paladin316

Exes_5573a44318d7a66f4a5aa71f96d58e26_exe_2019-07-18_06_30.txt

Jul 18th, 2019
2,497
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 154.88 KB | None | 0 0
  1.  
  2. * MalFamily: "TrojanDropper"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_5573a44318d7a66f4a5aa71f96d58e26.exe"
  7. * File Size: 1599488
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  9. * SHA256: "3ff33d1af25af8ef9269f07c7a16cd328a20e9848c73bf32032433d2d0040aef"
  10. * MD5: "5573a44318d7a66f4a5aa71f96d58e26"
  11. * SHA1: "9b265fa08e7281e808f1525ba22f9246b8cbd1b2"
  12. * SHA512: "14878cbe53c45481bb8059981b4c9473d4cf38162503be233fb0fcdb327fcd563e1d68832de1cdca4dfdcb5e046abfe3085ee0ce6698cc6cd76dcd12396aff18"
  13. * CRC32: "89E94A9A"
  14. * SSDEEP: "49152:KI6Me8PMsDOFrVMY1TXDHie/PylDe+/Hn8rKsJwt4W:AfduY1TXbieXylDe+/H8rKsJwKW"
  15.  
  16. * Process Execution:
  17. "Exes_5573a44318d7a66f4a5aa71f96d58e26.exe",
  18. "WMIC.exe",
  19. "LDSGameMasterInstRoad_211101.exe",
  20. "ldsgamemaster.exe",
  21. "SoftMgrInst.exe",
  22. "inst_buychannel_40.exe",
  23. "VZip_724.exe",
  24. "VZipUpdate.exe",
  25. "regsvr32.exe",
  26. "regsvr32.exe",
  27. "services.exe",
  28. "svchost.exe",
  29. "WmiPrvSE.exe",
  30. "dllhost.exe",
  31. "VZipService.exe",
  32. "taskhost.exe"
  33.  
  34.  
  35. * Executed Commands:
  36. "wmic csproduct get UUID",
  37. "\"C:\\Users\\user\\AppData\\Local\\Temp\\LDSGameMasterInstRoad_211101.exe\"/S",
  38. "\"C:\\Users\\user\\AppData\\Local\\Temp\\inst_buychannel_40.exe\"/S",
  39. "\"C:\\Users\\user\\AppData\\Local\\Temp\\VZip_724.exe\"/S",
  40. "\"C:\\Users\\user\\AppData\\Local\\Temp\\6789zip_131.exe\"/S",
  41. "\"C:\\Users\\user\\AppData\\Local\\Temp\\FunInstaller_PS_0109801.exe\"/S",
  42. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  43. "C:\\Windows\\system32\\DllHost.exe /Processid:AB8902B4-09CA-4BB6-B78D-A8F59079A8D5",
  44. "C:\\Users\\user\\AppData\\Local\\Temp\\ldsgamemaster.exe /PID=\"211101\" /S /FROM=inst",
  45. "\"C:\\LDSGameMaster\\SoftMgr\\SoftMgrInst.exe\" --hwnd=262532 --from=LDSGameMaster --new=true --log",
  46. "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -inst_fix -startby=8",
  47. "regsvr32.exe /s \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
  48. "C:\\Windows\\system32\\regsvr32.exe /s \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
  49. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
  50. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  51. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -auto -startby=5"
  52.  
  53.  
  54. * Signatures Detected:
  55.  
  56. "Description": "Creates RWX memory",
  57. "Details":
  58.  
  59.  
  60. "Description": "Possible date expiration check, exits too soon after checking local time",
  61. "Details":
  62.  
  63. "process": "LDSGameMasterInstRoad_211101.exe, PID 2840"
  64.  
  65.  
  66.  
  67.  
  68. "Description": "Attempts to connect to a dead IP:Port (19 unique times)",
  69. "Details":
  70.  
  71. "IP": "118.193.104.9:80"
  72.  
  73.  
  74. "IP": "36.99.227.228:80"
  75.  
  76.  
  77. "IP": "103.25.35.81:80"
  78.  
  79.  
  80. "IP": "103.25.35.80:80"
  81.  
  82.  
  83. "IP": "115.28.112.133:80"
  84.  
  85.  
  86. "IP": "103.25.35.85:80"
  87.  
  88.  
  89. "IP": "104.192.108.21:80"
  90.  
  91.  
  92. "IP": "120.27.83.10:80"
  93.  
  94.  
  95. "IP": "103.25.35.77:80"
  96.  
  97.  
  98. "IP": "221.230.141.50:80"
  99.  
  100.  
  101. "IP": "123.125.82.104:80"
  102.  
  103.  
  104. "IP": "118.212.225.117:80"
  105.  
  106.  
  107. "IP": "221.230.141.50:443"
  108.  
  109.  
  110. "IP": "103.25.35.86:80"
  111.  
  112.  
  113. "IP": "157.185.164.73:443"
  114.  
  115.  
  116. "IP": "222.245.77.75:443"
  117.  
  118.  
  119. "IP": "72.21.91.29:80"
  120.  
  121.  
  122. "IP": "65.153.196.229:80"
  123.  
  124.  
  125. "IP": "114.115.221.211:80"
  126.  
  127.  
  128.  
  129.  
  130. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  131. "Details":
  132.  
  133. "ioc": "www.digicert.com1"
  134.  
  135.  
  136.  
  137.  
  138. "Description": "Expresses interest in specific running processes",
  139. "Details":
  140.  
  141. "process": "explorer.exe"
  142.  
  143.  
  144.  
  145.  
  146. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  147. "Details":
  148.  
  149.  
  150. "Description": "Reads data out of its own binary image",
  151. "Details":
  152.  
  153. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00000000, length: 0x00000150"
  154.  
  155.  
  156. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00000000, length: 0x00004000"
  157.  
  158.  
  159. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00000154, length: 0x000031f4"
  160.  
  161.  
  162. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00000198, length: 0x00005468"
  163.  
  164.  
  165. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00003348, length: 0x00008000"
  166.  
  167.  
  168. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00005600, length: 0x00008000"
  169.  
  170.  
  171. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0000b348, length: 0x00008000"
  172.  
  173.  
  174. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0000d600, length: 0x00008000"
  175.  
  176.  
  177. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00013348, length: 0x00008000"
  178.  
  179.  
  180. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00015600, length: 0x00008000"
  181.  
  182.  
  183. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0001b348, length: 0x00008000"
  184.  
  185.  
  186. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0001d600, length: 0x00008000"
  187.  
  188.  
  189. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00023348, length: 0x00008000"
  190.  
  191.  
  192. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00025600, length: 0x00008000"
  193.  
  194.  
  195. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0002b348, length: 0x00008000"
  196.  
  197.  
  198. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0002d600, length: 0x00008000"
  199.  
  200.  
  201. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00033348, length: 0x00008000"
  202.  
  203.  
  204. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00035600, length: 0x00008000"
  205.  
  206.  
  207. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0003b348, length: 0x00008000"
  208.  
  209.  
  210. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0003d600, length: 0x00008000"
  211.  
  212.  
  213. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00043348, length: 0x00008000"
  214.  
  215.  
  216. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00045600, length: 0x00008000"
  217.  
  218.  
  219. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0004b348, length: 0x00008000"
  220.  
  221.  
  222. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0004d600, length: 0x00008000"
  223.  
  224.  
  225. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00053348, length: 0x00010000"
  226.  
  227.  
  228. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00055600, length: 0x00010000"
  229.  
  230.  
  231. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00063348, length: 0x00010000"
  232.  
  233.  
  234. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00065600, length: 0x00010000"
  235.  
  236.  
  237. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00073348, length: 0x00010000"
  238.  
  239.  
  240. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00075600, length: 0x00010000"
  241.  
  242.  
  243. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00083348, length: 0x00010000"
  244.  
  245.  
  246. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00085600, length: 0x00018000"
  247.  
  248.  
  249. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0009b348, length: 0x00010000"
  250.  
  251.  
  252. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0009d600, length: 0x00010000"
  253.  
  254.  
  255. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x000ab348, length: 0x00010000"
  256.  
  257.  
  258. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x000ad600, length: 0x00010000"
  259.  
  260.  
  261. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x000bb348, length: 0x00010000"
  262.  
  263.  
  264. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x000bd600, length: 0x00004000"
  265.  
  266.  
  267. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x000cb348, length: 0x00030000"
  268.  
  269.  
  270. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00103348, length: 0x000d0000"
  271.  
  272.  
  273. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x001e3348, length: 0x000d0000"
  274.  
  275.  
  276. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x002b3df4, length: 0x00004000"
  277.  
  278.  
  279. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x00333348, length: 0x000e8008"
  280.  
  281.  
  282. "self_read": "process: ldsgamemaster.exe, pid: 1708, offset: 0x0041b2b8, length: 0x000002a0"
  283.  
  284.  
  285. "self_read": "process: VZip_724.exe, pid: 3024, offset: 0x00000000, length: 0x00199200"
  286.  
  287.  
  288. "self_read": "process: VZip_724.exe, pid: 3024, offset: 0x0004901c, length: 0x00198000"
  289.  
  290.  
  291. "self_read": "process: VZip_724.exe, pid: 3024, offset: 0x00199200, length: 0x00263c93"
  292.  
  293.  
  294. "self_read": "process: VZip_724.exe, pid: 3024, offset: 0x001e101c, length: 0x0021be7b"
  295.  
  296.  
  297.  
  298.  
  299. "Description": "A process created a hidden window",
  300. "Details":
  301.  
  302. "Process": "VZipUpdate.exe -> regsvr32.exe"
  303.  
  304.  
  305.  
  306.  
  307. "Description": "Drops a binary and executes it",
  308. "Details":
  309.  
  310. "binary": "C:\\LDSGameMaster\\SoftMgr\\SoftMgrInst.exe"
  311.  
  312.  
  313. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\LDSGameMasterInstRoad_211101.exe"
  314.  
  315.  
  316. "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  317.  
  318.  
  319. "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
  320.  
  321.  
  322. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\inst_buychannel_40.exe"
  323.  
  324.  
  325. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\ldsgamemaster.exe"
  326.  
  327.  
  328. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\VZip_724.exe"
  329.  
  330.  
  331.  
  332.  
  333. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  334. "Details":
  335.  
  336. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  337.  
  338.  
  339. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  340.  
  341.  
  342. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  343.  
  344.  
  345. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  346.  
  347.  
  348. "suspicious_request": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  349.  
  350.  
  351. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  352.  
  353.  
  354. "suspicious_request": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe"
  355.  
  356.  
  357. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  358.  
  359.  
  360. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  361.  
  362.  
  363. "suspicious_request": "http://s.ludashi.com/mgame?type=instonline&action=run&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  364.  
  365.  
  366. "suspicious_request": "http://dl.360safe.com/ludashi/inst_buychannel_40.exe"
  367.  
  368.  
  369. "suspicious_request": "http://s.ludashi.com/mgame?type=instonline&action=down_start&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  370.  
  371.  
  372. "suspicious_request": "http://dl.ludashi.com/gamemaster/buychannelFull.exe"
  373.  
  374.  
  375. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  376.  
  377.  
  378. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  379.  
  380.  
  381. "suspicious_request": "http://dl.360safe.com/ludashi/ludashi_buy.exe"
  382.  
  383.  
  384. "suspicious_request": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  385.  
  386.  
  387. "suspicious_request": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  388.  
  389.  
  390. "suspicious_request": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe"
  391.  
  392.  
  393. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  394.  
  395.  
  396. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  397.  
  398.  
  399. "suspicious_request": "http://s.ludashi.com/mgame?type=instonline&action=down_success&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  400.  
  401.  
  402. "suspicious_request": "http://s.ludashi.com/mgame?type=instonline&action=down_exec&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  403.  
  404.  
  405. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=run&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  406.  
  407.  
  408. "suspicious_request": "http://zhushou.ludashi.com/game/Getloadernew?channel_num=211101&subpid=211101&from=inst&version=5.1.2047.2030&existsver=&osver=6.1&iever=8.0.7601.17514&ids=&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&motion="
  409.  
  410.  
  411. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=osver_6.1&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  412.  
  413.  
  414. "suspicious_request": "http://l.public.ludashi.com/pc/udmgame/dogSun"
  415.  
  416.  
  417. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=newinstall&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133620903&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  418.  
  419.  
  420. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=start_install&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133642153&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  421.  
  422.  
  423. "suspicious_request": "http://zhushou.ludashi.com/cms/shouyou/bizhi/lua.php?channel_num=211101&subpid=211101&from=inst&version=8.0.7601.17514&osver=6.1&iever=8.0.7601.17514&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  424.  
  425.  
  426. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=install_default&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133733543&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  427.  
  428.  
  429. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_start&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133735387&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  430.  
  431.  
  432. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  433.  
  434.  
  435. "suspicious_request": "http://cdn-file-ssl-monidashi.ludashi.com/gamemaster/pushfile/201907162222.file"
  436.  
  437.  
  438. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_fail&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  439.  
  440.  
  441. "suspicious_request": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_fail_0&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  442.  
  443.  
  444. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  445.  
  446.  
  447. "suspicious_request": "http://47.96.116.228:8081/api/recorder/install?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  448.  
  449.  
  450. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D"
  451.  
  452.  
  453. "suspicious_request": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D"
  454.  
  455.  
  456. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  457.  
  458.  
  459. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  460.  
  461.  
  462. "suspicious_request": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0"
  463.  
  464.  
  465. "suspicious_request": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe"
  466.  
  467.  
  468. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  469.  
  470.  
  471. "suspicious_request": "http://neirong.funshion.com/tools/acceconfig.ini"
  472.  
  473.  
  474. "suspicious_request": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16600*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  475.  
  476.  
  477. "suspicious_request": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=19000*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  478.  
  479.  
  480. "suspicious_request": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  481.  
  482.  
  483. "suspicious_request": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  484.  
  485.  
  486. "suspicious_request": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16204*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  487.  
  488.  
  489. "suspicious_request": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16706*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  490.  
  491.  
  492. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  493.  
  494.  
  495. "suspicious_request": "http://down1.wallpaper.shqingzao.com/install/qid/kb_001/CalfWallpaper_2244256949_kb_001.exe"
  496.  
  497.  
  498. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  499.  
  500.  
  501. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=8&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  502.  
  503.  
  504. "suspicious_request": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe"
  505.  
  506.  
  507. "suspicious_request": "http://report.wallpaper.shqingzao.com/wallpaper/online?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1"
  508.  
  509.  
  510. "suspicious_request": "http://report.wallpaper.shqingzao.com/wallpaper/install?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1nriJHnh3WVmnJ4dUA2EnP+dJzGBt0NGm7hfURH06a1CxrXb/sgILYpSRi8AMlmXXVUFORpcSQ8O4KBCmpPD7bezFaaE8zx26adAwfYprlNZsYaDiAsvBM+q6"
  511.  
  512.  
  513. "suspicious_request": "http://down1.wallpaper.shqingzao.com/report/queryinfo.xml"
  514.  
  515.  
  516. "suspicious_request": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN3objBfiZnZwXxQJoLWSEVC90Lo2IjtbTEmGyKAhtVMAKS1xWK3jhDN63kouYE9QrWbDQ="
  517.  
  518.  
  519. "suspicious_request": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CNzob20bQNbT0akArkIXyE6DuBY+DMxkJDL6xHdDAwxS3mxrXb+4CwGZvTiidIMlmXWIExTSooiApPQK0Gi"
  520.  
  521.  
  522. "suspicious_request": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CM8/unvVgRrCAXxDL52LUsZf7IL7xQXpr/L6xHdDBEVdUKB8gSUw1dDNw=="
  523.  
  524.  
  525. "suspicious_request": "http://www.msftncsi.com/ncsi.txt"
  526.  
  527.  
  528.  
  529.  
  530. "Description": "Performs some HTTP requests",
  531. "Details":
  532.  
  533. "url": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  534.  
  535.  
  536. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  537.  
  538.  
  539. "url": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe"
  540.  
  541.  
  542. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  543.  
  544.  
  545. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  546.  
  547.  
  548. "url": "http://s.ludashi.com/mgame?type=instonline&action=run&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  549.  
  550.  
  551. "url": "http://dl.360safe.com/ludashi/inst_buychannel_40.exe"
  552.  
  553.  
  554. "url": "http://s.ludashi.com/mgame?type=instonline&action=down_start&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  555.  
  556.  
  557. "url": "http://dl.ludashi.com/gamemaster/buychannelFull.exe"
  558.  
  559.  
  560. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  561.  
  562.  
  563. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  564.  
  565.  
  566. "url": "http://dl.360safe.com/ludashi/ludashi_buy.exe"
  567.  
  568.  
  569. "url": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  570.  
  571.  
  572. "url": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  573.  
  574.  
  575. "url": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe"
  576.  
  577.  
  578. "url": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  579.  
  580.  
  581. "url": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  582.  
  583.  
  584. "url": "http://s.ludashi.com/mgame?type=instonline&action=down_success&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  585.  
  586.  
  587. "url": "http://s.ludashi.com/mgame?type=instonline&action=down_exec&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030"
  588.  
  589.  
  590. "url": "http://s.ludashi.com/mgame?type=installpkg&action=run&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  591.  
  592.  
  593. "url": "http://zhushou.ludashi.com/game/Getloadernew?channel_num=211101&subpid=211101&from=inst&version=5.1.2047.2030&existsver=&osver=6.1&iever=8.0.7601.17514&ids=&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&motion="
  594.  
  595.  
  596. "url": "http://s.ludashi.com/mgame?type=installpkg&action=osver_6.1&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  597.  
  598.  
  599. "url": "http://l.public.ludashi.com/pc/udmgame/dogSun"
  600.  
  601.  
  602. "url": "http://s.ludashi.com/mgame?type=installpkg&action=newinstall&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133620903&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  603.  
  604.  
  605. "url": "http://s.ludashi.com/mgame?type=installpkg&action=start_install&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133642153&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  606.  
  607.  
  608. "url": "http://zhushou.ludashi.com/cms/shouyou/bizhi/lua.php?channel_num=211101&subpid=211101&from=inst&version=8.0.7601.17514&osver=6.1&iever=8.0.7601.17514&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  609.  
  610.  
  611. "url": "http://s.ludashi.com/mgame?type=installpkg&action=install_default&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133733543&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  612.  
  613.  
  614. "url": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_start&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133735387&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  615.  
  616.  
  617. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  618.  
  619.  
  620. "url": "http://cdn-file-ssl-monidashi.ludashi.com/gamemaster/pushfile/201907162222.file"
  621.  
  622.  
  623. "url": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_fail&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  624.  
  625.  
  626. "url": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_fail_0&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e"
  627.  
  628.  
  629. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  630.  
  631.  
  632. "url": "http://47.96.116.228:8081/api/recorder/install?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  633.  
  634.  
  635. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D"
  636.  
  637.  
  638. "url": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D"
  639.  
  640.  
  641. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  642.  
  643.  
  644. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  645.  
  646.  
  647. "url": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0"
  648.  
  649.  
  650. "url": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe"
  651.  
  652.  
  653. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  654.  
  655.  
  656. "url": "http://neirong.funshion.com/tools/acceconfig.ini"
  657.  
  658.  
  659. "url": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16600*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  660.  
  661.  
  662. "url": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=19000*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  663.  
  664.  
  665. "url": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  666.  
  667.  
  668. "url": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6"
  669.  
  670.  
  671. "url": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16204*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  672.  
  673.  
  674. "url": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16706*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056"
  675.  
  676.  
  677. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  678.  
  679.  
  680. "url": "http://down1.wallpaper.shqingzao.com/install/qid/kb_001/CalfWallpaper_2244256949_kb_001.exe"
  681.  
  682.  
  683. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  684.  
  685.  
  686. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=8&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  687.  
  688.  
  689. "url": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe"
  690.  
  691.  
  692. "url": "http://report.wallpaper.shqingzao.com/wallpaper/online?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1"
  693.  
  694.  
  695. "url": "http://report.wallpaper.shqingzao.com/wallpaper/install?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1nriJHnh3WVmnJ4dUA2EnP+dJzGBt0NGm7hfURH06a1CxrXb/sgILYpSRi8AMlmXXVUFORpcSQ8O4KBCmpPD7bezFaaE8zx26adAwfYprlNZsYaDiAsvBM+q6"
  696.  
  697.  
  698. "url": "http://down1.wallpaper.shqingzao.com/report/queryinfo.xml"
  699.  
  700.  
  701. "url": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN3objBfiZnZwXxQJoLWSEVC90Lo2IjtbTEmGyKAhtVMAKS1xWK3jhDN63kouYE9QrWbDQ="
  702.  
  703.  
  704. "url": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CNzob20bQNbT0akArkIXyE6DuBY+DMxkJDL6xHdDAwxS3mxrXb+4CwGZvTiidIMlmXWIExTSooiApPQK0Gi"
  705.  
  706.  
  707. "url": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CM8/unvVgRrCAXxDL52LUsZf7IL7xQXpr/L6xHdDBEVdUKB8gSUw1dDNw=="
  708.  
  709.  
  710. "url": "http://www.msftncsi.com/ncsi.txt"
  711.  
  712.  
  713.  
  714.  
  715. "Description": "Unconventionial language used in binary resources: Chinese (Simplified)",
  716. "Details":
  717.  
  718.  
  719. "Description": "The binary likely contains encrypted or compressed data.",
  720. "Details":
  721.  
  722. "section": "name: UPX1, entropy: 7.91, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0016ec00, virtual_size: 0x0016f000"
  723.  
  724.  
  725.  
  726.  
  727. "Description": "The executable is compressed using UPX",
  728. "Details":
  729.  
  730. "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0039c000"
  731.  
  732.  
  733.  
  734.  
  735. "Description": "Queries information on disks, possibly for anti-virtualization",
  736. "Details":
  737.  
  738.  
  739. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  740. "Details":
  741.  
  742. "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  743.  
  744.  
  745. "Process": "VZipService.exe tried to sleep 12600 seconds, actually delayed analysis time by 0 seconds"
  746.  
  747.  
  748. "Process": "Exes_5573a44318d7a66f4a5aa71f96d58e26.exe tried to sleep 291 seconds, actually delayed analysis time by 0 seconds"
  749.  
  750.  
  751.  
  752.  
  753. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  754. "Details":
  755.  
  756. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 457163 times"
  757.  
  758.  
  759.  
  760.  
  761. "Description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
  762. "Details":
  763.  
  764. "regkeyval": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\lua_push"
  765.  
  766.  
  767.  
  768.  
  769. "Description": "Network activity contains more than one unique useragent.",
  770. "Details":
  771.  
  772. "Process": "Exes_5573a44318d7a66f4a5aa71f96d58e26.exe"
  773.  
  774.  
  775. "User-Agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)"
  776.  
  777.  
  778. "Process": "LDSGameMasterInstRoad_211101.exe"
  779.  
  780.  
  781. "User-Agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)"
  782.  
  783.  
  784. "Process": "ldsgamemaster.exe"
  785.  
  786.  
  787. "User-Agent": ""
  788.  
  789.  
  790.  
  791.  
  792. "Description": "Installs itself for autorun at Windows startup",
  793. "Details":
  794.  
  795. "service name": "VZipService"
  796.  
  797.  
  798. "service path": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
  799.  
  800.  
  801. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\(Default)"
  802.  
  803.  
  804. "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll"
  805.  
  806.  
  807.  
  808.  
  809. "Description": "Collects information about installed applications",
  810. "Details":
  811.  
  812. "Program": "Google Update Helper"
  813.  
  814.  
  815. "Program": "Microsoft Excel MUI 2013"
  816.  
  817.  
  818. "Program": "Microsoft Outlook MUI 2013"
  819.  
  820.  
  821.  
  822.  
  823. "Program": "Google Chrome"
  824.  
  825.  
  826. "Program": "Adobe Flash Player 29 NPAPI"
  827.  
  828.  
  829. "Program": "Adobe Flash Player 29 ActiveX"
  830.  
  831.  
  832. "Program": "Microsoft DCF MUI 2013"
  833.  
  834.  
  835. "Program": "Microsoft Access MUI 2013"
  836.  
  837.  
  838. "Program": "Microsoft Office Proofing Tools 2013 - English"
  839.  
  840.  
  841. "Program": "Adobe Acrobat Reader DC"
  842.  
  843.  
  844. "Program": "Microsoft Publisher MUI 2013"
  845.  
  846.  
  847. "Program": "Microsoft Office Shared MUI 2013"
  848.  
  849.  
  850. "Program": "Microsoft Office OSM MUI 2013"
  851.  
  852.  
  853. "Program": "Microsoft InfoPath MUI 2013"
  854.  
  855.  
  856. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  857.  
  858.  
  859. "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
  860.  
  861.  
  862. "Program": "Microsoft Word MUI 2013"
  863.  
  864.  
  865. "Program": "Microsoft Groove MUI 2013"
  866.  
  867.  
  868. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
  869.  
  870.  
  871.  
  872.  
  873. "Program": "Microsoft Access Setup Metadata MUI 2013"
  874.  
  875.  
  876. "Program": "Microsoft Office OSM UX MUI 2013"
  877.  
  878.  
  879. "Program": "Java Auto Updater"
  880.  
  881.  
  882. "Program": "Microsoft PowerPoint MUI 2013"
  883.  
  884.  
  885. "Program": "Microsoft Office Professional Plus 2013"
  886.  
  887.  
  888. "Program": "Adobe Refresh Manager"
  889.  
  890.  
  891. "Program": "Microsoft Office Proofing 2013"
  892.  
  893.  
  894. "Program": "Microsoft Lync MUI 2013"
  895.  
  896.  
  897.  
  898.  
  899. "Program": "Microsoft OneNote MUI 2013"
  900.  
  901.  
  902.  
  903.  
  904. "Description": "File has been identified by 33 Antiviruses on VirusTotal as malicious",
  905. "Details":
  906.  
  907. "MicroWorld-eScan": "Trojan.GenericKD.32121116"
  908.  
  909.  
  910. "FireEye": "Trojan.GenericKD.32121116"
  911.  
  912.  
  913. "CAT-QuickHeal": "TrojanDropper.Agent"
  914.  
  915.  
  916. "McAfee": "Artemis!5573A44318D7"
  917.  
  918.  
  919. "Cylance": "Unsafe"
  920.  
  921.  
  922. "K7GW": "Riskware ( 0040eff71 )"
  923.  
  924.  
  925. "K7AntiVirus": "Riskware ( 0040eff71 )"
  926.  
  927.  
  928. "Arcabit": "Trojan.Generic.D1EA211C"
  929.  
  930.  
  931. "Symantec": "Trojan.Gen.MBT"
  932.  
  933.  
  934. "Kaspersky": "Trojan-Dropper.Win32.Agent.bjynhm"
  935.  
  936.  
  937. "BitDefender": "Trojan.GenericKD.32121116"
  938.  
  939.  
  940. "Avast": "Win32:Malware-gen"
  941.  
  942.  
  943. "Tencent": "Win32.Trojan-dropper.Agent.Svhj"
  944.  
  945.  
  946. "Ad-Aware": "Trojan.GenericKD.32121116"
  947.  
  948.  
  949. "Emsisoft": "Trojan.GenericKD.32121116 (B)"
  950.  
  951.  
  952. "TrendMicro": "TROJ_GEN.R002C0WGF19"
  953.  
  954.  
  955. "McAfee-GW-Edition": "BehavesLike.Win32.Dropper.tc"
  956.  
  957.  
  958. "Sophos": "Mal/Generic-S"
  959.  
  960.  
  961. "Antiy-AVL": "TrojanDropper/Win32.Agent"
  962.  
  963.  
  964. "Microsoft": "PUA:Win32/Puamson.A!ml"
  965.  
  966.  
  967. "AegisLab": "Trojan.Win32.Agent.4!c"
  968.  
  969.  
  970. "ZoneAlarm": "Trojan-Dropper.Win32.Agent.bjynhm"
  971.  
  972.  
  973. "GData": "Trojan.GenericKD.32121116"
  974.  
  975.  
  976. "AhnLab-V3": "Malware/Gen.Generic.C3320517"
  977.  
  978.  
  979. "ALYac": "Trojan.GenericKD.32121116"
  980.  
  981.  
  982. "MAX": "malware (ai score=99)"
  983.  
  984.  
  985. "TrendMicro-HouseCall": "TROJ_GEN.R002C0WGF19"
  986.  
  987.  
  988. "Rising": "Dropper.Agent!8.2F (TFE:5:FfoKNBWXTLE)"
  989.  
  990.  
  991. "Fortinet": "W32/Agent.BJYNHM!tr"
  992.  
  993.  
  994. "AVG": "Win32:Malware-gen"
  995.  
  996.  
  997. "Panda": "Trj/GdSda.A"
  998.  
  999.  
  1000. "CrowdStrike": "win/malicious_confidence_60% (W)"
  1001.  
  1002.  
  1003. "Qihoo-360": "HEUR/QVM11.1.448D.Malware.Gen"
  1004.  
  1005.  
  1006.  
  1007.  
  1008.  
  1009. * Started Service:
  1010. "VZipService",
  1011. "WerSvc"
  1012.  
  1013.  
  1014. * Mutexes:
  1015. "CicLoadWinStaWinSta0",
  1016. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  1017. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2840",
  1018. "GameMasterInstMutextName",
  1019. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2688",
  1020. "Q360ComputerzInstMutextName",
  1021. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 1708",
  1022. "LDSGameMasterSetupMutext",
  1023. "Global\\PushWinAppsMutex@LdsGameMasterInstaller",
  1024. "1830B7BD-F7A3-4c4d-989B-C004DE465EDE 2892",
  1025. "Instance_CE66C680-A468-4bc7-8975-A55F72B8FC60",
  1026. "LdsSoftMgrInstMutex_LDSGameMaster",
  1027. "LOCALLOG",
  1028. "Local\\ComputerZSoftMgrInstFileMutex",
  1029. "VZip_install",
  1030. "Global\\846B0D787F8CC6D5",
  1031. "VZip_Fix",
  1032. "06FA88EC1CA2B88D"
  1033.  
  1034.  
  1035. * Modified Files:
  1036. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\LDSGameMasterInstRoad_2111011.exe",
  1037. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\inst_buychannel_401.exe",
  1038. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\VZip_7241.exe",
  1039. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D",
  1040. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D",
  1041. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C8551E3A51B70BA2C25E09D550E69370",
  1042. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\C8551E3A51B70BA2C25E09D550E69370",
  1043. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\6789zip_1311.exe",
  1044. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\FunInstaller_PS_01098011.exe",
  1045. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\CalfWallpaper_2244256949_kb_0011.exe",
  1046. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  1047. "\\??\\WMIDataDevice",
  1048. "\\??\\PhysicalDrive0",
  1049. "\\??\\8C8DAC1D-0390-4B59-BF93-EC6C9E68D36A",
  1050. "C:\\Users\\user\\AppData\\Local\\Temp\\434B7005-2346-429b-9228-F1E1F4EAD39F.tf",
  1051. "C:\\Users\\user\\AppData\\Local\\Temp\\ludA144.tmp",
  1052. "C:\\Users\\user\\AppData\\Local\\Temp\\360Base.dll",
  1053. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\mgame1.txt",
  1054. "C:\\Users\\user\\AppData\\Local\\Temp\\F64B8B9B-5A20-450d-8CE2-0E1DB0B9EF1C.tf",
  1055. "C:\\Users\\user\\AppData\\Local\\Temp\\ludA9C0.tmp",
  1056. "C:\\Users\\user\\AppData\\Local\\Temp\\360net.dll",
  1057. "C:\\Users\\user\\AppData\\Local\\Temp\\C9001433-BB6A-4e5f-86C5-F9A8CA29A691.tf",
  1058. "C:\\Users\\user\\AppData\\Local\\Temp\\ldsgamemaster.exe",
  1059. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\mgame1.txt",
  1060. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\mgame1.txt",
  1061. "C:\\Users\\user\\AppData\\Local\\Temp\\5ED86E76-1AD7-43b9-91CE-040BCA16F182.tf",
  1062. "C:\\Users\\user\\AppData\\Local\\Temp\\ludCAE4.tmp",
  1063. "C:\\Users\\user\\AppData\\Local\\Temp\\CBF8BCF9-34DC-4f29-9FEF-989E5A7310B3.tf",
  1064. "C:\\Users\\user\\AppData\\Local\\Temp\\ludCC7B.tmp",
  1065. "C:\\Users\\user\\AppData\\Local\\Temp\\129F9D08-4428-452a-899E-099105FC4EBD.tf",
  1066. "C:\\Users\\user\\AppData\\Local\\Temp\\ludashisetup.exe",
  1067. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url21.txt",
  1068. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url22.txt",
  1069. "C:\\Users\\user\\AppData\\Local\\Temp\\41785576-1855-448b-8919-DCA04B0F6050.tf",
  1070. "C:\\Users\\user\\AppData\\Local\\Temp\\51953E1C-2BF3-4a5d-BF20-90CA104C19A8.tmp",
  1071. "C:\\Users\\user\\AppData\\Local\\Temp\\5502793B-9F92-493c-B778-9B1C9469D707.tmp\\7z.dll",
  1072. "C:\\Users\\user\\AppData\\Local\\Temp\\7775FB50-8A34-47d6-A8E0-9A4AA68F4905.tmp",
  1073. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp\\360Base.dll",
  1074. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp\\360NetUL.dll",
  1075. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp\\Utils\\LDSBasic.dll",
  1076. "C:\\Users\\user\\AppData\\Roaming\\360NetUL\\ldsgamemaster.netul.log",
  1077. "C:\\Users\\user\\AppData\\Local\\LDSGameMaster\\Store\\360Base.dll",
  1078. "C:\\Users\\user\\AppData\\Local\\LDSGameMaster\\Store\\360NetUL.dll",
  1079. "C:\\Users\\user\\AppData\\Local\\LDSGameMaster\\Store\\Utils\\LdsBasic.dll",
  1080. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\9AE3C9BA-B6E3-47ad-88E2-CE20DAD3B091.tf",
  1081. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360Base.dll",
  1082. "C:\\Users\\user\\AppData\\Local\\Temp\\9DD32CB0-9916-4418-BF3B-70F0AAA45E5C.tmp",
  1083. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp\\FileList.xml",
  1084. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp\\LDSGAMEMASTER.LDSPRJ",
  1085. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp\\UninstallRootDirFileList.xml",
  1086. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360Net.dll",
  1087. "C:\\LDSGameMaster\\3FFAB69C-FFB3-4642-86CB-7E405AF52317.tf",
  1088. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360NetBase.dll",
  1089. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360NetUL.dll",
  1090. "C:\\LDSGameMaster\\A99108B0-678B-4103-B91F-83F2880692D2.tf",
  1091. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360P2SP.dll",
  1092. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\mgame1.txt",
  1093. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\LiveUpd360.dll",
  1094. "C:\\LDSGameMaster\\A3A8AE07-E463-4894-BC1F-F76D2DDCD87E.tf",
  1095. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\PDown.dll",
  1096. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\SoftMgr\\SoftMgrInst.exe",
  1097. "C:\\LDSGameMaster\\D2ECED36-7EFA-4de4-998D-4C18373EEACF.tf",
  1098. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\Utils\\LDSBasic.dll",
  1099. "C:\\LDSGameMaster\\5371F23D-E86C-4498-8AC9-B249B3757A7B.tf",
  1100. "C:\\LDSGameMaster\\gamemaster_setup.log",
  1101. "C:\\Users\\user\\AppData\\Local\\GDIPFONTCACHEV1.DAT",
  1102. "C:\\LDSGameMaster\\360Base.dll",
  1103. "C:\\LDSGameMaster\\360Net.dll",
  1104. "C:\\LDSGameMaster\\360NetBase.dll",
  1105. "C:\\LDSGameMaster\\360NetUL.dll",
  1106. "C:\\LDSGameMaster\\360P2SP.dll",
  1107. "C:\\LDSGameMaster\\LiveUpd360.dll",
  1108. "C:\\LDSGameMaster\\PDown.dll",
  1109. "C:\\LDSGameMaster\\SoftMgr\\SoftMgrInst.exe",
  1110. "C:\\LDSGameMaster\\Utils\\LDSBasic.dll",
  1111. "C:\\LDSGameMaster\\7z.dll",
  1112. "C:\\LDSGameMaster\\ComputerZ.set",
  1113. "C:\\Users\\user\\AppData\\Roaming\\Ludashi\\softmgr\\SoftMgrInst.ini",
  1114. "C:\\LDSGameMaster\\Downloads\\Temp\\ldssoftmgrinst_testdir.dat",
  1115. "C:\\Users\\user\\AppData\\Local\\Temp\\nsz1EB2.tmp",
  1116. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1EC3.tmp\\InstHlp.dll",
  1117. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1EC3.tmp\\System.dll",
  1118. "C:\\Users\\user\\AppData\\Local\\VZip\\Uninst.exe",
  1119. "C:\\Users\\user\\AppData\\Local\\VZip\\VZip.exe",
  1120. "C:\\Users\\user\\AppData\\Local\\VZip\\VZip2.exe",
  1121. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern.dll",
  1122. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll",
  1123. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipKernel.dll",
  1124. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniNews.exe",
  1125. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniTray.exe",
  1126. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipPd.dll",
  1127. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
  1128. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe",
  1129. "C:\\Users\\user\\AppData\\Local\\VZip\\zip.sfx",
  1130. "C:\\Users\\user\\AppData\\Local\\VZip\\Lang\\en.ttt",
  1131. "C:\\Users\\user\\AppData\\Local\\VZip\\Lang\\zh-cn.txt",
  1132. "\\??\\PIPE\\srvsvc",
  1133. "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9\\ \\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
  1134. "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9\\\\xc3\\x90\\xc2\\xb6\\xc3\\x94\\xc3\\x98 \\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
  1135. "C:\\Users\\Public\\Desktop\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
  1136. "C:\\Users\\user\\AppData\\Local\\Temp\\service_temp_report",
  1137. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8"
  1138.  
  1139.  
  1140. * Deleted Files:
  1141. "C:\\Users\\user\\AppData\\Local\\Temp\\434B7005-2346-429b-9228-F1E1F4EAD39F.tf",
  1142. "C:\\Users\\user\\AppData\\Local\\Temp\\ludA144.tmp",
  1143. "C:\\Users\\user\\AppData\\Local\\Temp\\360Base.dll",
  1144. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\mgame1.txt",
  1145. "C:\\Users\\user\\AppData\\Local\\Temp\\F64B8B9B-5A20-450d-8CE2-0E1DB0B9EF1C.tf",
  1146. "C:\\Users\\user\\AppData\\Local\\Temp\\ludA9C0.tmp",
  1147. "C:\\Users\\user\\AppData\\Local\\Temp\\360net.dll",
  1148. "C:\\Users\\user\\AppData\\Local\\Temp\\C9001433-BB6A-4e5f-86C5-F9A8CA29A691.tf",
  1149. "C:\\Users\\user\\AppData\\Local\\Temp\\ldsgamemaster.exe",
  1150. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\mgame1.txt",
  1151. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\mgame1.txt",
  1152. "C:\\Users\\user\\AppData\\Local\\Temp\\5ED86E76-1AD7-43b9-91CE-040BCA16F182.tf",
  1153. "C:\\Users\\user\\AppData\\Local\\Temp\\ludCAE4.tmp",
  1154. "C:\\Users\\user\\AppData\\Local\\Temp\\CBF8BCF9-34DC-4f29-9FEF-989E5A7310B3.tf",
  1155. "C:\\Users\\user\\AppData\\Local\\Temp\\ludCC7B.tmp",
  1156. "C:\\Users\\user\\AppData\\Local\\Temp\\129F9D08-4428-452a-899E-099105FC4EBD.tf",
  1157. "C:\\Users\\user\\AppData\\Local\\Temp\\ludashisetup.exe",
  1158. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\url22.txt",
  1159. "C:\\Users\\user\\AppData\\Local\\Temp\\41785576-1855-448b-8919-DCA04B0F6050.tf",
  1160. "C:\\Users\\user\\AppData\\Local\\Temp\\51953E1C-2BF3-4a5d-BF20-90CA104C19A8.tmp",
  1161. "C:\\Users\\user\\AppData\\Local\\Temp\\5502793B-9F92-493c-B778-9B1C9469D707.tmp\\7z.dll",
  1162. "C:\\Users\\user\\AppData\\Local\\Temp\\7775FB50-8A34-47d6-A8E0-9A4AA68F4905.tmp",
  1163. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp\\Utils\\LDSBasic.dll",
  1164. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp\\360NetUL.dll",
  1165. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp\\360Base.dll",
  1166. "C:\\Users\\user\\AppData\\Local\\Temp\\16FF4C60-A5E7-4d86-A884-BE59D89FB151.tmp",
  1167. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\9AE3C9BA-B6E3-47ad-88E2-CE20DAD3B091.tf",
  1168. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp",
  1169. "C:\\Users\\user\\AppData\\Local\\Temp\\9DD32CB0-9916-4418-BF3B-70F0AAA45E5C.tmp",
  1170. "C:\\LDSGameMaster",
  1171. "C:\\LDSGameMaster\\3FFAB69C-FFB3-4642-86CB-7E405AF52317.tf",
  1172. "C:\\LDSGameMaster\\A99108B0-678B-4103-B91F-83F2880692D2.tf",
  1173. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\mgame1.txt",
  1174. "C:\\LDSGameMaster\\A3A8AE07-E463-4894-BC1F-F76D2DDCD87E.tf",
  1175. "C:\\LDSGameMaster\\D2ECED36-7EFA-4de4-998D-4C18373EEACF.tf",
  1176. "C:\\LDSGameMaster\\5371F23D-E86C-4498-8AC9-B249B3757A7B.tf",
  1177. "C:\\LDSGameMaster\\Utils\\spsvc.dll",
  1178. "C:\\LDSGameMaster\\GameMemoryOpt.dll",
  1179. "C:\\LDSGameMaster\\GameMemoryOpt_x64.dll",
  1180. "C:\\LDSGameMaster\\360Base64.dll",
  1181. "C:\\Users\\user\\AppData\\Local\\Temp\\remove_lds_gamemaster.bat",
  1182. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360Base.dll",
  1183. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360Net.dll",
  1184. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360NetBase.dll",
  1185. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360NetUL.dll",
  1186. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\360P2SP.dll",
  1187. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\LiveUpd360.dll",
  1188. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\PDown.dll",
  1189. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\SoftMgr\\SoftMgrInst.exe",
  1190. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\Utils\\LDSBasic.dll",
  1191. "C:\\LDSGameMaster\\360Base.dll",
  1192. "C:\\LDSGameMaster\\360Net.dll",
  1193. "C:\\LDSGameMaster\\360NetBase.dll",
  1194. "C:\\LDSGameMaster\\360NetUL.dll",
  1195. "C:\\LDSGameMaster\\360P2SP.dll",
  1196. "C:\\LDSGameMaster\\7z.dll",
  1197. "C:\\LDSGameMaster\\ComputerZ.set",
  1198. "C:\\LDSGameMaster\\Downloads\\Temp",
  1199. "C:\\LDSGameMaster\\Downloads",
  1200. "C:\\LDSGameMaster\\gamemaster_setup.log",
  1201. "C:\\LDSGameMaster\\LiveUpd360.dll",
  1202. "C:\\LDSGameMaster\\PDown.dll",
  1203. "C:\\LDSGameMaster\\SoftMgr\\SoftMgrInst.exe",
  1204. "C:\\LDSGameMaster\\SoftMgr",
  1205. "C:\\LDSGameMaster\\Utils\\LDSBasic.dll",
  1206. "C:\\LDSGameMaster\\Utils",
  1207. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp",
  1208. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp\\FileList.xml",
  1209. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp\\LDSGAMEMASTER.LDSPRJ",
  1210. "C:\\Users\\user\\AppData\\Local\\Temp\\E12906C5-6F85-4485-8444-69F0858792E4.tmp\\UninstallRootDirFileList.xml",
  1211. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\SoftMgr",
  1212. "C:\\ProgramData\\6278BC2D-9B39-4a59-B694-2F849AF409D7.tmp\\Utils",
  1213. "C:\\LDSGameMaster\\Downloads\\Temp\\ldssoftmgrinst_testdir.dat",
  1214. "C:\\Users\\user\\AppData\\Local\\Temp\\nst1DA7.tmp",
  1215. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1EC3.tmp",
  1216. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1EC3.tmp\\InstHlp.dll",
  1217. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1EC3.tmp\\System.dll",
  1218. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1EC3.tmp\\"
  1219.  
  1220.  
  1221. * Modified Registry Keys:
  1222. "HKEY_LOCAL_MACHINE\\Software\\360Safe\\Liveup",
  1223. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\360Safe\\Liveup\\mid",
  1224. "HKEY_LOCAL_MACHINE\\SOFTWARE\\LiveUpdate360",
  1225. "HKEY_LOCAL_MACHINE\\SOFTWARE\\LDSGameMaster",
  1226. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\FROM",
  1227. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  1228. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@\"%windir%\\System32\\ie4uinit.exe\",-738",
  1229. "HKEY_LOCAL_MACHINE\\SOFTWARE\\ComMaster",
  1230. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\ComMaster\\m2",
  1231. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\Setup Path",
  1232. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\HallPath",
  1233. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\UninstallPath",
  1234. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\SUBPID",
  1235. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SESSION MANAGER\\PendingFileRenameOperations",
  1236. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LDSGameMaster\\lua_push",
  1237. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\LiveUpdate360\\IsLowPC",
  1238. "HKEY_CURRENT_USER\\SOFTWARE\\VZip",
  1239. "HKEY_CURRENT_USER\\Software\\VZip\\UserSID",
  1240. "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZip",
  1241. "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZip\\UserSID",
  1242. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZip\\VZip",
  1243. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\QID",
  1244. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\AppDataPath",
  1245. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\isps",
  1246. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallPath",
  1247. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallTime",
  1248. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallSvrTime",
  1249. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\Shell",
  1250. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip",
  1251. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayName",
  1252. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\Publisher",
  1253. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayIcon",
  1254. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\UninstallString",
  1255. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayVersion",
  1256. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\AV",
  1257. "HKEY_CLASSES_ROOT\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07",
  1258. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\(Default)",
  1259. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32",
  1260. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\(Default)",
  1261. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\ThreadingModel",
  1262. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07",
  1263. "HKEY_CLASSES_ROOT\\*\\shellex\\ContextMenuHandlers\\VZipShell",
  1264. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
  1265. "HKEY_CLASSES_ROOT\\Folder\\shellex\\ContextMenuHandlers\\VZipShell",
  1266. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\VZipShell\\(Default)",
  1267. "HKEY_CLASSES_ROOT\\Directory\\shellex\\ContextMenuHandlers\\VZipShell",
  1268. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
  1269. "HKEY_CLASSES_ROOT\\Directory\\Background\\shellex\\ContextMenuHandlers\\VZipShell",
  1270. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Background\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
  1271. "HKEY_CLASSES_ROOT\\Directory\\shellex\\DragDropHandlers\\VZipShell",
  1272. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
  1273. "HKEY_CLASSES_ROOT\\Drive\\shellex\\DragDropHandlers\\VZipShell",
  1274. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
  1275. "HKEY_CLASSES_ROOT\\Directory\\Background\\shellex\\DragDropHandlers\\VZipShell",
  1276. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Background\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
  1277. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZip Shell Extension",
  1278. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZip Shell Extension\\(Default)",
  1279. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VZipService\\Start",
  1280. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  1281. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
  1282.  
  1283.  
  1284. * Deleted Registry Keys:
  1285. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\ldsgamemaster_uninst"
  1286.  
  1287.  
  1288. * DNS Communications:
  1289.  
  1290. "type": "A",
  1291. "request": "dlres-a.iyims.com",
  1292. "answers":
  1293.  
  1294. "data": "103.25.35.86",
  1295. "type": "A"
  1296.  
  1297.  
  1298. "data": "103.25.35.80",
  1299. "type": "A"
  1300.  
  1301.  
  1302. "data": "103.25.35.81",
  1303. "type": "A"
  1304.  
  1305.  
  1306. "data": "103.25.35.82",
  1307. "type": "A"
  1308.  
  1309.  
  1310. "data": "103.25.35.83",
  1311. "type": "A"
  1312.  
  1313.  
  1314. "data": "103.25.35.77",
  1315. "type": "A"
  1316.  
  1317.  
  1318. "data": "103.25.35.84",
  1319. "type": "A"
  1320.  
  1321.  
  1322. "data": "dlres-a.iyims.com.w.kunluncan.com",
  1323. "type": "CNAME"
  1324.  
  1325.  
  1326. "data": "103.25.35.85",
  1327. "type": "A"
  1328.  
  1329.  
  1330.  
  1331.  
  1332. "type": "A",
  1333. "request": "dl.ludashi.com",
  1334. "answers":
  1335.  
  1336. "data": "dl.360safe.com",
  1337. "type": "CNAME"
  1338.  
  1339.  
  1340. "data": "104.192.108.21",
  1341. "type": "A"
  1342.  
  1343.  
  1344. "data": "dl.qhcdn.com",
  1345. "type": "CNAME"
  1346.  
  1347.  
  1348. "data": "104.192.108.18",
  1349. "type": "A"
  1350.  
  1351.  
  1352.  
  1353.  
  1354. "type": "A",
  1355. "request": "s.ludashi.com",
  1356. "answers":
  1357.  
  1358. "data": "114.115.221.211",
  1359. "type": "A"
  1360.  
  1361.  
  1362.  
  1363.  
  1364. "type": "A",
  1365. "request": "dl.360safe.com",
  1366. "answers":
  1367.  
  1368. "data": "104.192.108.21",
  1369. "type": "A"
  1370.  
  1371.  
  1372. "data": "dl.qhcdn.com",
  1373. "type": "CNAME"
  1374.  
  1375.  
  1376. "data": "104.192.108.18",
  1377. "type": "A"
  1378.  
  1379.  
  1380.  
  1381.  
  1382. "type": "A",
  1383. "request": "s1.ludashi.com",
  1384. "answers":
  1385.  
  1386. "data": "123.125.82.104",
  1387. "type": "A"
  1388.  
  1389.  
  1390.  
  1391.  
  1392. "type": "A",
  1393. "request": "down.zhanfukeji.cn",
  1394. "answers":
  1395.  
  1396. "data": "221.230.141.50",
  1397. "type": "A"
  1398.  
  1399.  
  1400. "data": "down.zhanfukeji.cn.wsdvs.com",
  1401. "type": "CNAME"
  1402.  
  1403.  
  1404.  
  1405.  
  1406. "type": "A",
  1407. "request": "zhushou.ludashi.com",
  1408. "answers":
  1409.  
  1410. "data": "120.27.83.10",
  1411. "type": "A"
  1412.  
  1413.  
  1414.  
  1415.  
  1416. "type": "A",
  1417. "request": "l.public.ludashi.com",
  1418. "answers":
  1419.  
  1420. "data": "115.28.112.133",
  1421. "type": "A"
  1422.  
  1423.  
  1424.  
  1425.  
  1426. "type": "A",
  1427. "request": "cdn-file-ssl-monidashi.ludashi.com",
  1428. "answers":
  1429.  
  1430. "data": "36.99.227.232",
  1431. "type": "A"
  1432.  
  1433.  
  1434. "data": "36.99.227.231",
  1435. "type": "A"
  1436.  
  1437.  
  1438. "data": "36.99.227.230",
  1439. "type": "A"
  1440.  
  1441.  
  1442. "data": "36.99.227.228",
  1443. "type": "A"
  1444.  
  1445.  
  1446. "data": "36.99.227.229",
  1447. "type": "A"
  1448.  
  1449.  
  1450. "data": "cdn-file-ssl-monidashi.ludashi.com.m.alikunlun.com",
  1451. "type": "CNAME"
  1452.  
  1453.  
  1454. "data": "36.99.227.226",
  1455. "type": "A"
  1456.  
  1457.  
  1458. "data": "36.99.227.233",
  1459. "type": "A"
  1460.  
  1461.  
  1462. "data": "36.99.227.227",
  1463. "type": "A"
  1464.  
  1465.  
  1466.  
  1467.  
  1468. "type": "A",
  1469. "request": "api.zhanfukeji.cn",
  1470. "answers":
  1471.  
  1472. "data": "157.185.164.73",
  1473. "type": "A"
  1474.  
  1475.  
  1476. "data": "api.zhanfukeji.cn.wswebpic.com",
  1477. "type": "CNAME"
  1478.  
  1479.  
  1480. "data": "222.245.77.75",
  1481. "type": "A"
  1482.  
  1483.  
  1484.  
  1485.  
  1486. "type": "A",
  1487. "request": "down.soft.6789.net",
  1488. "answers":
  1489.  
  1490. "data": "221.230.141.50",
  1491. "type": "A"
  1492.  
  1493.  
  1494. "data": "down.soft.6789.net.wsdvs.com",
  1495. "type": "CNAME"
  1496.  
  1497.  
  1498.  
  1499.  
  1500. "type": "A",
  1501. "request": "ocsp2.digicert.com",
  1502. "answers":
  1503.  
  1504. "data": "cs9.wac.phicdn.net",
  1505. "type": "CNAME"
  1506.  
  1507.  
  1508. "data": "72.21.91.29",
  1509. "type": "A"
  1510.  
  1511.  
  1512.  
  1513.  
  1514. "type": "A",
  1515. "request": "partner.funshion.com",
  1516. "answers":
  1517.  
  1518. "data": "118.193.104.10",
  1519. "type": "A"
  1520.  
  1521.  
  1522. "data": "118.193.104.9",
  1523. "type": "A"
  1524.  
  1525.  
  1526.  
  1527.  
  1528. "type": "A",
  1529. "request": "downloads.funshion.net",
  1530. "answers":
  1531.  
  1532. "data": "65.153.196.229",
  1533. "type": "A"
  1534.  
  1535.  
  1536. "data": "65.153.196.227",
  1537. "type": "A"
  1538.  
  1539.  
  1540. "data": "65.153.196.228",
  1541. "type": "A"
  1542.  
  1543.  
  1544. "data": "65.153.158.164",
  1545. "type": "A"
  1546.  
  1547.  
  1548. "data": "65.153.158.172",
  1549. "type": "A"
  1550.  
  1551.  
  1552. "data": "u887.v.qingcdn.com",
  1553. "type": "CNAME"
  1554.  
  1555.  
  1556. "data": "65.153.196.230",
  1557. "type": "A"
  1558.  
  1559.  
  1560. "data": "downloads.funshion.net.qingcdn.com",
  1561. "type": "CNAME"
  1562.  
  1563.  
  1564.  
  1565.  
  1566. "type": "A",
  1567. "request": "neirong.funshion.com",
  1568. "answers":
  1569.  
  1570. "data": "58.254.181.35",
  1571. "type": "A"
  1572.  
  1573.  
  1574. "data": "neirong.funshion.com.cnixpcloud.com",
  1575. "type": "CNAME"
  1576.  
  1577.  
  1578. "data": "neirong.funshion.com.a.bdydns.com",
  1579. "type": "CNAME"
  1580.  
  1581.  
  1582. "data": "opencdncloud.jomodns.com",
  1583. "type": "CNAME"
  1584.  
  1585.  
  1586.  
  1587.  
  1588. "type": "A",
  1589. "request": "stat.funshion.net",
  1590. "answers":
  1591.  
  1592. "data": "123.58.100.31",
  1593. "type": "A"
  1594.  
  1595.  
  1596. "data": "123.58.100.34",
  1597. "type": "A"
  1598.  
  1599.  
  1600. "data": "123.58.100.177",
  1601. "type": "A"
  1602.  
  1603.  
  1604. "data": "123.58.100.33",
  1605. "type": "A"
  1606.  
  1607.  
  1608. "data": "123.58.100.30",
  1609. "type": "A"
  1610.  
  1611.  
  1612.  
  1613.  
  1614. "type": "A",
  1615. "request": "down1.wallpaper.shqingzao.com",
  1616. "answers":
  1617.  
  1618. "data": "113.59.43.98",
  1619. "type": "A"
  1620.  
  1621.  
  1622. "data": "220.194.79.107",
  1623. "type": "A"
  1624.  
  1625.  
  1626. "data": "218.11.11.221",
  1627. "type": "A"
  1628.  
  1629.  
  1630. "data": "118.212.225.117",
  1631. "type": "A"
  1632.  
  1633.  
  1634. "data": "218.11.11.246",
  1635. "type": "A"
  1636.  
  1637.  
  1638. "data": "220.194.79.73",
  1639. "type": "A"
  1640.  
  1641.  
  1642. "data": "218.11.11.245",
  1643. "type": "A"
  1644.  
  1645.  
  1646. "data": "157.255.134.80",
  1647. "type": "A"
  1648.  
  1649.  
  1650. "data": "121.29.54.234",
  1651. "type": "A"
  1652.  
  1653.  
  1654. "data": "113.1.0.63",
  1655. "type": "A"
  1656.  
  1657.  
  1658. "data": "1.189.213.200",
  1659. "type": "A"
  1660.  
  1661.  
  1662. "data": "157.255.134.75",
  1663. "type": "A"
  1664.  
  1665.  
  1666. "data": "1835929.p23.tc.cdntip.com",
  1667. "type": "CNAME"
  1668.  
  1669.  
  1670. "data": "121.29.54.65",
  1671. "type": "A"
  1672.  
  1673.  
  1674. "data": "113.1.0.98",
  1675. "type": "A"
  1676.  
  1677.  
  1678. "data": "down1.wallpaper.shqingzao.com.cdn.dnsv1.com",
  1679. "type": "CNAME"
  1680.  
  1681.  
  1682.  
  1683.  
  1684. "type": "A",
  1685. "request": "cd002.www.duba.net",
  1686. "answers":
  1687.  
  1688. "data": "sal.topgslb.com",
  1689. "type": "CNAME"
  1690.  
  1691.  
  1692. "data": "60.174.241.133",
  1693. "type": "A"
  1694.  
  1695.  
  1696. "data": "cd002.www.duba.net.scc.topgslb.com",
  1697. "type": "CNAME"
  1698.  
  1699.  
  1700. "data": "cd002.www.duba.net.spdydns.com",
  1701. "type": "CNAME"
  1702.  
  1703.  
  1704.  
  1705.  
  1706. "type": "A",
  1707. "request": "report.wallpaper.shqingzao.com",
  1708. "answers":
  1709.  
  1710. "data": "117.50.84.13",
  1711. "type": "A"
  1712.  
  1713.  
  1714.  
  1715.  
  1716.  
  1717. * Domains:
  1718.  
  1719. "ip": "43.247.234.75",
  1720. "domain": "dlres-a.iyims.com"
  1721.  
  1722.  
  1723. "ip": "120.27.83.10",
  1724. "domain": "zhushou.ludashi.com"
  1725.  
  1726.  
  1727. "ip": "123.125.82.104",
  1728. "domain": "s1.ludashi.com"
  1729.  
  1730.  
  1731. "ip": "104.192.108.21",
  1732. "domain": "dl.360safe.com"
  1733.  
  1734.  
  1735. "ip": "36.99.227.231",
  1736. "domain": "cdn-file-ssl-monidashi.ludashi.com"
  1737.  
  1738.  
  1739. "ip": "114.115.214.33",
  1740. "domain": "s.ludashi.com"
  1741.  
  1742.  
  1743. "ip": "115.28.112.133",
  1744. "domain": "l.public.ludashi.com"
  1745.  
  1746.  
  1747. "ip": "104.192.108.21",
  1748. "domain": "dl.ludashi.com"
  1749.  
  1750.  
  1751. "ip": "221.230.141.50",
  1752. "domain": "down.zhanfukeji.cn"
  1753.  
  1754.  
  1755. "ip": "65.153.196.227",
  1756. "domain": "downloads.funshion.net"
  1757.  
  1758.  
  1759. "ip": "118.193.104.9",
  1760. "domain": "partner.funshion.com"
  1761.  
  1762.  
  1763. "ip": "72.21.91.29",
  1764. "domain": "ocsp2.digicert.com"
  1765.  
  1766.  
  1767. "ip": "221.230.141.50",
  1768. "domain": "down.soft.6789.net"
  1769.  
  1770.  
  1771. "ip": "222.245.77.75",
  1772. "domain": "api.zhanfukeji.cn"
  1773.  
  1774.  
  1775. "ip": "60.174.241.133",
  1776. "domain": "cd002.www.duba.net"
  1777.  
  1778.  
  1779. "ip": "113.1.0.98",
  1780. "domain": "down1.wallpaper.shqingzao.com"
  1781.  
  1782.  
  1783. "ip": "117.50.84.13",
  1784. "domain": "report.wallpaper.shqingzao.com"
  1785.  
  1786.  
  1787. "ip": "123.58.100.30",
  1788. "domain": "stat.funshion.net"
  1789.  
  1790.  
  1791. "ip": "58.254.181.35",
  1792. "domain": "neirong.funshion.com"
  1793.  
  1794.  
  1795.  
  1796. * Network Communication - ICMP:
  1797.  
  1798. "src": "98.124.173.249",
  1799. "dst": "169.254.255.254
  1800. "type": 3,
  1801. "data": ""
  1802.  
  1803.  
  1804.  
  1805. * Network Communication - HTTP:
  1806.  
  1807. "count": 1,
  1808. "body": "",
  1809. "uri": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1810. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1811. "method": "GET",
  1812. "host": "47.96.116.228:8081",
  1813. "version": "1.1",
  1814. "path": "/api/software/getMain?downloadId=1&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1815. "data": "GET /api/software/getMain?downloadId=1&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1816. "port": 8081
  1817.  
  1818.  
  1819. "count": 1,
  1820. "body": "",
  1821. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1822. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1823. "method": "GET",
  1824. "host": "47.96.116.228:8081",
  1825. "version": "1.1",
  1826. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1827. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1828. "port": 8081
  1829.  
  1830.  
  1831. "count": 1,
  1832. "body": "",
  1833. "uri": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe",
  1834. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1835. "method": "GET",
  1836. "host": "dl.ludashi.com",
  1837. "version": "1.1",
  1838. "path": "/gamemaster/LDSGameMasterInstRoad_211101.exe",
  1839. "data": "GET /gamemaster/LDSGameMasterInstRoad_211101.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  1840. "port": 80
  1841.  
  1842.  
  1843. "count": 1,
  1844. "body": "",
  1845. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1846. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1847. "method": "GET",
  1848. "host": "47.96.116.228:8081",
  1849. "version": "1.1",
  1850. "path": "/api/recorder/downloadComplete?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1851. "data": "GET /api/recorder/downloadComplete?downloadId=1&softwareId=16&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1852. "port": 8081
  1853.  
  1854.  
  1855. "count": 1,
  1856. "body": "",
  1857. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1858. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1859. "method": "GET",
  1860. "host": "47.96.116.228:8081",
  1861. "version": "1.1",
  1862. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1863. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1864. "port": 8081
  1865.  
  1866.  
  1867. "count": 1,
  1868. "body": "",
  1869. "uri": "http://s.ludashi.com/mgame?type=instonline&action=run&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  1870. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1871. "method": "GET",
  1872. "host": "s.ludashi.com",
  1873. "version": "1.1",
  1874. "path": "/mgame?type=instonline&action=run&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  1875. "data": "GET /mgame?type=instonline&action=run&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  1876. "port": 80
  1877.  
  1878.  
  1879. "count": 1,
  1880. "body": "",
  1881. "uri": "http://dl.360safe.com/ludashi/inst_buychannel_40.exe",
  1882. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1883. "method": "GET",
  1884. "host": "dl.360safe.com",
  1885. "version": "1.1",
  1886. "path": "/ludashi/inst_buychannel_40.exe",
  1887. "data": "GET /ludashi/inst_buychannel_40.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\n\r\n",
  1888. "port": 80
  1889.  
  1890.  
  1891. "count": 1,
  1892. "body": "",
  1893. "uri": "http://s.ludashi.com/mgame?type=instonline&action=down_start&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  1894. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1895. "method": "GET",
  1896. "host": "s.ludashi.com",
  1897. "version": "1.1",
  1898. "path": "/mgame?type=instonline&action=down_start&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  1899. "data": "GET /mgame?type=instonline&action=down_start&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  1900. "port": 80
  1901.  
  1902.  
  1903. "count": 1,
  1904. "body": "",
  1905. "uri": "http://dl.ludashi.com/gamemaster/buychannelFull.exe",
  1906. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  1907. "method": "GET",
  1908. "host": "dl.ludashi.com",
  1909. "version": "1.1",
  1910. "path": "/gamemaster/buychannelFull.exe",
  1911. "data": "GET /gamemaster/buychannelFull.exe HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1912. "port": 80
  1913.  
  1914.  
  1915. "count": 1,
  1916. "body": "",
  1917. "uri": "http://dl.ludashi.com/gamemaster/buychannelFull.exe",
  1918. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  1919. "method": "GET",
  1920. "host": "dl.ludashi.com",
  1921. "version": "1.1",
  1922. "path": "/gamemaster/buychannelFull.exe",
  1923. "data": "GET /gamemaster/buychannelFull.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=2605056-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1924. "port": 80
  1925.  
  1926.  
  1927. "count": 1,
  1928. "body": "",
  1929. "uri": "http://dl.ludashi.com/gamemaster/buychannelFull.exe",
  1930. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  1931. "method": "GET",
  1932. "host": "dl.ludashi.com",
  1933. "version": "1.1",
  1934. "path": "/gamemaster/buychannelFull.exe",
  1935. "data": "GET /gamemaster/buychannelFull.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=1736704-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1936. "port": 80
  1937.  
  1938.  
  1939. "count": 1,
  1940. "body": "",
  1941. "uri": "http://dl.ludashi.com/gamemaster/buychannelFull.exe",
  1942. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  1943. "method": "GET",
  1944. "host": "dl.ludashi.com",
  1945. "version": "1.1",
  1946. "path": "/gamemaster/buychannelFull.exe",
  1947. "data": "GET /gamemaster/buychannelFull.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=3473408-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1948. "port": 80
  1949.  
  1950.  
  1951. "count": 1,
  1952. "body": "",
  1953. "uri": "http://dl.ludashi.com/gamemaster/buychannelFull.exe",
  1954. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  1955. "method": "GET",
  1956. "host": "dl.ludashi.com",
  1957. "version": "1.1",
  1958. "path": "/gamemaster/buychannelFull.exe",
  1959. "data": "GET /gamemaster/buychannelFull.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=868352-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1960. "port": 80
  1961.  
  1962.  
  1963. "count": 1,
  1964. "body": "",
  1965. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1966. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1967. "method": "GET",
  1968. "host": "47.96.116.228:8081",
  1969. "version": "1.1",
  1970. "path": "/api/recorder/downloadComplete?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1971. "data": "GET /api/recorder/downloadComplete?downloadId=1&softwareId=17&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1972. "port": 8081
  1973.  
  1974.  
  1975. "count": 1,
  1976. "body": "",
  1977. "uri": "http://dl.ludashi.com/gamemaster/buychannelFull.exe",
  1978. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  1979. "method": "GET",
  1980. "host": "dl.ludashi.com",
  1981. "version": "1.1",
  1982. "path": "/gamemaster/buychannelFull.exe",
  1983. "data": "GET /gamemaster/buychannelFull.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=524288-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1984. "port": 80
  1985.  
  1986.  
  1987. "count": 1,
  1988. "body": "",
  1989. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1990. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1991. "method": "GET",
  1992. "host": "47.96.116.228:8081",
  1993. "version": "1.1",
  1994. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  1995. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1996. "port": 8081
  1997.  
  1998.  
  1999. "count": 1,
  2000. "body": "",
  2001. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2002. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2003. "method": "GET",
  2004. "host": "dl.360safe.com",
  2005. "version": "1.1",
  2006. "path": "/ludashi/ludashi_buy.exe",
  2007. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2008. "port": 80
  2009.  
  2010.  
  2011. "count": 1,
  2012. "body": "",
  2013. "uri": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2014. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2015. "method": "GET",
  2016. "host": "s1.ludashi.com",
  2017. "version": "1.1",
  2018. "path": "/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2019. "data": "GET /url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2020. "port": 80
  2021.  
  2022.  
  2023. "count": 1,
  2024. "body": "",
  2025. "uri": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2026. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2027. "method": "GET",
  2028. "host": "s1.ludashi.com",
  2029. "version": "1.1",
  2030. "path": "/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2031. "data": "GET /url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2032. "port": 80
  2033.  
  2034.  
  2035. "count": 1,
  2036. "body": "",
  2037. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2038. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2039. "method": "GET",
  2040. "host": "dl.360safe.com",
  2041. "version": "1.1",
  2042. "path": "/ludashi/ludashi_buy.exe",
  2043. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=38854656-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2044. "port": 80
  2045.  
  2046.  
  2047. "count": 1,
  2048. "body": "",
  2049. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2050. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2051. "method": "GET",
  2052. "host": "dl.360safe.com",
  2053. "version": "1.1",
  2054. "path": "/ludashi/ludashi_buy.exe",
  2055. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=12951552-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2056. "port": 80
  2057.  
  2058.  
  2059. "count": 1,
  2060. "body": "",
  2061. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2062. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2063. "method": "GET",
  2064. "host": "dl.360safe.com",
  2065. "version": "1.1",
  2066. "path": "/ludashi/ludashi_buy.exe",
  2067. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=25903104-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2068. "port": 80
  2069.  
  2070.  
  2071. "count": 1,
  2072. "body": "",
  2073. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2074. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2075. "method": "GET",
  2076. "host": "dl.360safe.com",
  2077. "version": "1.1",
  2078. "path": "/ludashi/ludashi_buy.exe",
  2079. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=51806208-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2080. "port": 80
  2081.  
  2082.  
  2083. "count": 2,
  2084. "body": "",
  2085. "uri": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe",
  2086. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2087. "method": "GET",
  2088. "host": "down.zhanfukeji.cn",
  2089. "version": "1.1",
  2090. "path": "/VZip/ver_1.0.1.6/channel/VZip_724.exe",
  2091. "data": "GET /VZip/ver_1.0.1.6/channel/VZip_724.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: down.zhanfukeji.cn\r\nConnection: Keep-Alive\r\n\r\n",
  2092. "port": 80
  2093.  
  2094.  
  2095. "count": 1,
  2096. "body": "",
  2097. "uri": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2098. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2099. "method": "GET",
  2100. "host": "s.ludashi.com",
  2101. "version": "1.1",
  2102. "path": "/url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2103. "data": "GET /url2?pid=buychannel_40&type=instonline&action=down_start&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  2104. "port": 80
  2105.  
  2106.  
  2107. "count": 1,
  2108. "body": "",
  2109. "uri": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2110. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2111. "method": "GET",
  2112. "host": "s.ludashi.com",
  2113. "version": "1.1",
  2114. "path": "/url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2115. "data": "GET /url2?pid=buychannel_40&type=instonline&action=run&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  2116. "port": 80
  2117.  
  2118.  
  2119. "count": 1,
  2120. "body": "",
  2121. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2122. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2123. "method": "GET",
  2124. "host": "dl.360safe.com",
  2125. "version": "1.1",
  2126. "path": "/ludashi/ludashi_buy.exe",
  2127. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=442708-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2128. "port": 80
  2129.  
  2130.  
  2131. "count": 1,
  2132. "body": "",
  2133. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2134. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2135. "method": "GET",
  2136. "host": "dl.360safe.com",
  2137. "version": "1.1",
  2138. "path": "/ludashi/ludashi_buy.exe",
  2139. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=13158400-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2140. "port": 80
  2141.  
  2142.  
  2143. "count": 1,
  2144. "body": "",
  2145. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2146. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2147. "method": "GET",
  2148. "host": "dl.360safe.com",
  2149. "version": "1.1",
  2150. "path": "/ludashi/ludashi_buy.exe",
  2151. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=51992576-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2152. "port": 80
  2153.  
  2154.  
  2155. "count": 1,
  2156. "body": "",
  2157. "uri": "http://s.ludashi.com/mgame?type=instonline&action=down_success&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  2158. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2159. "method": "GET",
  2160. "host": "s.ludashi.com",
  2161. "version": "1.1",
  2162. "path": "/mgame?type=instonline&action=down_success&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  2163. "data": "GET /mgame?type=instonline&action=down_success&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2164. "port": 80
  2165.  
  2166.  
  2167. "count": 1,
  2168. "body": "",
  2169. "uri": "http://s.ludashi.com/mgame?type=instonline&action=down_exec&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  2170. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2171. "method": "GET",
  2172. "host": "s.ludashi.com",
  2173. "version": "1.1",
  2174. "path": "/mgame?type=instonline&action=down_exec&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030",
  2175. "data": "GET /mgame?type=instonline&action=down_exec&channel=211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.2.0.1030&modver=5.2.0.1030 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2176. "port": 80
  2177.  
  2178.  
  2179. "count": 1,
  2180. "body": "",
  2181. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=run&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2182. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2183. "method": "GET",
  2184. "host": "s.ludashi.com",
  2185. "version": "1.1",
  2186. "path": "/mgame?type=installpkg&action=run&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2187. "data": "GET /mgame?type=installpkg&action=run&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2188. "port": 80
  2189.  
  2190.  
  2191. "count": 1,
  2192. "body": "",
  2193. "uri": "http://zhushou.ludashi.com/game/Getloadernew?channel_num=211101&subpid=211101&from=inst&version=5.1.2047.2030&existsver=&osver=6.1&iever=8.0.7601.17514&ids=&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&motion=",
  2194. "user-agent": "",
  2195. "method": "GET",
  2196. "host": "zhushou.ludashi.com",
  2197. "version": "1.1",
  2198. "path": "/game/Getloadernew?channel_num=211101&subpid=211101&from=inst&version=5.1.2047.2030&existsver=&osver=6.1&iever=8.0.7601.17514&ids=&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&motion=",
  2199. "data": "GET /game/Getloadernew?channel_num=211101&subpid=211101&from=inst&version=5.1.2047.2030&existsver=&osver=6.1&iever=8.0.7601.17514&ids=&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&motion= HTTP/1.1\r\nConnection: Close\r\nHost: zhushou.ludashi.com\r\n\r\n",
  2200. "port": 80
  2201.  
  2202.  
  2203. "count": 1,
  2204. "body": "",
  2205. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=osver_6.1&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2206. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2207. "method": "GET",
  2208. "host": "s.ludashi.com",
  2209. "version": "1.1",
  2210. "path": "/mgame?type=installpkg&action=osver_6.1&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2211. "data": "GET /mgame?type=installpkg&action=osver_6.1&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133619059&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2212. "port": 80
  2213.  
  2214.  
  2215. "count": 1,
  2216. "body": "-----------------------------1qaz28079078\r\nContent-Disposition: form-data; name=\"data\"\r\n\r\nL4bwobzrJNE0zmOKR/jsmllh6EwsFBME65LTVr07kMiaH+emlGZsS/hWqqNJEyCHUqZB3WQuVZfk/A5tYEHP1H5gKHkTs04uPzO2MDxgWG6S6dq7VC99Z+h2e2RK+DsRwG1pJMXwbbxlPCos7LyvpYmY40Y8ZcpX1oA6KXvRO9sleJravmXtCg6VW463/VHSrnxbsxAa/lyFLKpTfNoD5YrPedqIKuQLU5AS/GIk420GU4YyRE4UwKnscCwJ0dUqPobQydzBWII=\r\n-----------------------------1qaz28079078--\r\n",
  2217. "uri": "http://l.public.ludashi.com/pc/udmgame/dogSun",
  2218. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2219. "method": "POST",
  2220. "host": "l.public.ludashi.com",
  2221. "version": "1.1",
  2222. "path": "/pc/udmgame/dogSun",
  2223. "data": "POST /pc/udmgame/dogSun HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nContent-Type: multipart/form-data; boundary=---------------------------1qaz28079078\r\nHost: l.public.ludashi.com\r\nContent-Length: 405\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n-----------------------------1qaz28079078\r\nContent-Disposition: form-data; name=\"data\"\r\n\r\nL4bwobzrJNE0zmOKR/jsmllh6EwsFBME65LTVr07kMiaH+emlGZsS/hWqqNJEyCHUqZB3WQuVZfk/A5tYEHP1H5gKHkTs04uPzO2MDxgWG6S6dq7VC99Z+h2e2RK+DsRwG1pJMXwbbxlPCos7LyvpYmY40Y8ZcpX1oA6KXvRO9sleJravmXtCg6VW463/VHSrnxbsxAa/lyFLKpTfNoD5YrPedqIKuQLU5AS/GIk420GU4YyRE4UwKnscCwJ0dUqPobQydzBWII=\r\n-----------------------------1qaz28079078--\r\n",
  2224. "port": 80
  2225.  
  2226.  
  2227. "count": 1,
  2228. "body": "",
  2229. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=newinstall&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133620903&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2230. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2231. "method": "GET",
  2232. "host": "s.ludashi.com",
  2233. "version": "1.1",
  2234. "path": "/mgame?type=installpkg&action=newinstall&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133620903&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2235. "data": "GET /mgame?type=installpkg&action=newinstall&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133620903&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2236. "port": 80
  2237.  
  2238.  
  2239. "count": 1,
  2240. "body": "",
  2241. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=start_install&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133642153&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2242. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2243. "method": "GET",
  2244. "host": "s.ludashi.com",
  2245. "version": "1.1",
  2246. "path": "/mgame?type=installpkg&action=start_install&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133642153&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2247. "data": "GET /mgame?type=installpkg&action=start_install&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133642153&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2248. "port": 80
  2249.  
  2250.  
  2251. "count": 1,
  2252. "body": "",
  2253. "uri": "http://zhushou.ludashi.com/cms/shouyou/bizhi/lua.php?channel_num=211101&subpid=211101&from=inst&version=8.0.7601.17514&osver=6.1&iever=8.0.7601.17514&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2254. "user-agent": "",
  2255. "method": "GET",
  2256. "host": "zhushou.ludashi.com",
  2257. "version": "1.1",
  2258. "path": "/cms/shouyou/bizhi/lua.php?channel_num=211101&subpid=211101&from=inst&version=8.0.7601.17514&osver=6.1&iever=8.0.7601.17514&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2259. "data": "GET /cms/shouyou/bizhi/lua.php?channel_num=211101&subpid=211101&from=inst&version=8.0.7601.17514&osver=6.1&iever=8.0.7601.17514&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nConnection: Close\r\nHost: zhushou.ludashi.com\r\n\r\n",
  2260. "port": 80
  2261.  
  2262.  
  2263. "count": 1,
  2264. "body": "",
  2265. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=install_default&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133733543&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2266. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2267. "method": "GET",
  2268. "host": "s.ludashi.com",
  2269. "version": "1.1",
  2270. "path": "/mgame?type=installpkg&action=install_default&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133733543&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2271. "data": "GET /mgame?type=installpkg&action=install_default&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133733543&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2272. "port": 80
  2273.  
  2274.  
  2275. "count": 1,
  2276. "body": "",
  2277. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_start&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133735387&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2278. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2279. "method": "GET",
  2280. "host": "s.ludashi.com",
  2281. "version": "1.1",
  2282. "path": "/mgame?type=installpkg&action=down_hall_start&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133735387&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2283. "data": "GET /mgame?type=installpkg&action=down_hall_start&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133735387&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2284. "port": 80
  2285.  
  2286.  
  2287. "count": 1,
  2288. "body": "",
  2289. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2290. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2291. "method": "GET",
  2292. "host": "47.96.116.228:8081",
  2293. "version": "1.1",
  2294. "path": "/api/recorder/downloadComplete?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2295. "data": "GET /api/recorder/downloadComplete?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2296. "port": 8081
  2297.  
  2298.  
  2299. "count": 2,
  2300. "body": "",
  2301. "uri": "http://cdn-file-ssl-monidashi.ludashi.com/gamemaster/pushfile/201907162222.file",
  2302. "user-agent": "",
  2303. "method": "GET",
  2304. "host": "cdn-file-ssl-monidashi.ludashi.com",
  2305. "version": "1.1",
  2306. "path": "/gamemaster/pushfile/201907162222.file",
  2307. "data": "GET /gamemaster/pushfile/201907162222.file HTTP/1.1\r\nConnection: Close\r\nHost: cdn-file-ssl-monidashi.ludashi.com\r\n\r\n",
  2308. "port": 80
  2309.  
  2310.  
  2311. "count": 1,
  2312. "body": "",
  2313. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_fail&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2314. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2315. "method": "GET",
  2316. "host": "s.ludashi.com",
  2317. "version": "1.1",
  2318. "path": "/mgame?type=installpkg&action=down_hall_fail&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2319. "data": "GET /mgame?type=installpkg&action=down_hall_fail&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2320. "port": 80
  2321.  
  2322.  
  2323. "count": 1,
  2324. "body": "",
  2325. "uri": "http://s.ludashi.com/mgame?type=installpkg&action=down_hall_fail_0&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2326. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2327. "method": "GET",
  2328. "host": "s.ludashi.com",
  2329. "version": "1.1",
  2330. "path": "/mgame?type=installpkg&action=down_hall_fail_0&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e",
  2331. "data": "GET /mgame?type=installpkg&action=down_hall_fail_0&channel=211101__211101&from=inst&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6&appver=5.1.2047.2030&modver=5.1.2047.2030&timestamp=20190718133842309&mid2=a47590134691d299afd9ea7c4bd83a5022a1e33b2b7e HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2332. "port": 80
  2333.  
  2334.  
  2335. "count": 1,
  2336. "body": "",
  2337. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2338. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2339. "method": "GET",
  2340. "host": "47.96.116.228:8081",
  2341. "version": "1.1",
  2342. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2343. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2344. "port": 8081
  2345.  
  2346.  
  2347. "count": 1,
  2348. "body": "",
  2349. "uri": "http://47.96.116.228:8081/api/recorder/install?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2350. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2351. "method": "GET",
  2352. "host": "47.96.116.228:8081",
  2353. "version": "1.1",
  2354. "path": "/api/recorder/install?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2355. "data": "GET /api/recorder/install?downloadId=1&softwareId=7&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2356. "port": 8081
  2357.  
  2358.  
  2359. "count": 1,
  2360. "body": "",
  2361. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D",
  2362. "user-agent": "Microsoft-CryptoAPI/6.1",
  2363. "method": "GET",
  2364. "host": "ocsp.digicert.com",
  2365. "version": "1.1",
  2366. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D",
  2367. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  2368. "port": 80
  2369.  
  2370.  
  2371. "count": 1,
  2372. "body": "",
  2373. "uri": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D",
  2374. "user-agent": "Microsoft-CryptoAPI/6.1",
  2375. "method": "GET",
  2376. "host": "ocsp2.digicert.com",
  2377. "version": "1.1",
  2378. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D",
  2379. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp2.digicert.com\r\n\r\n",
  2380. "port": 80
  2381.  
  2382.  
  2383. "count": 1,
  2384. "body": "",
  2385. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2386. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2387. "method": "GET",
  2388. "host": "47.96.116.228:8081",
  2389. "version": "1.1",
  2390. "path": "/api/recorder/downloadComplete?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2391. "data": "GET /api/recorder/downloadComplete?downloadId=1&softwareId=37&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2392. "port": 8081
  2393.  
  2394.  
  2395. "count": 1,
  2396. "body": "",
  2397. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2398. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2399. "method": "GET",
  2400. "host": "47.96.116.228:8081",
  2401. "version": "1.1",
  2402. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2403. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2404. "port": 8081
  2405.  
  2406.  
  2407. "count": 1,
  2408. "body": "",
  2409. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2410. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2411. "method": "GET",
  2412. "host": "dl.360safe.com",
  2413. "version": "1.1",
  2414. "path": "/ludashi/ludashi_buy.exe",
  2415. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=61065216-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2416. "port": 80
  2417.  
  2418.  
  2419. "count": 1,
  2420. "body": "",
  2421. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2422. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2423. "method": "GET",
  2424. "host": "dl.360safe.com",
  2425. "version": "1.1",
  2426. "path": "/ludashi/ludashi_buy.exe",
  2427. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=21442560-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2428. "port": 80
  2429.  
  2430.  
  2431. "count": 1,
  2432. "body": "",
  2433. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2434. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2435. "method": "GET",
  2436. "host": "dl.360safe.com",
  2437. "version": "1.1",
  2438. "path": "/ludashi/ludashi_buy.exe",
  2439. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=50110464-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2440. "port": 80
  2441.  
  2442.  
  2443. "count": 1,
  2444. "body": "",
  2445. "uri": "http://dl.360safe.com/ludashi/ludashi_buy.exe",
  2446. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)",
  2447. "method": "GET",
  2448. "host": "dl.360safe.com",
  2449. "version": "1.1",
  2450. "path": "/ludashi/ludashi_buy.exe",
  2451. "data": "GET /ludashi/ludashi_buy.exe HTTP/1.1\r\nAccept: */*\r\nRange: bytes=9455956-\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  2452. "port": 80
  2453.  
  2454.  
  2455. "count": 1,
  2456. "body": "",
  2457. "uri": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0",
  2458. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2459. "method": "GET",
  2460. "host": "partner.funshion.com",
  2461. "version": "1.1",
  2462. "path": "/partner/tk_download.php?id=9801\\xa0",
  2463. "data": "GET /partner/tk_download.php?id=9801\\xa0 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: partner.funshion.com\r\nConnection: Keep-Alive\r\n\r\n",
  2464. "port": 80
  2465.  
  2466.  
  2467. "count": 1,
  2468. "body": "",
  2469. "uri": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe",
  2470. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2471. "method": "GET",
  2472. "host": "downloads.funshion.net",
  2473. "version": "1.1",
  2474. "path": "/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe",
  2475. "data": "GET /tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: downloads.funshion.net\r\n\r\n",
  2476. "port": 80
  2477.  
  2478.  
  2479. "count": 1,
  2480. "body": "",
  2481. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2482. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2483. "method": "GET",
  2484. "host": "47.96.116.228:8081",
  2485. "version": "1.1",
  2486. "path": "/api/recorder/downloadComplete?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2487. "data": "GET /api/recorder/downloadComplete?downloadId=1&softwareId=13&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2488. "port": 8081
  2489.  
  2490.  
  2491. "count": 2,
  2492. "body": "",
  2493. "uri": "http://neirong.funshion.com/tools/acceconfig.ini",
  2494. "user-agent": "Funshion/4.0",
  2495. "method": "GET",
  2496. "host": "neirong.funshion.com",
  2497. "version": "1.1",
  2498. "path": "/tools/acceconfig.ini",
  2499. "data": "GET /tools/acceconfig.ini HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Funshion/4.0\r\nHost: neirong.funshion.com\r\n\r\n",
  2500. "port": 80
  2501.  
  2502.  
  2503. "count": 1,
  2504. "body": "",
  2505. "uri": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16600*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2506. "user-agent": "Funshion/4.0",
  2507. "method": "GET",
  2508. "host": "stat.funshion.net",
  2509. "version": "1.1",
  2510. "path": "/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16600*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2511. "data": "GET /tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16600*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056 HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Funshion/4.0\r\nHost: stat.funshion.net\r\n\r\n",
  2512. "port": 80
  2513.  
  2514.  
  2515. "count": 1,
  2516. "body": "",
  2517. "uri": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=19000*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2518. "user-agent": "Funshion/4.0",
  2519. "method": "GET",
  2520. "host": "stat.funshion.net",
  2521. "version": "1.1",
  2522. "path": "/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=19000*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2523. "data": "GET /tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=19000*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056 HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Funshion/4.0\r\nHost: stat.funshion.net\r\n\r\n",
  2524. "port": 80
  2525.  
  2526.  
  2527. "count": 1,
  2528. "body": "",
  2529. "uri": "http://s1.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2530. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2531. "method": "GET",
  2532. "host": "s1.ludashi.com",
  2533. "version": "1.1",
  2534. "path": "/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2535. "data": "GET /url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: s1.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  2536. "port": 80
  2537.  
  2538.  
  2539. "count": 1,
  2540. "body": "",
  2541. "uri": "http://s.ludashi.com/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2542. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2543. "method": "GET",
  2544. "host": "s.ludashi.com",
  2545. "version": "1.1",
  2546. "path": "/url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6",
  2547. "data": "GET /url2?pid=buychannel_40&type=instonline&action=down_success&appver=5.1.0.1005&modver=5.1.0.1005&mid=11e3f45faf1fc6b98fdfc08d15e9e6c6 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: s.ludashi.com\r\n\r\n",
  2548. "port": 80
  2549.  
  2550.  
  2551. "count": 1,
  2552. "body": "",
  2553. "uri": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16204*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2554. "user-agent": "Funshion/4.0",
  2555. "method": "GET",
  2556. "host": "stat.funshion.net",
  2557. "version": "1.1",
  2558. "path": "/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16204*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2559. "data": "GET /tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16204*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056 HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Funshion/4.0\r\nHost: stat.funshion.net\r\n\r\n",
  2560. "port": 80
  2561.  
  2562.  
  2563. "count": 1,
  2564. "body": "",
  2565. "uri": "http://stat.funshion.net/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16706*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2566. "user-agent": "Funshion/4.0",
  2567. "method": "GET",
  2568. "host": "stat.funshion.net",
  2569. "version": "1.1",
  2570. "path": "/tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16706*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056",
  2571. "data": "GET /tools/FsPlatformAction?rprotocol=3*_*action=funacceinstall*_*actionresult=16706*_*actionobjectver=1*_*channelid=2*_*mac=18C086CD4732*_*guid=355744D2-6DB6-4f59-9448-7A8A6968C75E*_*name=FunInstaller_PS_0109801*_*version=1.0.5.72Beta*_*actiontime=old*_*pullupname=*_*pullupversion=00%7Cwin7-64-0*_*cid=9801*_*aptid=065475000e0e0d0619007624501403547101147475005c1a27027f0025555056 HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Funshion/4.0\r\nHost: stat.funshion.net\r\n\r\n",
  2572. "port": 80
  2573.  
  2574.  
  2575. "count": 1,
  2576. "body": "",
  2577. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2578. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2579. "method": "GET",
  2580. "host": "47.96.116.228:8081",
  2581. "version": "1.1",
  2582. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2583. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2584. "port": 8081
  2585.  
  2586.  
  2587. "count": 4,
  2588. "body": "",
  2589. "uri": "http://down1.wallpaper.shqingzao.com/install/qid/kb_001/CalfWallpaper_2244256949_kb_001.exe",
  2590. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2591. "method": "GET",
  2592. "host": "down1.wallpaper.shqingzao.com",
  2593. "version": "1.1",
  2594. "path": "/install/qid/kb_001/CalfWallpaper_2244256949_kb_001.exe",
  2595. "data": "GET /install/qid/kb_001/CalfWallpaper_2244256949_kb_001.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: down1.wallpaper.shqingzao.com\r\nConnection: Keep-Alive\r\n\r\n",
  2596. "port": 80
  2597.  
  2598.  
  2599. "count": 1,
  2600. "body": "",
  2601. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2602. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2603. "method": "GET",
  2604. "host": "47.96.116.228:8081",
  2605. "version": "1.1",
  2606. "path": "/api/recorder/downloadComplete?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2607. "data": "GET /api/recorder/downloadComplete?downloadId=1&softwareId=25&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2608. "port": 8081
  2609.  
  2610.  
  2611. "count": 1,
  2612. "body": "",
  2613. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&softwareId=8&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2614. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  2615. "method": "GET",
  2616. "host": "47.96.116.228:8081",
  2617. "version": "1.1",
  2618. "path": "/api/recorder/downloadStart?downloadId=1&softwareId=8&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  2619. "data": "GET /api/recorder/downloadStart?downloadId=1&softwareId=8&machineCode=9CF21863-06B7-4C40-B129-9D96A3CA414B&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  2620. "port": 8081
  2621.  
  2622.  
  2623. "count": 1,
  2624. "body": "",
  2625. "uri": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe",
  2626. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  2627. "method": "GET",
  2628. "host": "cd002.www.duba.net",
  2629. "version": "1.1",
  2630. "path": "/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe",
  2631. "data": "GET /duba/install/2011/ever/duba_u21055977_sv1_115_1.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: cd002.www.duba.net\r\nConnection: Keep-Alive\r\n\r\n",
  2632. "port": 80
  2633.  
  2634.  
  2635. "count": 1,
  2636. "body": "",
  2637. "uri": "http://report.wallpaper.shqingzao.com/wallpaper/online?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1",
  2638. "user-agent": "",
  2639. "method": "POST",
  2640. "host": "report.wallpaper.shqingzao.com",
  2641. "version": "1.1",
  2642. "path": "/wallpaper/online?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1",
  2643. "data": "POST /wallpaper/online?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1 HTTP/1.1\r\nHost: report.wallpaper.shqingzao.com\r\nAccept: */*\r\nContent-Length: 0\r\n\r\n",
  2644. "port": 80
  2645.  
  2646.  
  2647. "count": 1,
  2648. "body": "",
  2649. "uri": "http://report.wallpaper.shqingzao.com/wallpaper/install?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1nriJHnh3WVmnJ4dUA2EnP+dJzGBt0NGm7hfURH06a1CxrXb/sgILYpSRi8AMlmXXVUFORpcSQ8O4KBCmpPD7bezFaaE8zx26adAwfYprlNZsYaDiAsvBM+q6",
  2650. "user-agent": "",
  2651. "method": "POST",
  2652. "host": "report.wallpaper.shqingzao.com",
  2653. "version": "1.1",
  2654. "path": "/wallpaper/install?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1nriJHnh3WVmnJ4dUA2EnP+dJzGBt0NGm7hfURH06a1CxrXb/sgILYpSRi8AMlmXXVUFORpcSQ8O4KBCmpPD7bezFaaE8zx26adAwfYprlNZsYaDiAsvBM+q6",
  2655. "data": "POST /wallpaper/install?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN1nriJHnh3WVmnJ4dUA2EnP+dJzGBt0NGm7hfURH06a1CxrXb/sgILYpSRi8AMlmXXVUFORpcSQ8O4KBCmpPD7bezFaaE8zx26adAwfYprlNZsYaDiAsvBM+q6 HTTP/1.1\r\nHost: report.wallpaper.shqingzao.com\r\nAccept: */*\r\nContent-Length: 0\r\n\r\n",
  2656. "port": 80
  2657.  
  2658.  
  2659. "count": 2,
  2660. "body": "",
  2661. "uri": "http://down1.wallpaper.shqingzao.com/report/queryinfo.xml",
  2662. "user-agent": "",
  2663. "method": "GET",
  2664. "host": "down1.wallpaper.shqingzao.com",
  2665. "version": "1.1",
  2666. "path": "/report/queryinfo.xml",
  2667. "data": "GET /report/queryinfo.xml HTTP/1.1\r\nHost: down1.wallpaper.shqingzao.com\r\nAccept: */*\r\n\r\n",
  2668. "port": 80
  2669.  
  2670.  
  2671. "count": 1,
  2672. "body": "",
  2673. "uri": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN3objBfiZnZwXxQJoLWSEVC90Lo2IjtbTEmGyKAhtVMAKS1xWK3jhDN63kouYE9QrWbDQ=",
  2674. "user-agent": "",
  2675. "method": "POST",
  2676. "host": "report.wallpaper.shqingzao.com",
  2677. "version": "1.1",
  2678. "path": "/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN3objBfiZnZwXxQJoLWSEVC90Lo2IjtbTEmGyKAhtVMAKS1xWK3jhDN63kouYE9QrWbDQ=",
  2679. "data": "POST /wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CN3objBfiZnZwXxQJoLWSEVC90Lo2IjtbTEmGyKAhtVMAKS1xWK3jhDN63kouYE9QrWbDQ= HTTP/1.1\r\nHost: report.wallpaper.shqingzao.com\r\nAccept: */*\r\nContent-Length: 0\r\n\r\n",
  2680. "port": 80
  2681.  
  2682.  
  2683. "count": 1,
  2684. "body": "",
  2685. "uri": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CNzob20bQNbT0akArkIXyE6DuBY+DMxkJDL6xHdDAwxS3mxrXb+4CwGZvTiidIMlmXWIExTSooiApPQK0Gi",
  2686. "user-agent": "",
  2687. "method": "POST",
  2688. "host": "report.wallpaper.shqingzao.com",
  2689. "version": "1.1",
  2690. "path": "/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CNzob20bQNbT0akArkIXyE6DuBY+DMxkJDL6xHdDAwxS3mxrXb+4CwGZvTiidIMlmXWIExTSooiApPQK0Gi",
  2691. "data": "POST /wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CNzob20bQNbT0akArkIXyE6DuBY+DMxkJDL6xHdDAwxS3mxrXb+4CwGZvTiidIMlmXWIExTSooiApPQK0Gi HTTP/1.1\r\nHost: report.wallpaper.shqingzao.com\r\nAccept: */*\r\nContent-Length: 0\r\n\r\n",
  2692. "port": 80
  2693.  
  2694.  
  2695. "count": 1,
  2696. "body": "",
  2697. "uri": "http://report.wallpaper.shqingzao.com/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CM8/unvVgRrCAXxDL52LUsZf7IL7xQXpr/L6xHdDBEVdUKB8gSUw1dDNw==",
  2698. "user-agent": "",
  2699. "method": "POST",
  2700. "host": "report.wallpaper.shqingzao.com",
  2701. "version": "1.1",
  2702. "path": "/wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CM8/unvVgRrCAXxDL52LUsZf7IL7xQXpr/L6xHdDBEVdUKB8gSUw1dDNw==",
  2703. "data": "POST /wallpaper/ex_service?code=w31nJMzQBFx8oMdUR8yuFdpDJ1QQJ2pQjPpXDfaHDDXkEUR8wVdRwpneaLMNqtdYMGKfm0VelB3lU372Hb1KTCugHEjH2uxHNx1jptzsOzw4vXHpzFyDjLI31r8rXLrewtVW0PURpxyZmza2V5E1jZQXlrBzJMeZ9Td4nMOjgxBdvnCL3kOr7xF6iym/8Hm09vThrSL+g34FtHnboAVzri0EXuzPcQ/+MeCD4fhzU8Oyu/etlOKu2Rk4PDU21A5RIkaY7FHUYX8I2460pNXhd3siM9gleGw5bUIrOwjxneTEGzEMfEHL6CM8/unvVgRrCAXxDL52LUsZf7IL7xQXpr/L6xHdDBEVdUKB8gSUw1dDNw== HTTP/1.1\r\nHost: report.wallpaper.shqingzao.com\r\nAccept: */*\r\nContent-Length: 0\r\n\r\n",
  2704. "port": 80
  2705.  
  2706.  
  2707. "count": 1,
  2708. "body": "",
  2709. "uri": "http://www.msftncsi.com/ncsi.txt",
  2710. "user-agent": "Microsoft NCSI",
  2711. "method": "GET",
  2712. "host": "www.msftncsi.com",
  2713. "version": "1.1",
  2714. "path": "/ncsi.txt",
  2715. "data": "GET /ncsi.txt HTTP/1.1\r\nConnection: Close\r\nUser-Agent: Microsoft NCSI\r\nHost: www.msftncsi.com\r\n\r\n",
  2716. "port": 80
  2717.  
  2718.  
  2719.  
  2720. * Network Communication - SMTP:
  2721.  
  2722. * Network Communication - Hosts:
  2723.  
  2724. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment