18C086CD4729.dat",
  592. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.5608E7DD-A995-11E9-8070-18C086CD4729.dat",
  593. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf24ee2.TMP",
  594. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\67165994-A995-11E9-8070-18C086CD4729.dat",
  595. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.67165993-A995-11E9-8070-18C086CD4729.dat",
  596. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf2b2ad.TMP",
  597. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\76101EE4-A995-11E9-8070-18C086CD4729.dat",
  598. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.76101EE3-A995-11E9-8070-18C086CD4729.dat",
  599. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3138a.TMP",
  600. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\85621B36-A995-11E9-8070-18C086CD4729.dat",
  601. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.85621B35-A995-11E9-8070-18C086CD4729.dat",
  602. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf370ad.TMP",
  603. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\93F2F90E-A995-11E9-8070-18C086CD4729.dat",
  604. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.93F2F90D-A995-11E9-8070-18C086CD4729.dat",
  605. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3cfd5.TMP",
  606. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\A2699D08-A995-11E9-8070-18C086CD4729.dat",
  607. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.A2699D07-A995-11E9-8070-18C086CD4729.dat"
  608.  
  609.  
  610. * Modified Registry Keys:
  611. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown",
  612. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown_TIMESTAMP",
  613. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown",
  614. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown_TIMESTAMP",
  615. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\Check_Associations",
  616. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\VerCache",
  617. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\VerCache",
  618. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\VerCache",
  619. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CompatibilityFlags",
  620. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  621. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  622. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
  623. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  624. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  625. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  626. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\25BA224F-A995-11E9-8070-18C086CD4729",
  627. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\2670000A-7350-4F3C-8081-5663EE0C6C49\\iexplore\\Type",
  628. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\2670000A-7350-4F3C-8081-5663EE0C6C49\\iexplore\\Count",
  629. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\2670000A-7350-4F3C-8081-5663EE0C6C49\\iexplore\\Time",
  630. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\Type",
  631. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\Count",
  632. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\Time",
  633. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\789FE86F-6FC4-46A1-9849-EDE0DB0C95CA\\iexplore\\Type",
  634. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\789FE86F-6FC4-46A1-9849-EDE0DB0C95CA\\iexplore\\Count",
  635. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\789FE86F-6FC4-46A1-9849-EDE0DB0C95CA\\iexplore\\Time",
  636. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FullScreen",
  637. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder\\Favorites\\Links\\Order",
  638. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\LoadTime",
  639. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\Type",
  640. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\Count",
  641. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\Time",
  642. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\LoadTime",
  643. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\Type",
  644. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\Count",
  645. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\Time",
  646. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\LoadTime",
  647. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\CFBFAE00-17A6-11D0-99CB-00C04FD64497\\iexplore\\Type",
  648. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\CFBFAE00-17A6-11D0-99CB-00C04FD64497\\iexplore\\Count",
  649. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\CFBFAE00-17A6-11D0-99CB-00C04FD64497\\iexplore\\Time",
  650. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\3462D7AB-A995-11E9-8070-18C086CD4729",
  651. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\457C3523-A995-11E9-8070-18C086CD4729",
  652. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\5608E7DD-A995-11E9-8070-18C086CD4729",
  653. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\67165993-A995-11E9-8070-18C086CD4729",
  654. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\76101EE3-A995-11E9-8070-18C086CD4729",
  655. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\85621B35-A995-11E9-8070-18C086CD4729",
  656. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\93F2F90D-A995-11E9-8070-18C086CD4729",
  657. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\A2699D07-A995-11E9-8070-18C086CD4729"
  658.  
  659.  
  660. * Deleted Registry Keys:
  661. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  662. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  663. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  664. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  665. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  666. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
  667. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\25BA224F-A995-11E9-8070-18C086CD4729",
  668. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
  669. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
  670. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\3462D7AB-A995-11E9-8070-18C086CD4729",
  671. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\457C3523-A995-11E9-8070-18C086CD4729",
  672. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\5608E7DD-A995-11E9-8070-18C086CD4729",
  673. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\67165993-A995-11E9-8070-18C086CD4729",
  674. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\76101EE3-A995-11E9-8070-18C086CD4729",
  675. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\85621B35-A995-11E9-8070-18C086CD4729",
  676. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\93F2F90D-A995-11E9-8070-18C086CD4729",
  677. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\A2699D07-A995-11E9-8070-18C086CD4729"
  678.  
  679.  
  680. * DNS Communications:
  681.  
  682. "type": "A",
  683. "request": "x1.narutik.at",
  684. "answers":
  685.  
  686. "data": "47.91.73.174",
  687. "type": "A"
  688.  
  689.  
  690.  
  691.  
  692. "type": "A",
  693. "request": "www.bing.com",
  694. "answers":
  695.  
  696. "data": "dual-a-0001.a-msedge.net",
  697. "type": "CNAME"
  698.  
  699.  
  700. "data": "a-0001.a-afdentry.net.trafficmanager.net",
  701. "type": "CNAME"
  702.  
  703.  
  704. "data": "204.79.197.200",
  705. "type": "A"
  706.  
  707.  
  708. "data": "13.107.21.200",
  709. "type": "A"
  710.  
  711.  
  712.  
  713.  
  714. "type": "A",
  715. "request": "cdn5.narutik.at",
  716. "answers":
  717.  
  718. "data": "47.91.73.174",
  719. "type": "A"
  720.  
  721.  
  722.  
  723.  
  724. "type": "A",
  725. "request": "cd.pranahat.at",
  726. "answers":
  727.  
  728. "data": "47.91.73.174",
  729. "type": "A"
  730.  
  731.  
  732.  
  733.  
  734.  
  735. * Domains:
  736.  
  737. "ip": "47.91.73.174",
  738. "domain": "cdn5.narutik.at"
  739.  
  740.  
  741. "ip": "47.91.73.174",
  742. "domain": "x1.narutik.at"
  743.  
  744.  
  745. "ip": "47.91.73.174",
  746. "domain": "cd.pranahat.at"
  747.  
  748.  
  749. "ip": "204.79.197.200",
  750. "domain": "www.bing.com"
  751.  
  752.  
  753.  
  754. * Network Communication - ICMP:
  755.  
  756. * Network Communication - HTTP:
  757.  
  758. "count": 10,
  759. "body": "",
  760. "uri": "http://www.bing.com/favicon.ico",
  761. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  762. "method": "GET",
  763. "host": "www.bing.com",
  764. "version": "1.1",
  765. "path": "/favicon.ico",
  766. "data": "GET /favicon.ico HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.bing.com\r\nConnection: Keep-Alive\r\nCookie: MUID=055643067C21678412144E247D39664A; SRCHD=AF=NOFORM; SRCHUID=V=2&GUID=5262DC06BBB54635AC9D8A0AD382875E&dmnchg=1; SRCHUSR=DOB=20190317\r\n\r\n",
  767. "port": 80
  768.  
  769.  
  770. "count": 1,
  771. "body": "",
  772. "uri": "http://x1.narutik.at/webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V",
  773. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  774. "method": "GET",
  775. "host": "x1.narutik.at",
  776. "version": "1.1",
  777. "path": "/webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V",
  778. "data": "GET /webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V HTTP/1.1\r\nAccept: */*\r\nHost: x1.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  779. "port": 80
  780.  
  781.  
  782. "count": 1,
  783. "body": "",
  784. "uri": "http://cdn5.narutik.at/webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1",
  785. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  786. "method": "GET",
  787. "host": "cdn5.narutik.at",
  788. "version": "1.1",
  789. "path": "/webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1",
  790. "data": "GET /webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1 HTTP/1.1\r\nAccept: */*\r\nHost: cdn5.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  791. "port": 80
  792.  
  793.  
  794. "count": 1,
  795. "body": "",
  796. "uri": "http://cd.pranahat.at/webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1",
  797. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  798. "method": "GET",
  799. "host": "cd.pranahat.at",
  800. "version": "1.1",
  801. "path": "/webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1",
  802. "data": "GET /webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1 HTTP/1.1\r\nAccept: */*\r\nHost: cd.pranahat.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  803. "port": 80
  804.  
  805.  
  806. "count": 1,
  807. "body": "",
  808. "uri": "http://x1.narutik.at/webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy",
  809. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  810. "method": "GET",
  811. "host": "x1.narutik.at",
  812. "version": "1.1",
  813. "path": "/webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy",
  814. "data": "GET /webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy HTTP/1.1\r\nAccept: */*\r\nHost: x1.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  815. "port": 80
  816.  
  817.  
  818. "count": 1,
  819. "body": "",
  820. "uri": "http://cdn5.narutik.at/webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8",
  821. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  822. "method": "GET",
  823. "host": "cdn5.narutik.at",
  824. "version": "1.1",
  825. "path": "/webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8",
  826. "data": "GET /webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8 HTTP/1.1\r\nAccept: */*\r\nHost: cdn5.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  827. "port": 80
  828.  
  829.  
  830. "count": 1,
  831. "body": "",
  832. "uri": "http://cd.pranahat.at/webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T",
  833. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  834. "method": "GET",
  835. "host": "cd.pranahat.at",
  836. "version": "1.1",
  837. "path": "/webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T",
  838. "data": "GET /webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T HTTP/1.1\r\nAccept: */*\r\nHost: cd.pranahat.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  839. "port": 80
  840.  
  841.  
  842. "count": 1,
  843. "body": "",
  844. "uri": "http://x1.narutik.at/webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu",
  845. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  846. "method": "GET",
  847. "host": "x1.narutik.at",
  848. "version": "1.1",
  849. "path": "/webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu",
  850. "data": "GET /webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu HTTP/1.1\r\nAccept: */*\r\nHost: x1.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  851. "port": 80
  852.  
  853.  
  854. "count": 1,
  855. "body": "",
  856. "uri": "http://cdn5.narutik.at/webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d",
  857. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  858. "method": "GET",
  859. "host": "cdn5.narutik.at",
  860. "version": "1.1",
  861. "path": "/webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d",
  862. "data": "GET /webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d HTTP/1.1\r\nAccept: */*\r\nHost: cdn5.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  863. "port": 80
  864.  
  865.  
  866. "count": 1,
  867. "body": "",
  868. "uri": "http://cd.pranahat.at/webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG",
  869. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  870. "method": "GET",
  871. "host": "cd.pranahat.at",
  872. "version": "1.1",
  873. "path": "/webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG",
  874. "data": "GET /webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG HTTP/1.1\r\nAccept: */*\r\nHost: cd.pranahat.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
  875. "port": 80
  876.  
  877.  
  878.  
  879. * Network Communication - SMTP:
  880.  
  881. * Network Communication - Hosts:
  882.  
  883. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment