Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Razy"
- * MalScore: 10.0
- * File Name: "Exes_c1fe4073f9b75321d9070f11bcb5b99a.exe"
- * File Size: 1600512
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- * SHA256: "2060d572a6eef2933b9e79d4f6a8b3ff6c98a2f0cd4c76d0e7396c63f3948040"
- * MD5: "c1fe4073f9b75321d9070f11bcb5b99a"
- * SHA1: "cfbbf9518200f1ea5ca88c5b96f2beaa65b64861"
- * SHA512: "aec6489a76ae90995bf1c8595f43c7916bafe8f65433089ab16f115f70a0df6da8fb793cc93bb61d844d026f2f5a725397ae6e6838fede4c147e02a3042d8bed"
- * CRC32: "F162541D"
- * SSDEEP: "49152:zwGAaPn5kEfE0PwLxSBWUdmchYneirW3O4VYs:zdAaP5kEfE0YLx1smcinrUO4as"
- * Process Execution:
- "Exes_c1fe4073f9b75321d9070f11bcb5b99a.exe",
- "WMIC.exe",
- "svchost.exe",
- "WmiPrvSE.exe"
- * Executed Commands:
- "wmic csproduct get UUID",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Attempts to connect to a dead IP:Port (7 unique times)",
- "Details":
- "IP": "118.193.104.9:80"
- "IP": "104.192.108.21:80"
- "IP": "221.230.141.50:443"
- "IP": "221.230.141.50:80"
- "IP": "72.21.91.29:80"
- "IP": "65.153.158.164:80"
- "IP": "103.8.207.107:80"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
- "suspicious_request": "http://dlres-a.iyims.com/upload/20190707115452/downloading_bg1.gif"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
- "suspicious_request": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
- "suspicious_request": "http://dl.360safe.com/ludashi/inst_buychannel_18.exe"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
- "suspicious_request": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
- "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D"
- "suspicious_request": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
- "suspicious_request": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0"
- "suspicious_request": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25"
- "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8"
- "suspicious_request": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
- "url": "http://dlres-a.iyims.com/upload/20190707115452/downloading_bg1.gif"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
- "url": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe"
- "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
- "url": "http://dl.360safe.com/ludashi/inst_buychannel_18.exe"
- "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
- "url": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe"
- "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D"
- "url": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D"
- "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
- "url": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0"
- "url": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe"
- "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25"
- "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8"
- "url": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe"
- "Description": "Unconventionial language used in binary resources: Chinese (Simplified)",
- "Details":
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: UPX1, entropy: 7.91, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0016f000, virtual_size: 0x0016f000"
- "Description": "The executable is compressed using UPX",
- "Details":
- "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0039c000"
- "Description": "Collects information about installed applications",
- "Details":
- "Program": "Google Update Helper"
- "Program": "Microsoft Excel MUI 2013"
- "Program": "Microsoft Outlook MUI 2013"
- "Program": "Google Chrome"
- "Program": "Adobe Flash Player 29 NPAPI"
- "Program": "Adobe Flash Player 29 ActiveX"
- "Program": "Microsoft DCF MUI 2013"
- "Program": "Microsoft Access MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- "Program": "Adobe Acrobat Reader DC"
- "Program": "Microsoft Publisher MUI 2013"
- "Program": "Microsoft Office Shared MUI 2013"
- "Program": "Microsoft Office OSM MUI 2013"
- "Program": "Microsoft InfoPath MUI 2013"
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
- "Program": "Microsoft Word MUI 2013"
- "Program": "Microsoft Groove MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- "Program": "Microsoft Office OSM UX MUI 2013"
- "Program": "Java Auto Updater"
- "Program": "Microsoft PowerPoint MUI 2013"
- "Program": "Microsoft Office Professional Plus 2013"
- "Program": "Adobe Refresh Manager"
- "Program": "Microsoft Office Proofing 2013"
- "Program": "Microsoft Lync MUI 2013"
- "Program": "Microsoft OneNote MUI 2013"
- "Description": "File has been identified by 26 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Gen:Variant.Razy.529694"
- "FireEye": "Gen:Variant.Razy.529694"
- "CAT-QuickHeal": "Trojan.Multi"
- "ALYac": "Gen:Variant.Razy.529694"
- "Arcabit": "Trojan.Razy.D8151E"
- "Symantec": "Trojan.Gen.2"
- "Avast": "Win32:Malware-gen"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "BitDefender": "Gen:Variant.Razy.529694"
- "AegisLab": "Trojan.Multi.Generic.4!c"
- "Tencent": "Win32.Trojan.Generic.Szlm"
- "Ad-Aware": "Gen:Variant.Razy.529694"
- "Emsisoft": "Gen:Variant.Razy.529694 (B)"
- "VIPRE": "Trojan.Win32.Generic!BT"
- "McAfee-GW-Edition": "BehavesLike.Win32.Dropper.tc"
- "MAX": "malware (ai score=100)"
- "Microsoft": "Trojan:Win32/Tiggre!plock"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "GData": "Gen:Variant.Razy.529694"
- "AhnLab-V3": "Malware/Gen.Generic.C3320517"
- "McAfee": "Artemis!C1FE4073F9B7"
- "TrendMicro-HouseCall": "TROJ_GEN.R020H09G819"
- "Rising": "Dropper.Agent!8.2F (TFE:5:FfoKNBWXTLE)"
- "AVG": "Win32:Malware-gen"
- "CrowdStrike": "win/malicious_confidence_60% (W)"
- "Qihoo-360": "HEUR/QVM11.1.7FCD.Malware.Gen"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\downloading_bg11.gif",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\LDSGameMasterInstRoad_2111011.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\inst_buychannel_181.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\VZip_7241.exe",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C8551E3A51B70BA2C25E09D550E69370",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\C8551E3A51B70BA2C25E09D550E69370",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\6789zip_1311.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\FunInstaller_PS_01098011.exe",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\WMIDataDevice"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "dlres-a.iyims.com",
- "answers":
- "data": "103.8.207.102",
- "type": "A"
- "data": "103.8.207.103",
- "type": "A"
- "data": "103.8.207.100",
- "type": "A"
- "data": "103.8.207.101",
- "type": "A"
- "data": "103.8.207.106",
- "type": "A"
- "data": "103.8.207.107",
- "type": "A"
- "data": "103.8.207.104",
- "type": "A"
- "data": "103.8.207.105",
- "type": "A"
- "data": "dlres-a.iyims.com.w.kunluncan.com",
- "type": "CNAME"
- "data": "112.19.0.228",
- "type": "A"
- "data": "103.228.208.115",
- "type": "A"
- "data": "103.228.208.116",
- "type": "A"
- "data": "103.228.208.185",
- "type": "A"
- "data": "103.228.208.86",
- "type": "A"
- "data": "103.228.208.118",
- "type": "A"
- "data": "103.228.208.84",
- "type": "A"
- "data": "103.228.208.119",
- "type": "A"
- "type": "A",
- "request": "dl.ludashi.com",
- "answers":
- "data": "dl.360safe.com",
- "type": "CNAME"
- "data": "104.192.108.21",
- "type": "A"
- "data": "dl.qhcdn.com",
- "type": "CNAME"
- "data": "104.192.108.18",
- "type": "A"
- "type": "A",
- "request": "dl.360safe.com",
- "answers":
- "data": "104.192.108.21",
- "type": "A"
- "data": "dl.qhcdn.com",
- "type": "CNAME"
- "data": "104.192.108.18",
- "type": "A"
- "type": "A",
- "request": "down.zhanfukeji.cn",
- "answers":
- "data": "221.230.141.50",
- "type": "A"
- "data": "down.zhanfukeji.cn.wsdvs.com",
- "type": "CNAME"
- "type": "A",
- "request": "down.soft.6789.net",
- "answers":
- "data": "221.230.141.50",
- "type": "A"
- "data": "down.soft.6789.net.wsdvs.com",
- "type": "CNAME"
- "type": "A",
- "request": "ocsp2.digicert.com",
- "answers":
- "data": "cs9.wac.phicdn.net",
- "type": "CNAME"
- "data": "72.21.91.29",
- "type": "A"
- "type": "A",
- "request": "partner.funshion.com",
- "answers":
- "data": "118.193.104.10",
- "type": "A"
- "data": "118.193.104.9",
- "type": "A"
- "type": "A",
- "request": "downloads.funshion.net",
- "answers":
- "data": "65.153.196.229",
- "type": "A"
- "data": "65.153.196.227",
- "type": "A"
- "data": "65.153.196.228",
- "type": "A"
- "data": "65.153.158.164",
- "type": "A"
- "data": "65.153.158.172",
- "type": "A"
- "data": "u887.v.qingcdn.com",
- "type": "CNAME"
- "data": "65.153.196.230",
- "type": "A"
- "data": "downloads.funshion.net.qingcdn.com",
- "type": "CNAME"
- "type": "A",
- "request": "down1.wallpaper.shqingzao.com",
- "answers":
- "data": "123.6.2.238",
- "type": "A"
- "data": "113.59.43.98",
- "type": "A"
- "data": "220.194.79.107",
- "type": "A"
- "data": "59.80.39.108",
- "type": "A"
- "data": "218.11.11.221",
- "type": "A"
- "data": "123.6.2.101",
- "type": "A"
- "data": "218.11.11.246",
- "type": "A"
- "data": "220.194.87.190",
- "type": "A"
- "data": "1.189.213.92",
- "type": "A"
- "data": "218.11.11.245",
- "type": "A"
- "data": "121.29.54.234",
- "type": "A"
- "data": "121.29.54.65",
- "type": "A"
- "data": "220.194.79.73",
- "type": "A"
- "data": "1835929.p23.tc.cdntip.com",
- "type": "CNAME"
- "data": "down1.wallpaper.shqingzao.com.cdn.dnsv1.com",
- "type": "CNAME"
- "data": "218.11.8.104",
- "type": "A"
- "data": "211.91.160.204",
- "type": "A"
- "type": "A",
- "request": "cd002.www.duba.net",
- "answers":
- "data": "sal.topgslb.com",
- "type": "CNAME"
- "data": "60.174.241.133",
- "type": "A"
- "data": "cd002.www.duba.net.scc.topgslb.com",
- "type": "CNAME"
- "data": "cd002.www.duba.net.spdydns.com",
- "type": "CNAME"
- * Domains:
- "ip": "65.153.158.164",
- "domain": "downloads.funshion.net"
- "ip": "113.215.225.29",
- "domain": "dlres-a.iyims.com"
- "ip": "72.21.91.29",
- "domain": "ocsp2.digicert.com"
- "ip": "221.230.141.50",
- "domain": "down.soft.6789.net"
- "ip": "221.230.141.50",
- "domain": "down.zhanfukeji.cn"
- "ip": "113.59.43.98",
- "domain": "down1.wallpaper.shqingzao.com"
- "ip": "118.193.104.9",
- "domain": "partner.funshion.com"
- "ip": "104.192.108.18",
- "domain": "dl.360safe.com"
- "ip": "60.174.241.133",
- "domain": "cd002.www.duba.net"
- "ip": "104.192.108.18",
- "domain": "dl.ludashi.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
- "data": "GET /api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://dlres-a.iyims.com/upload/20190707115452/downloading_bg1.gif",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "dlres-a.iyims.com",
- "version": "1.1",
- "path": "/upload/20190707115452/downloading_bg1.gif",
- "data": "GET /upload/20190707115452/downloading_bg1.gif HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dlres-a.iyims.com\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "dl.ludashi.com",
- "version": "1.1",
- "path": "/gamemaster/LDSGameMasterInstRoad_211101.exe",
- "data": "GET /gamemaster/LDSGameMasterInstRoad_211101.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
- "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://dl.360safe.com/ludashi/inst_buychannel_18.exe",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "dl.360safe.com",
- "version": "1.1",
- "path": "/ludashi/inst_buychannel_18.exe",
- "data": "GET /ludashi/inst_buychannel_18.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
- "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "down.zhanfukeji.cn",
- "version": "1.1",
- "path": "/VZip/ver_1.0.1.6/channel/VZip_724.exe",
- "data": "GET /VZip/ver_1.0.1.6/channel/VZip_724.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: down.zhanfukeji.cn\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
- "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp2.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp2.digicert.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
- "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 2,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "partner.funshion.com",
- "version": "1.1",
- "path": "/partner/tk_download.php?id=9801\\xa0",
- "data": "GET /partner/tk_download.php?id=9801\\xa0 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: partner.funshion.com\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "downloads.funshion.net",
- "version": "1.1",
- "path": "/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe",
- "data": "GET /tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: downloads.funshion.net\r\n\r\n",
- "port": 80
- "count": 2,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
- "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
- "method": "GET",
- "host": "47.96.116.228:8081",
- "version": "1.1",
- "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8",
- "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
- "port": 8081
- "count": 1,
- "body": "",
- "uri": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "cd002.www.duba.net",
- "version": "1.1",
- "path": "/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe",
- "data": "GET /duba/install/2011/ever/duba_u21055977_sv1_115_1.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: cd002.www.duba.net\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment