paladin316

Exes_c1fe4073f9b75321d9070f11bcb5b99a_exe_2019-07-20_08_30.txt

Jul 20th, 2019
2,376
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 46.27 KB | None | 0 0
  1.  
  2. * MalFamily: "Razy"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_c1fe4073f9b75321d9070f11bcb5b99a.exe"
  7. * File Size: 1600512
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  9. * SHA256: "2060d572a6eef2933b9e79d4f6a8b3ff6c98a2f0cd4c76d0e7396c63f3948040"
  10. * MD5: "c1fe4073f9b75321d9070f11bcb5b99a"
  11. * SHA1: "cfbbf9518200f1ea5ca88c5b96f2beaa65b64861"
  12. * SHA512: "aec6489a76ae90995bf1c8595f43c7916bafe8f65433089ab16f115f70a0df6da8fb793cc93bb61d844d026f2f5a725397ae6e6838fede4c147e02a3042d8bed"
  13. * CRC32: "F162541D"
  14. * SSDEEP: "49152:zwGAaPn5kEfE0PwLxSBWUdmchYneirW3O4VYs:zdAaP5kEfE0YLx1smcinrUO4as"
  15.  
  16. * Process Execution:
  17. "Exes_c1fe4073f9b75321d9070f11bcb5b99a.exe",
  18. "WMIC.exe",
  19. "svchost.exe",
  20. "WmiPrvSE.exe"
  21.  
  22.  
  23. * Executed Commands:
  24. "wmic csproduct get UUID",
  25. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
  26.  
  27.  
  28. * Signatures Detected:
  29.  
  30. "Description": "Creates RWX memory",
  31. "Details":
  32.  
  33.  
  34. "Description": "A process attempted to delay the analysis task.",
  35. "Details":
  36.  
  37. "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  38.  
  39.  
  40.  
  41.  
  42. "Description": "Attempts to connect to a dead IP:Port (7 unique times)",
  43. "Details":
  44.  
  45. "IP": "118.193.104.9:80"
  46.  
  47.  
  48. "IP": "104.192.108.21:80"
  49.  
  50.  
  51. "IP": "221.230.141.50:443"
  52.  
  53.  
  54. "IP": "221.230.141.50:80"
  55.  
  56.  
  57. "IP": "72.21.91.29:80"
  58.  
  59.  
  60. "IP": "65.153.158.164:80"
  61.  
  62.  
  63. "IP": "103.8.207.107:80"
  64.  
  65.  
  66.  
  67.  
  68. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  69. "Details":
  70.  
  71. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  72.  
  73.  
  74. "suspicious_request": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  75.  
  76.  
  77. "suspicious_request": "http://dlres-a.iyims.com/upload/20190707115452/downloading_bg1.gif"
  78.  
  79.  
  80. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
  81.  
  82.  
  83. "suspicious_request": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe"
  84.  
  85.  
  86. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
  87.  
  88.  
  89. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
  90.  
  91.  
  92. "suspicious_request": "http://dl.360safe.com/ludashi/inst_buychannel_18.exe"
  93.  
  94.  
  95. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
  96.  
  97.  
  98. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
  99.  
  100.  
  101. "suspicious_request": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe"
  102.  
  103.  
  104. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
  105.  
  106.  
  107. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
  108.  
  109.  
  110. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D"
  111.  
  112.  
  113. "suspicious_request": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D"
  114.  
  115.  
  116. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
  117.  
  118.  
  119. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
  120.  
  121.  
  122. "suspicious_request": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0"
  123.  
  124.  
  125. "suspicious_request": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe"
  126.  
  127.  
  128. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
  129.  
  130.  
  131. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25"
  132.  
  133.  
  134. "suspicious_request": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8"
  135.  
  136.  
  137. "suspicious_request": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe"
  138.  
  139.  
  140.  
  141.  
  142. "Description": "Performs some HTTP requests",
  143. "Details":
  144.  
  145. "url": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0"
  146.  
  147.  
  148. "url": "http://dlres-a.iyims.com/upload/20190707115452/downloading_bg1.gif"
  149.  
  150.  
  151. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
  152.  
  153.  
  154. "url": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe"
  155.  
  156.  
  157. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16"
  158.  
  159.  
  160. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
  161.  
  162.  
  163. "url": "http://dl.360safe.com/ludashi/inst_buychannel_18.exe"
  164.  
  165.  
  166. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17"
  167.  
  168.  
  169. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
  170.  
  171.  
  172. "url": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe"
  173.  
  174.  
  175. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7"
  176.  
  177.  
  178. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
  179.  
  180.  
  181. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D"
  182.  
  183.  
  184. "url": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D"
  185.  
  186.  
  187. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37"
  188.  
  189.  
  190. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
  191.  
  192.  
  193. "url": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0"
  194.  
  195.  
  196. "url": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe"
  197.  
  198.  
  199. "url": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13"
  200.  
  201.  
  202. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25"
  203.  
  204.  
  205. "url": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8"
  206.  
  207.  
  208. "url": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe"
  209.  
  210.  
  211.  
  212.  
  213. "Description": "Unconventionial language used in binary resources: Chinese (Simplified)",
  214. "Details":
  215.  
  216.  
  217. "Description": "The binary likely contains encrypted or compressed data.",
  218. "Details":
  219.  
  220. "section": "name: UPX1, entropy: 7.91, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0016f000, virtual_size: 0x0016f000"
  221.  
  222.  
  223.  
  224.  
  225. "Description": "The executable is compressed using UPX",
  226. "Details":
  227.  
  228. "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0039c000"
  229.  
  230.  
  231.  
  232.  
  233. "Description": "Collects information about installed applications",
  234. "Details":
  235.  
  236. "Program": "Google Update Helper"
  237.  
  238.  
  239. "Program": "Microsoft Excel MUI 2013"
  240.  
  241.  
  242. "Program": "Microsoft Outlook MUI 2013"
  243.  
  244.  
  245.  
  246.  
  247. "Program": "Google Chrome"
  248.  
  249.  
  250. "Program": "Adobe Flash Player 29 NPAPI"
  251.  
  252.  
  253. "Program": "Adobe Flash Player 29 ActiveX"
  254.  
  255.  
  256. "Program": "Microsoft DCF MUI 2013"
  257.  
  258.  
  259. "Program": "Microsoft Access MUI 2013"
  260.  
  261.  
  262. "Program": "Microsoft Office Proofing Tools 2013 - English"
  263.  
  264.  
  265. "Program": "Adobe Acrobat Reader DC"
  266.  
  267.  
  268. "Program": "Microsoft Publisher MUI 2013"
  269.  
  270.  
  271. "Program": "Microsoft Office Shared MUI 2013"
  272.  
  273.  
  274. "Program": "Microsoft Office OSM MUI 2013"
  275.  
  276.  
  277. "Program": "Microsoft InfoPath MUI 2013"
  278.  
  279.  
  280. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  281.  
  282.  
  283. "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
  284.  
  285.  
  286. "Program": "Microsoft Word MUI 2013"
  287.  
  288.  
  289. "Program": "Microsoft Groove MUI 2013"
  290.  
  291.  
  292. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
  293.  
  294.  
  295.  
  296.  
  297. "Program": "Microsoft Access Setup Metadata MUI 2013"
  298.  
  299.  
  300. "Program": "Microsoft Office OSM UX MUI 2013"
  301.  
  302.  
  303. "Program": "Java Auto Updater"
  304.  
  305.  
  306. "Program": "Microsoft PowerPoint MUI 2013"
  307.  
  308.  
  309. "Program": "Microsoft Office Professional Plus 2013"
  310.  
  311.  
  312. "Program": "Adobe Refresh Manager"
  313.  
  314.  
  315. "Program": "Microsoft Office Proofing 2013"
  316.  
  317.  
  318. "Program": "Microsoft Lync MUI 2013"
  319.  
  320.  
  321.  
  322.  
  323. "Program": "Microsoft OneNote MUI 2013"
  324.  
  325.  
  326.  
  327.  
  328. "Description": "File has been identified by 26 Antiviruses on VirusTotal as malicious",
  329. "Details":
  330.  
  331. "MicroWorld-eScan": "Gen:Variant.Razy.529694"
  332.  
  333.  
  334. "FireEye": "Gen:Variant.Razy.529694"
  335.  
  336.  
  337. "CAT-QuickHeal": "Trojan.Multi"
  338.  
  339.  
  340. "ALYac": "Gen:Variant.Razy.529694"
  341.  
  342.  
  343. "Arcabit": "Trojan.Razy.D8151E"
  344.  
  345.  
  346. "Symantec": "Trojan.Gen.2"
  347.  
  348.  
  349. "Avast": "Win32:Malware-gen"
  350.  
  351.  
  352. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  353.  
  354.  
  355. "BitDefender": "Gen:Variant.Razy.529694"
  356.  
  357.  
  358. "AegisLab": "Trojan.Multi.Generic.4!c"
  359.  
  360.  
  361. "Tencent": "Win32.Trojan.Generic.Szlm"
  362.  
  363.  
  364. "Ad-Aware": "Gen:Variant.Razy.529694"
  365.  
  366.  
  367. "Emsisoft": "Gen:Variant.Razy.529694 (B)"
  368.  
  369.  
  370. "VIPRE": "Trojan.Win32.Generic!BT"
  371.  
  372.  
  373. "McAfee-GW-Edition": "BehavesLike.Win32.Dropper.tc"
  374.  
  375.  
  376. "MAX": "malware (ai score=100)"
  377.  
  378.  
  379. "Microsoft": "Trojan:Win32/Tiggre!plock"
  380.  
  381.  
  382. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  383.  
  384.  
  385. "GData": "Gen:Variant.Razy.529694"
  386.  
  387.  
  388. "AhnLab-V3": "Malware/Gen.Generic.C3320517"
  389.  
  390.  
  391. "McAfee": "Artemis!C1FE4073F9B7"
  392.  
  393.  
  394. "TrendMicro-HouseCall": "TROJ_GEN.R020H09G819"
  395.  
  396.  
  397. "Rising": "Dropper.Agent!8.2F (TFE:5:FfoKNBWXTLE)"
  398.  
  399.  
  400. "AVG": "Win32:Malware-gen"
  401.  
  402.  
  403. "CrowdStrike": "win/malicious_confidence_60% (W)"
  404.  
  405.  
  406. "Qihoo-360": "HEUR/QVM11.1.7FCD.Malware.Gen"
  407.  
  408.  
  409.  
  410.  
  411.  
  412. * Started Service:
  413.  
  414. * Mutexes:
  415. "CicLoadWinStaWinSta0",
  416. "Local\\MSCTF.CtfMonitorInstMutexDefault1"
  417.  
  418.  
  419. * Modified Files:
  420. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\downloading_bg11.gif",
  421. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\LDSGameMasterInstRoad_2111011.exe",
  422. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\inst_buychannel_181.exe",
  423. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\VZip_7241.exe",
  424. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D",
  425. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D",
  426. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\C8551E3A51B70BA2C25E09D550E69370",
  427. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\C8551E3A51B70BA2C25E09D550E69370",
  428. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\6789zip_1311.exe",
  429. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\FunInstaller_PS_01098011.exe",
  430. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  431. "\\??\\WMIDataDevice"
  432.  
  433.  
  434. * Deleted Files:
  435.  
  436. * Modified Registry Keys:
  437.  
  438. * Deleted Registry Keys:
  439.  
  440. * DNS Communications:
  441.  
  442. "type": "A",
  443. "request": "dlres-a.iyims.com",
  444. "answers":
  445.  
  446. "data": "103.8.207.102",
  447. "type": "A"
  448.  
  449.  
  450. "data": "103.8.207.103",
  451. "type": "A"
  452.  
  453.  
  454. "data": "103.8.207.100",
  455. "type": "A"
  456.  
  457.  
  458. "data": "103.8.207.101",
  459. "type": "A"
  460.  
  461.  
  462. "data": "103.8.207.106",
  463. "type": "A"
  464.  
  465.  
  466. "data": "103.8.207.107",
  467. "type": "A"
  468.  
  469.  
  470. "data": "103.8.207.104",
  471. "type": "A"
  472.  
  473.  
  474. "data": "103.8.207.105",
  475. "type": "A"
  476.  
  477.  
  478. "data": "dlres-a.iyims.com.w.kunluncan.com",
  479. "type": "CNAME"
  480.  
  481.  
  482. "data": "112.19.0.228",
  483. "type": "A"
  484.  
  485.  
  486. "data": "103.228.208.115",
  487. "type": "A"
  488.  
  489.  
  490. "data": "103.228.208.116",
  491. "type": "A"
  492.  
  493.  
  494. "data": "103.228.208.185",
  495. "type": "A"
  496.  
  497.  
  498. "data": "103.228.208.86",
  499. "type": "A"
  500.  
  501.  
  502. "data": "103.228.208.118",
  503. "type": "A"
  504.  
  505.  
  506. "data": "103.228.208.84",
  507. "type": "A"
  508.  
  509.  
  510. "data": "103.228.208.119",
  511. "type": "A"
  512.  
  513.  
  514.  
  515.  
  516. "type": "A",
  517. "request": "dl.ludashi.com",
  518. "answers":
  519.  
  520. "data": "dl.360safe.com",
  521. "type": "CNAME"
  522.  
  523.  
  524. "data": "104.192.108.21",
  525. "type": "A"
  526.  
  527.  
  528. "data": "dl.qhcdn.com",
  529. "type": "CNAME"
  530.  
  531.  
  532. "data": "104.192.108.18",
  533. "type": "A"
  534.  
  535.  
  536.  
  537.  
  538. "type": "A",
  539. "request": "dl.360safe.com",
  540. "answers":
  541.  
  542. "data": "104.192.108.21",
  543. "type": "A"
  544.  
  545.  
  546. "data": "dl.qhcdn.com",
  547. "type": "CNAME"
  548.  
  549.  
  550. "data": "104.192.108.18",
  551. "type": "A"
  552.  
  553.  
  554.  
  555.  
  556. "type": "A",
  557. "request": "down.zhanfukeji.cn",
  558. "answers":
  559.  
  560. "data": "221.230.141.50",
  561. "type": "A"
  562.  
  563.  
  564. "data": "down.zhanfukeji.cn.wsdvs.com",
  565. "type": "CNAME"
  566.  
  567.  
  568.  
  569.  
  570. "type": "A",
  571. "request": "down.soft.6789.net",
  572. "answers":
  573.  
  574. "data": "221.230.141.50",
  575. "type": "A"
  576.  
  577.  
  578. "data": "down.soft.6789.net.wsdvs.com",
  579. "type": "CNAME"
  580.  
  581.  
  582.  
  583.  
  584. "type": "A",
  585. "request": "ocsp2.digicert.com",
  586. "answers":
  587.  
  588. "data": "cs9.wac.phicdn.net",
  589. "type": "CNAME"
  590.  
  591.  
  592. "data": "72.21.91.29",
  593. "type": "A"
  594.  
  595.  
  596.  
  597.  
  598. "type": "A",
  599. "request": "partner.funshion.com",
  600. "answers":
  601.  
  602. "data": "118.193.104.10",
  603. "type": "A"
  604.  
  605.  
  606. "data": "118.193.104.9",
  607. "type": "A"
  608.  
  609.  
  610.  
  611.  
  612. "type": "A",
  613. "request": "downloads.funshion.net",
  614. "answers":
  615.  
  616. "data": "65.153.196.229",
  617. "type": "A"
  618.  
  619.  
  620. "data": "65.153.196.227",
  621. "type": "A"
  622.  
  623.  
  624. "data": "65.153.196.228",
  625. "type": "A"
  626.  
  627.  
  628. "data": "65.153.158.164",
  629. "type": "A"
  630.  
  631.  
  632. "data": "65.153.158.172",
  633. "type": "A"
  634.  
  635.  
  636. "data": "u887.v.qingcdn.com",
  637. "type": "CNAME"
  638.  
  639.  
  640. "data": "65.153.196.230",
  641. "type": "A"
  642.  
  643.  
  644. "data": "downloads.funshion.net.qingcdn.com",
  645. "type": "CNAME"
  646.  
  647.  
  648.  
  649.  
  650. "type": "A",
  651. "request": "down1.wallpaper.shqingzao.com",
  652. "answers":
  653.  
  654. "data": "123.6.2.238",
  655. "type": "A"
  656.  
  657.  
  658. "data": "113.59.43.98",
  659. "type": "A"
  660.  
  661.  
  662. "data": "220.194.79.107",
  663. "type": "A"
  664.  
  665.  
  666. "data": "59.80.39.108",
  667. "type": "A"
  668.  
  669.  
  670. "data": "218.11.11.221",
  671. "type": "A"
  672.  
  673.  
  674. "data": "123.6.2.101",
  675. "type": "A"
  676.  
  677.  
  678. "data": "218.11.11.246",
  679. "type": "A"
  680.  
  681.  
  682. "data": "220.194.87.190",
  683. "type": "A"
  684.  
  685.  
  686. "data": "1.189.213.92",
  687. "type": "A"
  688.  
  689.  
  690. "data": "218.11.11.245",
  691. "type": "A"
  692.  
  693.  
  694. "data": "121.29.54.234",
  695. "type": "A"
  696.  
  697.  
  698. "data": "121.29.54.65",
  699. "type": "A"
  700.  
  701.  
  702. "data": "220.194.79.73",
  703. "type": "A"
  704.  
  705.  
  706. "data": "1835929.p23.tc.cdntip.com",
  707. "type": "CNAME"
  708.  
  709.  
  710. "data": "down1.wallpaper.shqingzao.com.cdn.dnsv1.com",
  711. "type": "CNAME"
  712.  
  713.  
  714. "data": "218.11.8.104",
  715. "type": "A"
  716.  
  717.  
  718. "data": "211.91.160.204",
  719. "type": "A"
  720.  
  721.  
  722.  
  723.  
  724. "type": "A",
  725. "request": "cd002.www.duba.net",
  726. "answers":
  727.  
  728. "data": "sal.topgslb.com",
  729. "type": "CNAME"
  730.  
  731.  
  732. "data": "60.174.241.133",
  733. "type": "A"
  734.  
  735.  
  736. "data": "cd002.www.duba.net.scc.topgslb.com",
  737. "type": "CNAME"
  738.  
  739.  
  740. "data": "cd002.www.duba.net.spdydns.com",
  741. "type": "CNAME"
  742.  
  743.  
  744.  
  745.  
  746.  
  747. * Domains:
  748.  
  749. "ip": "65.153.158.164",
  750. "domain": "downloads.funshion.net"
  751.  
  752.  
  753. "ip": "113.215.225.29",
  754. "domain": "dlres-a.iyims.com"
  755.  
  756.  
  757. "ip": "72.21.91.29",
  758. "domain": "ocsp2.digicert.com"
  759.  
  760.  
  761. "ip": "221.230.141.50",
  762. "domain": "down.soft.6789.net"
  763.  
  764.  
  765. "ip": "221.230.141.50",
  766. "domain": "down.zhanfukeji.cn"
  767.  
  768.  
  769. "ip": "113.59.43.98",
  770. "domain": "down1.wallpaper.shqingzao.com"
  771.  
  772.  
  773. "ip": "118.193.104.9",
  774. "domain": "partner.funshion.com"
  775.  
  776.  
  777. "ip": "104.192.108.18",
  778. "domain": "dl.360safe.com"
  779.  
  780.  
  781. "ip": "60.174.241.133",
  782. "domain": "cd002.www.duba.net"
  783.  
  784.  
  785. "ip": "104.192.108.18",
  786. "domain": "dl.ludashi.com"
  787.  
  788.  
  789.  
  790. * Network Communication - ICMP:
  791.  
  792. * Network Communication - HTTP:
  793.  
  794. "count": 1,
  795. "body": "",
  796. "uri": "http://47.96.116.228:8081/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  797. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  798. "method": "GET",
  799. "host": "47.96.116.228:8081",
  800. "version": "1.1",
  801. "path": "/api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0",
  802. "data": "GET /api/software/getMain?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  803. "port": 8081
  804.  
  805.  
  806. "count": 1,
  807. "body": "",
  808. "uri": "http://dlres-a.iyims.com/upload/20190707115452/downloading_bg1.gif",
  809. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  810. "method": "GET",
  811. "host": "dlres-a.iyims.com",
  812. "version": "1.1",
  813. "path": "/upload/20190707115452/downloading_bg1.gif",
  814. "data": "GET /upload/20190707115452/downloading_bg1.gif HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dlres-a.iyims.com\r\nConnection: Keep-Alive\r\n\r\n",
  815. "port": 80
  816.  
  817.  
  818. "count": 1,
  819. "body": "",
  820. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
  821. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  822. "method": "GET",
  823. "host": "47.96.116.228:8081",
  824. "version": "1.1",
  825. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
  826. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  827. "port": 8081
  828.  
  829.  
  830. "count": 1,
  831. "body": "",
  832. "uri": "http://dl.ludashi.com/gamemaster/LDSGameMasterInstRoad_211101.exe",
  833. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  834. "method": "GET",
  835. "host": "dl.ludashi.com",
  836. "version": "1.1",
  837. "path": "/gamemaster/LDSGameMasterInstRoad_211101.exe",
  838. "data": "GET /gamemaster/LDSGameMasterInstRoad_211101.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dl.ludashi.com\r\nConnection: Keep-Alive\r\n\r\n",
  839. "port": 80
  840.  
  841.  
  842. "count": 1,
  843. "body": "",
  844. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
  845. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  846. "method": "GET",
  847. "host": "47.96.116.228:8081",
  848. "version": "1.1",
  849. "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16",
  850. "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=16 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  851. "port": 8081
  852.  
  853.  
  854. "count": 1,
  855. "body": "",
  856. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
  857. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  858. "method": "GET",
  859. "host": "47.96.116.228:8081",
  860. "version": "1.1",
  861. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
  862. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  863. "port": 8081
  864.  
  865.  
  866. "count": 1,
  867. "body": "",
  868. "uri": "http://dl.360safe.com/ludashi/inst_buychannel_18.exe",
  869. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  870. "method": "GET",
  871. "host": "dl.360safe.com",
  872. "version": "1.1",
  873. "path": "/ludashi/inst_buychannel_18.exe",
  874. "data": "GET /ludashi/inst_buychannel_18.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: dl.360safe.com\r\nConnection: Keep-Alive\r\n\r\n",
  875. "port": 80
  876.  
  877.  
  878. "count": 1,
  879. "body": "",
  880. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
  881. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  882. "method": "GET",
  883. "host": "47.96.116.228:8081",
  884. "version": "1.1",
  885. "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17",
  886. "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=17 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  887. "port": 8081
  888.  
  889.  
  890. "count": 1,
  891. "body": "",
  892. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
  893. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  894. "method": "GET",
  895. "host": "47.96.116.228:8081",
  896. "version": "1.1",
  897. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
  898. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  899. "port": 8081
  900.  
  901.  
  902. "count": 1,
  903. "body": "",
  904. "uri": "http://down.zhanfukeji.cn/VZip/ver_1.0.1.6/channel/VZip_724.exe",
  905. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  906. "method": "GET",
  907. "host": "down.zhanfukeji.cn",
  908. "version": "1.1",
  909. "path": "/VZip/ver_1.0.1.6/channel/VZip_724.exe",
  910. "data": "GET /VZip/ver_1.0.1.6/channel/VZip_724.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: down.zhanfukeji.cn\r\nConnection: Keep-Alive\r\n\r\n",
  911. "port": 80
  912.  
  913.  
  914. "count": 1,
  915. "body": "",
  916. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
  917. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  918. "method": "GET",
  919. "host": "47.96.116.228:8081",
  920. "version": "1.1",
  921. "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7",
  922. "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=7 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  923. "port": 8081
  924.  
  925.  
  926. "count": 1,
  927. "body": "",
  928. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
  929. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  930. "method": "GET",
  931. "host": "47.96.116.228:8081",
  932. "version": "1.1",
  933. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
  934. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  935. "port": 8081
  936.  
  937.  
  938. "count": 1,
  939. "body": "",
  940. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D",
  941. "user-agent": "Microsoft-CryptoAPI/6.1",
  942. "method": "GET",
  943. "host": "ocsp.digicert.com",
  944. "version": "1.1",
  945. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D",
  946. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  947. "port": 80
  948.  
  949.  
  950. "count": 1,
  951. "body": "",
  952. "uri": "http://ocsp2.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D",
  953. "user-agent": "Microsoft-CryptoAPI/6.1",
  954. "method": "GET",
  955. "host": "ocsp2.digicert.com",
  956. "version": "1.1",
  957. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D",
  958. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAPmVVVnuUALPnoHj%2Fw%2B3Xo%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp2.digicert.com\r\n\r\n",
  959. "port": 80
  960.  
  961.  
  962. "count": 1,
  963. "body": "",
  964. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
  965. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  966. "method": "GET",
  967. "host": "47.96.116.228:8081",
  968. "version": "1.1",
  969. "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37",
  970. "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=37 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  971. "port": 8081
  972.  
  973.  
  974. "count": 2,
  975. "body": "",
  976. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
  977. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  978. "method": "GET",
  979. "host": "47.96.116.228:8081",
  980. "version": "1.1",
  981. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
  982. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  983. "port": 8081
  984.  
  985.  
  986. "count": 1,
  987. "body": "",
  988. "uri": "http://partner.funshion.com/partner/tk_download.php?id=9801\\xa0",
  989. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  990. "method": "GET",
  991. "host": "partner.funshion.com",
  992. "version": "1.1",
  993. "path": "/partner/tk_download.php?id=9801\\xa0",
  994. "data": "GET /partner/tk_download.php?id=9801\\xa0 HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: partner.funshion.com\r\nConnection: Keep-Alive\r\n\r\n",
  995. "port": 80
  996.  
  997.  
  998. "count": 1,
  999. "body": "",
  1000. "uri": "http://downloads.funshion.net/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe",
  1001. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1002. "method": "GET",
  1003. "host": "downloads.funshion.net",
  1004. "version": "1.1",
  1005. "path": "/tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe",
  1006. "data": "GET /tools/cloudinstall_signature/9801/FunInstaller_PS_0109801.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nConnection: Keep-Alive\r\nHost: downloads.funshion.net\r\n\r\n",
  1007. "port": 80
  1008.  
  1009.  
  1010. "count": 2,
  1011. "body": "",
  1012. "uri": "http://47.96.116.228:8081/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
  1013. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1014. "method": "GET",
  1015. "host": "47.96.116.228:8081",
  1016. "version": "1.1",
  1017. "path": "/api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13",
  1018. "data": "GET /api/recorder/downloadComplete?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=13 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1019. "port": 8081
  1020.  
  1021.  
  1022. "count": 1,
  1023. "body": "",
  1024. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25",
  1025. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1026. "method": "GET",
  1027. "host": "47.96.116.228:8081",
  1028. "version": "1.1",
  1029. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25",
  1030. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=25 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1031. "port": 8081
  1032.  
  1033.  
  1034. "count": 1,
  1035. "body": "",
  1036. "uri": "http://47.96.116.228:8081/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8",
  1037. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)",
  1038. "method": "GET",
  1039. "host": "47.96.116.228:8081",
  1040. "version": "1.1",
  1041. "path": "/api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8",
  1042. "data": "GET /api/recorder/downloadStart?downloadId=1&machineCode=4A413003-7C5A-C04A-8408-0D8E05B6B9AA&sys=Windows%207_6.1&s360=0&sTen=0&sJS=0&softwareId=8 HTTP/1.1\r\nAccept: *,*/*\r\nAccept-Language: zh-cn\r\nContent-Type: application/x-www-form-urlencoded\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\r\nHost: 47.96.116.228:8081\r\nCache-Control: no-cache\r\n\r\n",
  1043. "port": 8081
  1044.  
  1045.  
  1046. "count": 1,
  1047. "body": "",
  1048. "uri": "http://cd002.www.duba.net/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe",
  1049. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1050. "method": "GET",
  1051. "host": "cd002.www.duba.net",
  1052. "version": "1.1",
  1053. "path": "/duba/install/2011/ever/duba_u21055977_sv1_115_1.exe",
  1054. "data": "GET /duba/install/2011/ever/duba_u21055977_sv1_115_1.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: cd002.www.duba.net\r\nConnection: Keep-Alive\r\n\r\n",
  1055. "port": 80
  1056.  
  1057.  
  1058.  
  1059. * Network Communication - SMTP:
  1060.  
  1061. * Network Communication - Hosts:
  1062.  
  1063. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment