Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Gozi"
- * MalScore: 10.0
- * File Name: "Gozi_616cbb4e11a548edd591c2616e6f013f.exe"
- * File Size: 226304
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "1903054965db85227c9324e88928a00e36890de4e0dec8961abf68520b48e3f3"
- * MD5: "616cbb4e11a548edd591c2616e6f013f"
- * SHA1: "f44f8aff3f97f40f245e66cb3567b86d4a54233b"
- * SHA512: "b8d4be20f1966d95647c7e210c3f980f1672625df24f097e9b139071ed42ec6ac02dc1f33ac96f0b65d159821a5353b839d2d9522c6f85b2aa51b655adb0256f"
- * CRC32: "455A7EAD"
- * SSDEEP: "3072:6b5luOp7O8qqImu2yvIB+RBNyBNKKh2XKqxWBNUx+kL+ERNvUfb/XzV4XS83DhQi:QsO2ths6UwhXxWWRL+fD/Xzu19Qi"
- * Process Execution:
- "Gozi_616cbb4e11a548edd591c2616e6f013f.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe"
- * Executed Commands:
- "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -secured -Embedding",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" -Embedding",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1644 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2256 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1640 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1356 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:992 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2396 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1456 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2496 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2408 CREDAT:79873"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
- "Details":
- "IP": "204.79.197.200:80"
- "IP": "47.91.73.174:80"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "Gozi_616cbb4e11a548edd591c2616e6f013f.exe tried to sleep 1514 seconds, actually delayed analysis time by 0 seconds"
- "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://www.bing.com/favicon.ico"
- "url": "http://x1.narutik.at/webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V"
- "url": "http://cdn5.narutik.at/webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1"
- "url": "http://cd.pranahat.at/webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1"
- "url": "http://x1.narutik.at/webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy"
- "url": "http://cdn5.narutik.at/webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8"
- "url": "http://cd.pranahat.at/webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T"
- "url": "http://x1.narutik.at/webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu"
- "url": "http://cdn5.narutik.at/webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d"
- "url": "http://cd.pranahat.at/webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG"
- "Description": "Crashed cuckoomon during analysis. Report this error to the Github repo.",
- "Details":
- "pid": 1532
- "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x2fd0c4 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x2fd0c8 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x2fd0c0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x2fd0bc from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19689 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x2fd0cc from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x1969b in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x2fd0d0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196a2 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x2fd0d4 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196ad in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x2fd0d8 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196c0 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x2fd0bc from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x2fd0c0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x2fd0c4 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x2fd0c8 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c07 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x2fd030 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x2fd034 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x2fd02c from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x2fd028 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x2fd048 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x2fd04c from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x2fd050 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x2fd054 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x2fd028 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x2fd02c from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x2fd030 from hook RtlDispatchException"
- "pid": 1532
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x2fd034 from hook RtlDispatchException"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "Gozi_616cbb4e11a548edd591c2616e6f013f.exe (1532) called API GlobalMemoryStatus 416539 times"
- "Spam": "Gozi_616cbb4e11a548edd591c2616e6f013f.exe (1532) called API NtOpenFile 15951 times"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\IETldCache\\Low"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf09f9c.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf10e73.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf17c30.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf1eed0.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf24ee2.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf2b2ad.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3138a.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf370ad.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3cfd5.TMP"
- "Description": "File has been identified by 21 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Generic.mg.616cbb4e11a548ed"
- "McAfee": "Artemis!616CBB4E11A5"
- "SUPERAntiSpyware": "Trojan.Agent/Gen-Dropper"
- "CrowdStrike": "win/malicious_confidence_80% (W)"
- "Symantec": "Packed.Generic.516"
- "APEX": "Malicious"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "Paloalto": "generic.ml"
- "AegisLab": "Trojan.Win32.Generic.4!c"
- "Endgame": "malicious (high confidence)"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.dh"
- "SentinelOne": "DFI - Suspicious PE"
- "Webroot": "W32.Adware.Gen"
- "Microsoft": "Trojan:Win32/Gandcrab.AF"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "Acronis": "suspicious"
- "Malwarebytes": "Trojan.MalPack.GS"
- "Rising": "[email protected] (RDML:CDbyE720pcsJMvVEQZia/Q)"
- "AVG": "FileRepMalware"
- "Cybereason": "malicious.f3f97f"
- "Qihoo-360": "HEUR/QVM10.1.9C35.Malware.Gen"
- "Description": "Attempts to modify proxy settings",
- "Details":
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Found duplicated section names"
- * Started Service:
- * Mutexes:
- "Local\\_!MSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
- "Local\\WininetStartupMutex",
- "Local\\WininetConnectionMutex",
- "Local\\WininetProxyRegistryMutex",
- "Local\\!IETld!Mutex",
- "Local\\!BrowserEmulation!SharedMemory!Mutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "ConnHashTable<1644>_HashTable_Mutex",
- "Local\\ZonesCounterMutex",
- "Local\\RSS Eventing Connection Database Mutex 0000066c",
- "Local\\Feed Eventing Shared Memory Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
- "Local\\c:!users!user!appdata!local!microsoft!feeds cache!",
- "ConnHashTable<2256>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000008d0",
- "ConnHashTable<1640>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000668",
- "ConnHashTable<1356>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 0000054c",
- "ConnHashTable<992>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000003e0",
- "ConnHashTable<2396>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 0000095c",
- "ConnHashTable<1456>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000005b0",
- "ConnHashTable<2496>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000009c0",
- "ConnHashTable<2408>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000968"
- * Modified Files:
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.25BA224F-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4CB658832126F78B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\25BA2250-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF771D0FE00087E115.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon1.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon2.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon3.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favicon4.ico",
- "\\??\\pipe\\MsFteWds",
- "\\??\\PIPE\\samr",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\S5Q2QB7LJANAQUUXHFRB.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf09f9c.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds Cache\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.3462D7AB-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4EEE15E52243545E.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\3462D7AC-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA9FFEC90889FD04F.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon1.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon2.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon3.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favicon4.ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\KHMCHWKQSXWA3B7NHSXT.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf10e73.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.457C3523-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF7A2A3A382E5327C2.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\457C3524-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB693E65D5CAD2BA9.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favicon1.ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\V7WL281QD4CX6XVK2PRY.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf17c30.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.5608E7DD-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF2C468E59BDEF8E2D.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\5608E7DE-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC03A8B944C00F2CB.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon1.ico",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favicon2.ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CSJD2B4DGSXPYZF6IDF2.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf1eed0.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.67165993-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF81468470E478850A.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\67165994-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF150ED1A06B650CD0.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\S8QRRJ6CW490MMY0SQAR.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf24ee2.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.76101EE3-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFFA902DC4111A16BE.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\76101EE4-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF25A86B062B7234F5.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\J0D9J9ROQLIXBTAYPXYC.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf2b2ad.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.85621B35-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFDBBAC43DD383C568.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\85621B36-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5D9ACA9646BCCB6A.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WH8QDSDR23E8JIUGJN4Z.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3138a.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.93F2F90D-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3CF6E8E3D115DEAC.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\93F2F90E-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFF9B0A06F17D1FB62.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\8O5FOB0CD3ECIXEIP0L8.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf370ad.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.A2699D07-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB1F4A52FBEBB0A47.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\A2699D08-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF000EB570925D5184.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CM9RX93WG6SWXU3K1MA8.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3cfd5.TMP"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\Internet Explorer\\Services\\search_0633EE93-D776-472f-A0FF-E1416B8B2E3A.ico",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf09f9c.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\25BA2250-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.25BA224F-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf10e73.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\3462D7AC-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.3462D7AB-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf17c30.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\457C3524-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.457C3523-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf1eed0.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\5608E7DE-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.5608E7DD-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf24ee2.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\67165994-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.67165993-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf2b2ad.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\76101EE4-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.76101EE3-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3138a.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\85621B36-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.85621B35-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf370ad.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\93F2F90E-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.93F2F90D-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RFf3cfd5.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\A2699D08-A995-11E9-8070-18C086CD4729.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.A2699D07-A995-11E9-8070-18C086CD4729.dat"
- * Modified Registry Keys:
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown_TIMESTAMP",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown_TIMESTAMP",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\Check_Associations",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CompatibilityFlags",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\25BA224F-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\2670000A-7350-4F3C-8081-5663EE0C6C49\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\2670000A-7350-4F3C-8081-5663EE0C6C49\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\2670000A-7350-4F3C-8081-5663EE0C6C49\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\789FE86F-6FC4-46A1-9849-EDE0DB0C95CA\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\789FE86F-6FC4-46A1-9849-EDE0DB0C95CA\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\789FE86F-6FC4-46A1-9849-EDE0DB0C95CA\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FullScreen",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder\\Favorites\\Links\\Order",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\31D09BA0-12F5-4CCE-BE8A-2923E76605DA\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\B4F3A835-0E21-4959-BA22-42B3008E02FF\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\CFBFAE00-17A6-11D0-99CB-00C04FD64497\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\CFBFAE00-17A6-11D0-99CB-00C04FD64497\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\CFBFAE00-17A6-11D0-99CB-00C04FD64497\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\3462D7AB-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\457C3523-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\5608E7DD-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\67165993-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\76101EE3-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\85621B35-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\93F2F90D-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\A2699D07-A995-11E9-8070-18C086CD4729"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\25BA224F-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\3462D7AB-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\457C3523-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\5608E7DD-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\67165993-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\76101EE3-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\85621B35-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\93F2F90D-A995-11E9-8070-18C086CD4729",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\A2699D07-A995-11E9-8070-18C086CD4729"
- * DNS Communications:
- "type": "A",
- "request": "x1.narutik.at",
- "answers":
- "data": "47.91.73.174",
- "type": "A"
- "type": "A",
- "request": "www.bing.com",
- "answers":
- "data": "dual-a-0001.a-msedge.net",
- "type": "CNAME"
- "data": "a-0001.a-afdentry.net.trafficmanager.net",
- "type": "CNAME"
- "data": "204.79.197.200",
- "type": "A"
- "data": "13.107.21.200",
- "type": "A"
- "type": "A",
- "request": "cdn5.narutik.at",
- "answers":
- "data": "47.91.73.174",
- "type": "A"
- "type": "A",
- "request": "cd.pranahat.at",
- "answers":
- "data": "47.91.73.174",
- "type": "A"
- * Domains:
- "ip": "47.91.73.174",
- "domain": "cdn5.narutik.at"
- "ip": "47.91.73.174",
- "domain": "x1.narutik.at"
- "ip": "47.91.73.174",
- "domain": "cd.pranahat.at"
- "ip": "204.79.197.200",
- "domain": "www.bing.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 10,
- "body": "",
- "uri": "http://www.bing.com/favicon.ico",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "www.bing.com",
- "version": "1.1",
- "path": "/favicon.ico",
- "data": "GET /favicon.ico HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.bing.com\r\nConnection: Keep-Alive\r\nCookie: MUID=055643067C21678412144E247D39664A; SRCHD=AF=NOFORM; SRCHUID=V=2&GUID=5262DC06BBB54635AC9D8A0AD382875E&dmnchg=1; SRCHUSR=DOB=20190317\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://x1.narutik.at/webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "x1.narutik.at",
- "version": "1.1",
- "path": "/webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V",
- "data": "GET /webstore/Bq7CZvlkelOh5dh4Uq6SYI/FNy09umMDXPZQ/G_2Fuu0r/WlqzRm_2BqyywvUv9ntk5Jy/ktBEFY0a8p/tfAeH4dnHATX3Tnik/pLSKiV0WfSD0/Qg0EwobUeoT/wTpl6T8UNORmLV/QVdJgScBBEDp_2FAHp5VN/UR8Rze01vi1QznEq/IFGp5KCbRxuS4ai/8_2BVumAfCTkABHx47/WlsWb9fqA/6Mlrx68wl0mt/V HTTP/1.1\r\nAccept: */*\r\nHost: x1.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://cdn5.narutik.at/webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cdn5.narutik.at",
- "version": "1.1",
- "path": "/webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1",
- "data": "GET /webstore/w9HxPDpmiripcj8u/aO84jkcUP5Lr4s9/MIoeCMszz8_2B1CHDz/lTdXgfWeJ/PWs5HyKLxeKYKWQ7XxiI/dEZjlv1pdbGQvvQzdSL/NcvRt_2BFt_2BylLYeuuRC/JTBQXLtPViyda/_2FWH122/vrT1uI_2Fp3uZWHnd_2BQGA/zsPYIK5pMi/USzDdP_2B8zUGWoAD/WHVBzxSJrXfO/57To56myvu5/Y_2Bp_2B5euBph/AGW8md0qb4HlNsLEl9imP/hKVt1 HTTP/1.1\r\nAccept: */*\r\nHost: cdn5.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://cd.pranahat.at/webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cd.pranahat.at",
- "version": "1.1",
- "path": "/webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1",
- "data": "GET /webstore/xJRv3mG209UWr/Zwg3x6dc/gpZeczWpSZFLAC3E_2FLL6_/2BLxZUsuru/sKMet320RAp_2FJWK/y7W_2BTkw7lj/Jh9YB3kP3x_/2B0J6i_2BLe7cy/hr1m7ebBNFv2Zs09dEXAs/HXORivawWX_2F9Lu/MDV_2F_2BmrOMRq/T_2FDioaSJvFldOhnC/MNXNRJDZo/dRyYqHPXG_2Br7vHQVGr/dq4m_2FzWxKUPVHtcgd/QAVvkndpXkcif8KetFz1Uk/XiIWtgVhbl/1 HTTP/1.1\r\nAccept: */*\r\nHost: cd.pranahat.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://x1.narutik.at/webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "x1.narutik.at",
- "version": "1.1",
- "path": "/webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy",
- "data": "GET /webstore/hO04_2Bn/1TcaxHZmBD9CBzS5QYGZ9S1/HTvqKIg8xz/7LJhO8eOEykBDS7lD/7cx7QWUuTi91/1z1ZAZnQ1Lc/UU6e2iSo7m_2Bo/qpy_2F0N9Jw_2BMIb6rsa/iUdRMyGG7hHd0HR5/CYS4TrJ_2Fjq8_2/BGXiZCjlSfE0u5RUDA/zNkfii_2F/oioY9vvq3QWdYIztI8cT/cNYHKZp0df3s1LCHL8c/jM8hQSsmp/1yeDmy HTTP/1.1\r\nAccept: */*\r\nHost: x1.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://cdn5.narutik.at/webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cdn5.narutik.at",
- "version": "1.1",
- "path": "/webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8",
- "data": "GET /webstore/w5_2FjZe3FHmUdMiSvsL/ohpSKSytFSed7HX9ikb/peOk0vZtQC6g2sMN_2BC5P/ne5BasD0qLCn_/2Bb1sCFB/3hXwBekCKbwlckrwDmasm75/FpmUAzfZPs/Z79q9LEdevlILmUXq/QU4fwuCoKVbw/nLwAHYq8pHa/NJj35JvrGXMZtK/O2APcZEzlEbc9zsiBUK1I/NV27qMTGkc1IQIop/EQdYz_2FsXpsBlD/8 HTTP/1.1\r\nAccept: */*\r\nHost: cdn5.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://cd.pranahat.at/webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cd.pranahat.at",
- "version": "1.1",
- "path": "/webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T",
- "data": "GET /webstore/ZdmWvLeEvviNotG/DK5DD0SUov8iBODYOc/Iel6iK6Vo/Z4DNpeZqRM6DLbrcJkGc/xwQK497dRX78RuMTTxD/SIux0U2v2jZ8R7S_2BDGWO/r4Xx8osYxsAuq/oHvBW8_2/BfkH3AbapDYe3CCpf5bFbd1/_2FfNhDcv0/TNyZAUJw5dPStXYEA/RywFC1vYe_2F/1bVJyFO3ioV/pD7CoVvZoasUZ0/17c8gqYQDHYM_2BySTsGb/Uio5vLv4_2/FmS6T HTTP/1.1\r\nAccept: */*\r\nHost: cd.pranahat.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://x1.narutik.at/webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "x1.narutik.at",
- "version": "1.1",
- "path": "/webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu",
- "data": "GET /webstore/lkcIZuvFxBzh/OgzwcqXyn4G/oNHmhof7MATfbc/rirN85_2FcNxwfZqi2pGF/Boj_2FiaKK807nwC/cbvQzooTZ5yvSwb/fG6jkBleHhUQG9A6g4/7BhDyZS23/H2ZdUarm_2BD3b33FqCd/kdG7HwsxZNpCGWDDIu_/2F4sjpN21u6rYTLf_2Fl1x/2hb1RppqlRif_/2F9oTIwS/uPZnDof1JhMT0J86Yn4ywa5/OO6j90GIsn/bnB4p31dKIC/GfS_2Fu HTTP/1.1\r\nAccept: */*\r\nHost: x1.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://cdn5.narutik.at/webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cdn5.narutik.at",
- "version": "1.1",
- "path": "/webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d",
- "data": "GET /webstore/caUZtecUHzKuTSNvuaD4pe/QMIrbg22Iav2D/lQXKFwTH/xj2SUS_2B_2BIBqNLCmfULo/4XW61Itknb/1Mc2ouCew1bisRUWD/x3hcTjXt1kbo/iAT0_2FXtHV/VHegfLRY_2Froz/6WdNvqLPi_2FWSFSk1Tjy/69iBuUaHXWL0jFzq/_2F88UewK2qfi9Q/onZS3sa1OvmvJDWTS7/UEu_2Ffgr/iQKEjnx3Ko61GieNYDYX/D2U1z6TJYjh/AIfWJN2e/d HTTP/1.1\r\nAccept: */*\r\nHost: cdn5.narutik.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://cd.pranahat.at/webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cd.pranahat.at",
- "version": "1.1",
- "path": "/webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG",
- "data": "GET /webstore/NywFmBjPi_2FJBPX02LU6V6/dcaWlV5AsX/FNdymZgkWpwl0woKU/LY8unisF0znV/61rrorZsLrr/lgXohiA8LlR_2B/o6S9UjmzdBCxn_2F0eteG/pJzvTJMU1ByZTm5d/ik_2BwyN8YZ6f2F/6HGe4kk8xiWMjTyMYa/4N8CcXJoi/UE4qihkNR3AX1FfZZLUx/_2BbdPHULC1JfWgUbLB/HQZfl0MhIsrMdAUkA3xZfn/s_2Bq4iTmh836rjKW/RmG HTTP/1.1\r\nAccept: */*\r\nHost: cd.pranahat.at\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nAccept-Encoding: gzip, deflate\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment