paladin316

acrotextextractor_exe_2019-07-29_15_30.txt

Jul 29th, 2019
2,293
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 42.81 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "acrotextextractor.exe"
  7. * File Size: 51696
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "d071abfc5306099b95c7146e2d61c938306a1f1b0b8ad7d589ed7884d4df6d6a"
  10. * MD5: "bedc68d63d11bb54aef2951660e9b708"
  11. * SHA1: "17ad64e9e986c984926fc75df2e5595bfe0827db"
  12. * SHA512: "a92b9726302d667f2b01203aec51377b87ec3288160fb9c7b3505d1b0a2e31b83516e1914d81089d8fa5631341508a770585b8a1ad071f52c24a53cc48b46d4f"
  13. * CRC32: "CCA3E4AE"
  14. * SSDEEP: "768:4jTELZ9kHqG2T402jH6f2dx/MQASHKPc+H63Hb2bxiPK3wh/:4/EkHd0Ci2zkQASqk+H6L2bxiygh/"
  15.  
  16. * Process Execution:
  17. "acrotextextractor.exe",
  18. "28D7.exe",
  19. "sysxbvt.exe",
  20. "23390.exe",
  21. "10021.exe",
  22. "30520.exe",
  23. "14440.exe",
  24. "33625.exe"
  25.  
  26.  
  27. * Executed Commands:
  28. "C:\\Windows\\44202012\\sysxbvt.exe",
  29. "C:\\Users\\user\\AppData\\Local\\Temp\\23390.exe",
  30. "C:\\Users\\user\\AppData\\Local\\Temp\\10021.exe",
  31. "C:\\Users\\user\\AppData\\Local\\Temp\\30520.exe",
  32. "C:\\Users\\user\\AppData\\Local\\Temp\\14440.exe",
  33. "C:\\Users\\user\\AppData\\Local\\Temp\\33625.exe"
  34.  
  35.  
  36. * Signatures Detected:
  37.  
  38. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  39. "Details":
  40.  
  41. "IP": "193.32.161.73:80"
  42.  
  43.  
  44.  
  45.  
  46. "Description": "Creates RWX memory",
  47. "Details":
  48.  
  49.  
  50. "Description": "A process attempted to delay the analysis task.",
  51. "Details":
  52.  
  53. "Process": "sysxbvt.exe tried to sleep 483 seconds, actually delayed analysis time by 0 seconds"
  54.  
  55.  
  56.  
  57.  
  58. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  59. "Details":
  60.  
  61.  
  62. "Description": "Drops a binary and executes it",
  63. "Details":
  64.  
  65. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\28D7.exe"
  66.  
  67.  
  68. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\30520.exe"
  69.  
  70.  
  71. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\10021.exe"
  72.  
  73.  
  74. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\33625.exe"
  75.  
  76.  
  77. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\23390.exe"
  78.  
  79.  
  80. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\14440.exe"
  81.  
  82.  
  83. "binary": "C:\\Windows\\44202012\\sysxbvt.exe"
  84.  
  85.  
  86.  
  87.  
  88. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  89. "Details":
  90.  
  91. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  92.  
  93.  
  94. "suspicious_request": "http://193.32.161.73/a.exe"
  95.  
  96.  
  97. "suspicious_request": "http://185.176.27.132/t.php?new=1"
  98.  
  99.  
  100. "suspicious_request": "http://193.32.161.73/t.php?new=1"
  101.  
  102.  
  103. "suspicious_request": "http://185.176.27.132/1"
  104.  
  105.  
  106. "suspicious_request": "http://185.176.27.132/2"
  107.  
  108.  
  109. "suspicious_request": "http://185.176.27.132/3"
  110.  
  111.  
  112. "suspicious_request": "http://185.176.27.132/4"
  113.  
  114.  
  115. "suspicious_request": "http://185.176.27.132/5"
  116.  
  117.  
  118. "suspicious_request": "http://185.176.27.132/6"
  119.  
  120.  
  121. "suspicious_request": "http://185.176.27.132/7"
  122.  
  123.  
  124. "suspicious_request": "http://185.176.27.132/8"
  125.  
  126.  
  127. "suspicious_request": "http://193.32.161.73/1"
  128.  
  129.  
  130. "suspicious_request": "http://193.32.161.73/2"
  131.  
  132.  
  133. "suspicious_request": "http://193.32.161.73/3"
  134.  
  135.  
  136. "suspicious_request": "http://193.32.161.73/4"
  137.  
  138.  
  139. "suspicious_request": "http://193.32.161.73/5"
  140.  
  141.  
  142. "suspicious_request": "http://193.32.161.73/6"
  143.  
  144.  
  145. "suspicious_request": "http://193.32.161.73/7"
  146.  
  147.  
  148. "suspicious_request": "http://193.32.161.73/8"
  149.  
  150.  
  151. "suspicious_request": "http://193.32.161.73/update.txt"
  152.  
  153.  
  154.  
  155.  
  156. "Description": "Performs some HTTP requests",
  157. "Details":
  158.  
  159. "url": "http://193.32.161.73/a.exe"
  160.  
  161.  
  162. "url": "http://185.176.27.132/t.php?new=1"
  163.  
  164.  
  165. "url": "http://193.32.161.73/t.php?new=1"
  166.  
  167.  
  168. "url": "http://185.176.27.132/1"
  169.  
  170.  
  171. "url": "http://185.176.27.132/2"
  172.  
  173.  
  174. "url": "http://185.176.27.132/3"
  175.  
  176.  
  177. "url": "http://185.176.27.132/4"
  178.  
  179.  
  180. "url": "http://185.176.27.132/5"
  181.  
  182.  
  183. "url": "http://185.176.27.132/6"
  184.  
  185.  
  186. "url": "http://185.176.27.132/7"
  187.  
  188.  
  189. "url": "http://185.176.27.132/8"
  190.  
  191.  
  192. "url": "http://193.32.161.73/1"
  193.  
  194.  
  195. "url": "http://193.32.161.73/2"
  196.  
  197.  
  198. "url": "http://193.32.161.73/3"
  199.  
  200.  
  201. "url": "http://193.32.161.73/4"
  202.  
  203.  
  204. "url": "http://193.32.161.73/5"
  205.  
  206.  
  207. "url": "http://193.32.161.73/6"
  208.  
  209.  
  210. "url": "http://193.32.161.73/7"
  211.  
  212.  
  213. "url": "http://193.32.161.73/8"
  214.  
  215.  
  216. "url": "http://193.32.161.73/update.txt"
  217.  
  218.  
  219.  
  220.  
  221. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  222. "Details":
  223.  
  224. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\28D7.exe:Zone.Identifier"
  225.  
  226.  
  227.  
  228.  
  229. "Description": "Detects Sandboxie through the presence of a library",
  230. "Details":
  231.  
  232.  
  233. "Description": "Detects SunBelt Sandbox through the presence of a library",
  234. "Details":
  235.  
  236.  
  237. "Description": "Installs itself for autorun at Windows startup",
  238. "Details":
  239.  
  240. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver"
  241.  
  242.  
  243. "data": "C:\\Windows\\44202012\\sysxbvt.exe"
  244.  
  245.  
  246. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver"
  247.  
  248.  
  249. "data": "C:\\Windows\\44202012\\sysxbvt.exe"
  250.  
  251.  
  252.  
  253.  
  254. "Description": "Creates a hidden or system file",
  255. "Details":
  256.  
  257. "file": "C:\\Windows\\44202012"
  258.  
  259.  
  260. "file": "C:\\Windows\\44202012\\sysxbvt.exe"
  261.  
  262.  
  263. "file": "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt"
  264.  
  265.  
  266.  
  267.  
  268. "Description": "Operates on local firewall's policies and settings",
  269. "Details":
  270.  
  271.  
  272. "Description": "Attempts to disable System Restore",
  273. "Details":
  274.  
  275.  
  276. "Description": "Attempts to modify or disable Security Center warnings",
  277. "Details":
  278.  
  279.  
  280. "Description": "Likely use of Domain Generation Algorithm (DGA)",
  281. "Details":
  282.  
  283.  
  284. "Description": "Created network traffic indicative of malicious activity",
  285. "Details":
  286.  
  287. "signature": "ET DROP Dshield Block Listed Source group 1"
  288.  
  289.  
  290. "signature": "ET TROJAN Single char EXE direct download likely trojan (multiple families)"
  291.  
  292.  
  293. "signature": "ET DNS Query for .cc TLD"
  294.  
  295.  
  296. "signature": "ET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile"
  297.  
  298.  
  299. "signature": "ET DNS Query for .su TLD (Soviet Union) Often Malware Related"
  300.  
  301.  
  302. "signature": "ET DNS Query for .co TLD"
  303.  
  304.  
  305. "signature": "ET CURRENT_EVENTS Possible Malicious Macro DL EXE Feb 2016"
  306.  
  307.  
  308.  
  309.  
  310.  
  311. * Started Service:
  312.  
  313. * Mutexes:
  314. "8493049",
  315. "36473358"
  316.  
  317.  
  318. * Modified Files:
  319. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\a1.exe",
  320. "C:\\Windows\\44202012\\sysxbvt.exe",
  321. "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt",
  322. "C:\\Users\\user\\AppData\\Local\\Temp\\23390.exe",
  323. "C:\\Users\\user\\AppData\\Local\\Temp\\10021.exe",
  324. "C:\\Users\\user\\AppData\\Local\\Temp\\30520.exe",
  325. "C:\\Users\\user\\AppData\\Local\\Temp\\14440.exe",
  326. "C:\\Users\\user\\AppData\\Local\\Temp\\33625.exe"
  327.  
  328.  
  329. * Deleted Files:
  330. "C:\\Users\\user\\AppData\\Local\\Temp\\28D7.exe:Zone.Identifier",
  331. "C:\\Windows\\44202012\\sysxbvt.exe:Zone.Identifier",
  332. "C:\\Users\\user\\AppData\\Local\\Temp\\23390.exe:Zone.Identifier",
  333. "C:\\Users\\user\\AppData\\Local\\Temp\\10021.exe:Zone.Identifier",
  334. "C:\\Users\\user\\AppData\\Local\\Temp\\30520.exe:Zone.Identifier",
  335. "C:\\Users\\user\\AppData\\Local\\Temp\\14440.exe:Zone.Identifier",
  336. "C:\\Users\\user\\AppData\\Local\\Temp\\33625.exe:Zone.Identifier"
  337.  
  338.  
  339. * Modified Registry Keys:
  340. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver",
  341. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Driver",
  342. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusOverride",
  343. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesOverride",
  344. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallOverride",
  345. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusDisableNotify",
  346. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesDisableNotify",
  347. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AutoUpdateDisableNotify",
  348. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallDisableNotify",
  349. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR"
  350.  
  351.  
  352. * Deleted Registry Keys:
  353.  
  354. * DNS Communications:
  355.  
  356. "type": "A",
  357. "request": "urusurofhsorhfuuhk.su",
  358. "answers":
  359.  
  360. "data": "",
  361. "type": "NXDOMAIN"
  362.  
  363.  
  364.  
  365.  
  366. "type": "A",
  367. "request": "aeifaeifhutuhuhusk.su",
  368. "answers":
  369.  
  370. "data": "",
  371. "type": "NXDOMAIN"
  372.  
  373.  
  374.  
  375.  
  376. "type": "A",
  377. "request": "rzhsudhugugfugugsk.su",
  378. "answers":
  379.  
  380. "data": "",
  381. "type": "NXDOMAIN"
  382.  
  383.  
  384.  
  385.  
  386. "type": "A",
  387. "request": "bfagzzezgaegzgfaik.su",
  388. "answers":
  389.  
  390. "data": "",
  391. "type": "NXDOMAIN"
  392.  
  393.  
  394.  
  395.  
  396. "type": "A",
  397. "request": "eaeuafhuaegfugeudk.su",
  398. "answers":
  399.  
  400. "data": "",
  401. "type": "NXDOMAIN"
  402.  
  403.  
  404.  
  405.  
  406. "type": "A",
  407. "request": "aeufuaehfiuehfuhfk.su",
  408. "answers":
  409.  
  410. "data": "",
  411. "type": "NXDOMAIN"
  412.  
  413.  
  414.  
  415.  
  416. "type": "A",
  417. "request": "daedagheauehfuuhfk.su",
  418. "answers":
  419.  
  420. "data": "",
  421. "type": "NXDOMAIN"
  422.  
  423.  
  424.  
  425.  
  426. "type": "A",
  427. "request": "aeoughaoheguaoehdk.su",
  428. "answers":
  429.  
  430. "data": "",
  431. "type": "NXDOMAIN"
  432.  
  433.  
  434.  
  435.  
  436. "type": "A",
  437. "request": "eguaheoghouughahsk.su",
  438. "answers":
  439.  
  440. "data": "",
  441. "type": "NXDOMAIN"
  442.  
  443.  
  444.  
  445.  
  446. "type": "A",
  447. "request": "huaeokaefoaeguaehk.su",
  448. "answers":
  449.  
  450. "data": "",
  451. "type": "NXDOMAIN"
  452.  
  453.  
  454.  
  455.  
  456. "type": "A",
  457. "request": "afaeigaifgsgrhhafk.su",
  458. "answers":
  459.  
  460. "data": "",
  461. "type": "NXDOMAIN"
  462.  
  463.  
  464.  
  465.  
  466. "type": "A",
  467. "request": "afaigaeigieufuifik.su",
  468. "answers":
  469.  
  470. "data": "",
  471. "type": "NXDOMAIN"
  472.  
  473.  
  474.  
  475.  
  476. "type": "A",
  477. "request": "geauhouefheuutiiik.su",
  478. "answers":
  479.  
  480. "data": "",
  481. "type": "NXDOMAIN"
  482.  
  483.  
  484.  
  485.  
  486. "type": "A",
  487. "request": "gaoheeuofhefefhutk.su",
  488. "answers":
  489.  
  490. "data": "",
  491. "type": "NXDOMAIN"
  492.  
  493.  
  494.  
  495.  
  496. "type": "A",
  497. "request": "gaouehaehfoaeajrsk.su",
  498. "answers":
  499.  
  500. "data": "",
  501. "type": "NXDOMAIN"
  502.  
  503.  
  504.  
  505.  
  506. "type": "A",
  507. "request": "gaohrhurhuhruhfsdk.su",
  508. "answers":
  509.  
  510. "data": "",
  511. "type": "NXDOMAIN"
  512.  
  513.  
  514.  
  515.  
  516. "type": "A",
  517. "request": "gaghpaheiafhjefijk.su",
  518. "answers":
  519.  
  520. "data": "",
  521. "type": "NXDOMAIN"
  522.  
  523.  
  524.  
  525.  
  526. "type": "A",
  527. "request": "gaoehuoaoefhuhfugk.su",
  528. "answers":
  529.  
  530. "data": "",
  531. "type": "NXDOMAIN"
  532.  
  533.  
  534.  
  535.  
  536. "type": "A",
  537. "request": "aegohaohuoruitiiek.su",
  538. "answers":
  539.  
  540. "data": "",
  541. "type": "NXDOMAIN"
  542.  
  543.  
  544.  
  545.  
  546. "type": "A",
  547. "request": "befaheaiudeuhughgk.su",
  548. "answers":
  549.  
  550. "data": "",
  551. "type": "NXDOMAIN"
  552.  
  553.  
  554.  
  555.  
  556. "type": "A",
  557. "request": "urusurofhsorhfuuho.io",
  558. "answers":
  559.  
  560. "data": "",
  561. "type": "NXDOMAIN"
  562.  
  563.  
  564.  
  565.  
  566. "type": "A",
  567. "request": "aeifaeifhutuhuhuso.io",
  568. "answers":
  569.  
  570. "data": "",
  571. "type": "NXDOMAIN"
  572.  
  573.  
  574.  
  575.  
  576. "type": "A",
  577. "request": "rzhsudhugugfugugso.io",
  578. "answers":
  579.  
  580. "data": "",
  581. "type": "NXDOMAIN"
  582.  
  583.  
  584.  
  585.  
  586. "type": "A",
  587. "request": "bfagzzezgaegzgfaio.io",
  588. "answers":
  589.  
  590. "data": "",
  591. "type": "NXDOMAIN"
  592.  
  593.  
  594.  
  595.  
  596. "type": "A",
  597. "request": "eaeuafhuaegfugeudo.io",
  598. "answers":
  599.  
  600. "data": "",
  601. "type": "NXDOMAIN"
  602.  
  603.  
  604.  
  605.  
  606. "type": "A",
  607. "request": "aeufuaehfiuehfuhfo.io",
  608. "answers":
  609.  
  610. "data": "",
  611. "type": "NXDOMAIN"
  612.  
  613.  
  614.  
  615.  
  616. "type": "A",
  617. "request": "daedagheauehfuuhfo.io",
  618. "answers":
  619.  
  620. "data": "",
  621. "type": "NXDOMAIN"
  622.  
  623.  
  624.  
  625.  
  626. "type": "A",
  627. "request": "aeoughaoheguaoehdo.io",
  628. "answers":
  629.  
  630. "data": "",
  631. "type": "NXDOMAIN"
  632.  
  633.  
  634.  
  635.  
  636. "type": "A",
  637. "request": "eguaheoghouughahso.io",
  638. "answers":
  639.  
  640. "data": "",
  641. "type": "NXDOMAIN"
  642.  
  643.  
  644.  
  645.  
  646. "type": "A",
  647. "request": "huaeokaefoaeguaeho.io",
  648. "answers":
  649.  
  650. "data": "",
  651. "type": "NXDOMAIN"
  652.  
  653.  
  654.  
  655.  
  656. "type": "A",
  657. "request": "afaeigaifgsgrhhafo.io",
  658. "answers":
  659.  
  660. "data": "",
  661. "type": "NXDOMAIN"
  662.  
  663.  
  664.  
  665.  
  666. "type": "A",
  667. "request": "afaigaeigieufuifio.io",
  668. "answers":
  669.  
  670. "data": "",
  671. "type": "NXDOMAIN"
  672.  
  673.  
  674.  
  675.  
  676. "type": "A",
  677. "request": "geauhouefheuutiiio.io",
  678. "answers":
  679.  
  680. "data": "",
  681. "type": "NXDOMAIN"
  682.  
  683.  
  684.  
  685.  
  686. "type": "A",
  687. "request": "gaoheeuofhefefhuto.io",
  688. "answers":
  689.  
  690. "data": "",
  691. "type": "NXDOMAIN"
  692.  
  693.  
  694.  
  695.  
  696. "type": "A",
  697. "request": "gaouehaehfoaeajrso.io",
  698. "answers":
  699.  
  700. "data": "",
  701. "type": "NXDOMAIN"
  702.  
  703.  
  704.  
  705.  
  706. "type": "A",
  707. "request": "gaohrhurhuhruhfsdo.io",
  708. "answers":
  709.  
  710. "data": "",
  711. "type": "NXDOMAIN"
  712.  
  713.  
  714.  
  715.  
  716. "type": "A",
  717. "request": "gaghpaheiafhjefijo.io",
  718. "answers":
  719.  
  720. "data": "",
  721. "type": "NXDOMAIN"
  722.  
  723.  
  724.  
  725.  
  726. "type": "A",
  727. "request": "gaoehuoaoefhuhfugo.io",
  728. "answers":
  729.  
  730. "data": "",
  731. "type": "NXDOMAIN"
  732.  
  733.  
  734.  
  735.  
  736. "type": "A",
  737. "request": "aegohaohuoruitiieo.io",
  738. "answers":
  739.  
  740. "data": "",
  741. "type": "NXDOMAIN"
  742.  
  743.  
  744.  
  745.  
  746. "type": "A",
  747. "request": "befaheaiudeuhughgo.io",
  748. "answers":
  749.  
  750. "data": "",
  751. "type": "NXDOMAIN"
  752.  
  753.  
  754.  
  755.  
  756. "type": "A",
  757. "request": "urusurofhsorhfuuhl.cc",
  758. "answers":
  759.  
  760. "data": "",
  761. "type": "NXDOMAIN"
  762.  
  763.  
  764.  
  765.  
  766. "type": "A",
  767. "request": "aeifaeifhutuhuhusl.cc",
  768. "answers":
  769.  
  770. "data": "",
  771. "type": "NXDOMAIN"
  772.  
  773.  
  774.  
  775.  
  776. "type": "A",
  777. "request": "rzhsudhugugfugugsl.cc",
  778. "answers":
  779.  
  780. "data": "",
  781. "type": "NXDOMAIN"
  782.  
  783.  
  784.  
  785.  
  786. "type": "A",
  787. "request": "bfagzzezgaegzgfail.cc",
  788. "answers":
  789.  
  790. "data": "",
  791. "type": "NXDOMAIN"
  792.  
  793.  
  794.  
  795.  
  796. "type": "A",
  797. "request": "eaeuafhuaegfugeudl.cc",
  798. "answers":
  799.  
  800. "data": "",
  801. "type": "NXDOMAIN"
  802.  
  803.  
  804.  
  805.  
  806. "type": "A",
  807. "request": "aeufuaehfiuehfuhfl.cc",
  808. "answers":
  809.  
  810. "data": "",
  811. "type": "NXDOMAIN"
  812.  
  813.  
  814.  
  815.  
  816. "type": "A",
  817. "request": "daedagheauehfuuhfl.cc",
  818. "answers":
  819.  
  820. "data": "",
  821. "type": "NXDOMAIN"
  822.  
  823.  
  824.  
  825.  
  826. "type": "A",
  827. "request": "aeoughaoheguaoehdl.cc",
  828. "answers":
  829.  
  830. "data": "",
  831. "type": "NXDOMAIN"
  832.  
  833.  
  834.  
  835.  
  836. "type": "A",
  837. "request": "eguaheoghouughahsl.cc",
  838. "answers":
  839.  
  840. "data": "",
  841. "type": "NXDOMAIN"
  842.  
  843.  
  844.  
  845.  
  846. "type": "A",
  847. "request": "huaeokaefoaeguaehl.cc",
  848. "answers":
  849.  
  850. "data": "",
  851. "type": "NXDOMAIN"
  852.  
  853.  
  854.  
  855.  
  856. "type": "A",
  857. "request": "afaeigaifgsgrhhafl.cc",
  858. "answers":
  859.  
  860. "data": "",
  861. "type": "NXDOMAIN"
  862.  
  863.  
  864.  
  865.  
  866. "type": "A",
  867. "request": "afaigaeigieufuifil.cc",
  868. "answers":
  869.  
  870. "data": "",
  871. "type": "NXDOMAIN"
  872.  
  873.  
  874.  
  875.  
  876. "type": "A",
  877. "request": "geauhouefheuutiiil.cc",
  878. "answers":
  879.  
  880. "data": "",
  881. "type": "NXDOMAIN"
  882.  
  883.  
  884.  
  885.  
  886. "type": "A",
  887. "request": "gaoheeuofhefefhutl.cc",
  888. "answers":
  889.  
  890. "data": "",
  891. "type": "NXDOMAIN"
  892.  
  893.  
  894.  
  895.  
  896. "type": "A",
  897. "request": "gaouehaehfoaeajrsl.cc",
  898. "answers":
  899.  
  900. "data": "",
  901. "type": "NXDOMAIN"
  902.  
  903.  
  904.  
  905.  
  906. "type": "A",
  907. "request": "gaohrhurhuhruhfsdl.cc",
  908. "answers":
  909.  
  910. "data": "",
  911. "type": "NXDOMAIN"
  912.  
  913.  
  914.  
  915.  
  916. "type": "A",
  917. "request": "gaghpaheiafhjefijl.cc",
  918. "answers":
  919.  
  920. "data": "",
  921. "type": "NXDOMAIN"
  922.  
  923.  
  924.  
  925.  
  926. "type": "A",
  927. "request": "gaoehuoaoefhuhfugl.cc",
  928. "answers":
  929.  
  930. "data": "",
  931. "type": "NXDOMAIN"
  932.  
  933.  
  934.  
  935.  
  936. "type": "A",
  937. "request": "aegohaohuoruitiiel.cc",
  938. "answers":
  939.  
  940. "data": "",
  941. "type": "NXDOMAIN"
  942.  
  943.  
  944.  
  945.  
  946. "type": "A",
  947. "request": "befaheaiudeuhughgl.cc",
  948. "answers":
  949.  
  950. "data": "",
  951. "type": "NXDOMAIN"
  952.  
  953.  
  954.  
  955.  
  956. "type": "A",
  957. "request": "urusurofhsorhfuuhp.co",
  958. "answers":
  959.  
  960. "data": "",
  961. "type": "NXDOMAIN"
  962.  
  963.  
  964.  
  965.  
  966. "type": "A",
  967. "request": "aeifaeifhutuhuhusp.co",
  968. "answers":
  969.  
  970. "data": "",
  971. "type": "NXDOMAIN"
  972.  
  973.  
  974.  
  975.  
  976. "type": "A",
  977. "request": "rzhsudhugugfugugsp.co",
  978. "answers":
  979.  
  980. "data": "",
  981. "type": "NXDOMAIN"
  982.  
  983.  
  984.  
  985.  
  986. "type": "A",
  987. "request": "bfagzzezgaegzgfaip.co",
  988. "answers":
  989.  
  990. "data": "",
  991. "type": "NXDOMAIN"
  992.  
  993.  
  994.  
  995.  
  996. "type": "A",
  997. "request": "eaeuafhuaegfugeudp.co",
  998. "answers":
  999.  
  1000. "data": "",
  1001. "type": "NXDOMAIN"
  1002.  
  1003.  
  1004.  
  1005.  
  1006. "type": "A",
  1007. "request": "aeufuaehfiuehfuhfp.co",
  1008. "answers":
  1009.  
  1010. "data": "",
  1011. "type": "NXDOMAIN"
  1012.  
  1013.  
  1014.  
  1015.  
  1016. "type": "A",
  1017. "request": "daedagheauehfuuhfp.co",
  1018. "answers":
  1019.  
  1020. "data": "",
  1021. "type": "NXDOMAIN"
  1022.  
  1023.  
  1024.  
  1025.  
  1026. "type": "A",
  1027. "request": "aeoughaoheguaoehdp.co",
  1028. "answers":
  1029.  
  1030. "data": "",
  1031. "type": "NXDOMAIN"
  1032.  
  1033.  
  1034.  
  1035.  
  1036. "type": "A",
  1037. "request": "eguaheoghouughahsp.co",
  1038. "answers":
  1039.  
  1040. "data": "",
  1041. "type": "NXDOMAIN"
  1042.  
  1043.  
  1044.  
  1045.  
  1046. "type": "A",
  1047. "request": "huaeokaefoaeguaehp.co",
  1048. "answers":
  1049.  
  1050. "data": "",
  1051. "type": "NXDOMAIN"
  1052.  
  1053.  
  1054.  
  1055.  
  1056. "type": "A",
  1057. "request": "afaeigaifgsgrhhafp.co",
  1058. "answers":
  1059.  
  1060. "data": "",
  1061. "type": "NXDOMAIN"
  1062.  
  1063.  
  1064.  
  1065.  
  1066. "type": "A",
  1067. "request": "afaigaeigieufuifip.co",
  1068. "answers":
  1069.  
  1070. "data": "",
  1071. "type": "NXDOMAIN"
  1072.  
  1073.  
  1074.  
  1075.  
  1076. "type": "A",
  1077. "request": "geauhouefheuutiiip.co",
  1078. "answers":
  1079.  
  1080. "data": "",
  1081. "type": "NXDOMAIN"
  1082.  
  1083.  
  1084.  
  1085.  
  1086. "type": "A",
  1087. "request": "gaoheeuofhefefhutp.co",
  1088. "answers":
  1089.  
  1090. "data": "",
  1091. "type": "NXDOMAIN"
  1092.  
  1093.  
  1094.  
  1095.  
  1096. "type": "A",
  1097. "request": "gaouehaehfoaeajrsp.co",
  1098. "answers":
  1099.  
  1100. "data": "",
  1101. "type": "NXDOMAIN"
  1102.  
  1103.  
  1104.  
  1105.  
  1106. "type": "A",
  1107. "request": "gaohrhurhuhruhfsdp.co",
  1108. "answers":
  1109.  
  1110. "data": "",
  1111. "type": "NXDOMAIN"
  1112.  
  1113.  
  1114.  
  1115.  
  1116. "type": "A",
  1117. "request": "gaghpaheiafhjefijp.co",
  1118. "answers":
  1119.  
  1120. "data": "",
  1121. "type": "NXDOMAIN"
  1122.  
  1123.  
  1124.  
  1125.  
  1126. "type": "A",
  1127. "request": "gaoehuoaoefhuhfugp.co",
  1128. "answers":
  1129.  
  1130. "data": "",
  1131. "type": "NXDOMAIN"
  1132.  
  1133.  
  1134.  
  1135.  
  1136. "type": "A",
  1137. "request": "aegohaohuoruitiiep.co",
  1138. "answers":
  1139.  
  1140. "data": "",
  1141. "type": "NXDOMAIN"
  1142.  
  1143.  
  1144.  
  1145.  
  1146. "type": "A",
  1147. "request": "befaheaiudeuhughgp.co",
  1148. "answers":
  1149.  
  1150. "data": "",
  1151. "type": "NXDOMAIN"
  1152.  
  1153.  
  1154.  
  1155.  
  1156. "type": "MX",
  1157. "request": "yahoo.com",
  1158. "answers":
  1159.  
  1160. "data": "mta5.am0.yahoodns.net",
  1161. "type": "MX"
  1162.  
  1163.  
  1164. "data": "mta7.am0.yahoodns.net",
  1165. "type": "MX"
  1166.  
  1167.  
  1168. "data": "mta6.am0.yahoodns.net",
  1169. "type": "MX"
  1170.  
  1171.  
  1172.  
  1173.  
  1174. "type": "A",
  1175. "request": "mta7.am0.yahoodns.net",
  1176. "answers":
  1177.  
  1178. "data": "66.218.85.139",
  1179. "type": "A"
  1180.  
  1181.  
  1182. "data": "74.6.137.65",
  1183. "type": "A"
  1184.  
  1185.  
  1186. "data": "67.195.228.106",
  1187. "type": "A"
  1188.  
  1189.  
  1190. "data": "98.137.159.26",
  1191. "type": "A"
  1192.  
  1193.  
  1194. "data": "98.137.159.25",
  1195. "type": "A"
  1196.  
  1197.  
  1198. "data": "98.137.159.28",
  1199. "type": "A"
  1200.  
  1201.  
  1202. "data": "74.6.137.63",
  1203. "type": "A"
  1204.  
  1205.  
  1206. "data": "67.195.228.111",
  1207. "type": "A"
  1208.  
  1209.  
  1210.  
  1211.  
  1212.  
  1213. * Domains:
  1214.  
  1215. "ip": "",
  1216. "domain": "gaohrhurhuhruhfsdl.cc"
  1217.  
  1218.  
  1219. "ip": "",
  1220. "domain": "huaeokaefoaeguaehl.cc"
  1221.  
  1222.  
  1223. "ip": "",
  1224. "domain": "afaigaeigieufuifip.co"
  1225.  
  1226.  
  1227. "ip": "",
  1228. "domain": "bfagzzezgaegzgfaio.io"
  1229.  
  1230.  
  1231. "ip": "",
  1232. "domain": "eguaheoghouughahsl.cc"
  1233.  
  1234.  
  1235. "ip": "",
  1236. "domain": "gaohrhurhuhruhfsdk.su"
  1237.  
  1238.  
  1239. "ip": "",
  1240. "domain": "daedagheauehfuuhfo.io"
  1241.  
  1242.  
  1243. "ip": "",
  1244. "domain": "afaigaeigieufuifil.cc"
  1245.  
  1246.  
  1247. "ip": "",
  1248. "domain": "aeoughaoheguaoehdp.co"
  1249.  
  1250.  
  1251. "ip": "",
  1252. "domain": "befaheaiudeuhughgk.su"
  1253.  
  1254.  
  1255. "ip": "",
  1256. "domain": "aegohaohuoruitiiep.co"
  1257.  
  1258.  
  1259. "ip": "",
  1260. "domain": "daedagheauehfuuhfp.co"
  1261.  
  1262.  
  1263. "ip": "",
  1264. "domain": "aeoughaoheguaoehdo.io"
  1265.  
  1266.  
  1267. "ip": "",
  1268. "domain": "aegohaohuoruitiiek.su"
  1269.  
  1270.  
  1271. "ip": "",
  1272. "domain": "gaoheeuofhefefhutp.co"
  1273.  
  1274.  
  1275. "ip": "",
  1276. "domain": "aeufuaehfiuehfuhfp.co"
  1277.  
  1278.  
  1279. "ip": "",
  1280. "domain": "rzhsudhugugfugugso.io"
  1281.  
  1282.  
  1283. "ip": "",
  1284. "domain": "gaouehaehfoaeajrso.io"
  1285.  
  1286.  
  1287. "ip": "",
  1288. "domain": "eguaheoghouughahsp.co"
  1289.  
  1290.  
  1291. "ip": "67.195.228.94",
  1292. "domain": "mta7.am0.yahoodns.net"
  1293.  
  1294.  
  1295. "ip": "",
  1296. "domain": "aeoughaoheguaoehdk.su"
  1297.  
  1298.  
  1299. "ip": "",
  1300. "domain": "aegohaohuoruitiieo.io"
  1301.  
  1302.  
  1303. "ip": "",
  1304. "domain": "gaoheeuofhefefhutk.su"
  1305.  
  1306.  
  1307. "ip": "",
  1308. "domain": "gaohrhurhuhruhfsdp.co"
  1309.  
  1310.  
  1311. "ip": "",
  1312. "domain": "huaeokaefoaeguaeho.io"
  1313.  
  1314.  
  1315. "ip": "",
  1316. "domain": "aeufuaehfiuehfuhfo.io"
  1317.  
  1318.  
  1319. "ip": "",
  1320. "domain": "aeoughaoheguaoehdl.cc"
  1321.  
  1322.  
  1323. "ip": "",
  1324. "domain": "eaeuafhuaegfugeudp.co"
  1325.  
  1326.  
  1327. "ip": "",
  1328. "domain": "gaghpaheiafhjefijk.su"
  1329.  
  1330.  
  1331. "ip": "",
  1332. "domain": "huaeokaefoaeguaehp.co"
  1333.  
  1334.  
  1335. "ip": "",
  1336. "domain": "eguaheoghouughahso.io"
  1337.  
  1338.  
  1339. "ip": "",
  1340. "domain": "afaeigaifgsgrhhafp.co"
  1341.  
  1342.  
  1343. "ip": "",
  1344. "domain": "geauhouefheuutiiil.cc"
  1345.  
  1346.  
  1347. "ip": "",
  1348. "domain": "gaouehaehfoaeajrsp.co"
  1349.  
  1350.  
  1351. "ip": "",
  1352. "domain": "daedagheauehfuuhfl.cc"
  1353.  
  1354.  
  1355. "ip": "",
  1356. "domain": "eaeuafhuaegfugeudl.cc"
  1357.  
  1358.  
  1359. "ip": "",
  1360. "domain": "gaoehuoaoefhuhfugl.cc"
  1361.  
  1362.  
  1363. "ip": "",
  1364. "domain": "aeufuaehfiuehfuhfk.su"
  1365.  
  1366.  
  1367. "ip": "",
  1368. "domain": "gaoehuoaoefhuhfugo.io"
  1369.  
  1370.  
  1371. "ip": "",
  1372. "domain": "gaghpaheiafhjefijl.cc"
  1373.  
  1374.  
  1375. "ip": "",
  1376. "domain": "gaouehaehfoaeajrsl.cc"
  1377.  
  1378.  
  1379. "ip": "98.138.219.232",
  1380. "domain": "yahoo.com"
  1381.  
  1382.  
  1383. "ip": "",
  1384. "domain": "aegohaohuoruitiiel.cc"
  1385.  
  1386.  
  1387. "ip": "",
  1388. "domain": "bfagzzezgaegzgfaik.su"
  1389.  
  1390.  
  1391. "ip": "",
  1392. "domain": "befaheaiudeuhughgo.io"
  1393.  
  1394.  
  1395. "ip": "",
  1396. "domain": "eaeuafhuaegfugeudo.io"
  1397.  
  1398.  
  1399. "ip": "",
  1400. "domain": "afaeigaifgsgrhhafk.su"
  1401.  
  1402.  
  1403. "ip": "",
  1404. "domain": "aeifaeifhutuhuhusl.cc"
  1405.  
  1406.  
  1407. "ip": "",
  1408. "domain": "bfagzzezgaegzgfail.cc"
  1409.  
  1410.  
  1411. "ip": "",
  1412. "domain": "urusurofhsorhfuuhl.cc"
  1413.  
  1414.  
  1415. "ip": "",
  1416. "domain": "afaigaeigieufuifio.io"
  1417.  
  1418.  
  1419. "ip": "",
  1420. "domain": "eaeuafhuaegfugeudk.su"
  1421.  
  1422.  
  1423. "ip": "",
  1424. "domain": "afaeigaifgsgrhhafl.cc"
  1425.  
  1426.  
  1427. "ip": "",
  1428. "domain": "rzhsudhugugfugugsk.su"
  1429.  
  1430.  
  1431. "ip": "",
  1432. "domain": "eguaheoghouughahsk.su"
  1433.  
  1434.  
  1435. "ip": "",
  1436. "domain": "afaeigaifgsgrhhafo.io"
  1437.  
  1438.  
  1439. "ip": "",
  1440. "domain": "rzhsudhugugfugugsp.co"
  1441.  
  1442.  
  1443. "ip": "",
  1444. "domain": "gaoheeuofhefefhutl.cc"
  1445.  
  1446.  
  1447. "ip": "",
  1448. "domain": "bfagzzezgaegzgfaip.co"
  1449.  
  1450.  
  1451. "ip": "",
  1452. "domain": "daedagheauehfuuhfk.su"
  1453.  
  1454.  
  1455. "ip": "",
  1456. "domain": "befaheaiudeuhughgp.co"
  1457.  
  1458.  
  1459. "ip": "",
  1460. "domain": "aeifaeifhutuhuhusp.co"
  1461.  
  1462.  
  1463. "ip": "",
  1464. "domain": "gaoehuoaoefhuhfugk.su"
  1465.  
  1466.  
  1467. "ip": "",
  1468. "domain": "urusurofhsorhfuuho.io"
  1469.  
  1470.  
  1471. "ip": "",
  1472. "domain": "urusurofhsorhfuuhp.co"
  1473.  
  1474.  
  1475. "ip": "",
  1476. "domain": "rzhsudhugugfugugsl.cc"
  1477.  
  1478.  
  1479. "ip": "",
  1480. "domain": "aeufuaehfiuehfuhfl.cc"
  1481.  
  1482.  
  1483. "ip": "",
  1484. "domain": "aeifaeifhutuhuhuso.io"
  1485.  
  1486.  
  1487. "ip": "",
  1488. "domain": "gaoehuoaoefhuhfugp.co"
  1489.  
  1490.  
  1491. "ip": "",
  1492. "domain": "afaigaeigieufuifik.su"
  1493.  
  1494.  
  1495. "ip": "",
  1496. "domain": "aeifaeifhutuhuhusk.su"
  1497.  
  1498.  
  1499. "ip": "",
  1500. "domain": "gaghpaheiafhjefijp.co"
  1501.  
  1502.  
  1503. "ip": "",
  1504. "domain": "huaeokaefoaeguaehk.su"
  1505.  
  1506.  
  1507. "ip": "",
  1508. "domain": "gaoheeuofhefefhuto.io"
  1509.  
  1510.  
  1511. "ip": "",
  1512. "domain": "gaohrhurhuhruhfsdo.io"
  1513.  
  1514.  
  1515. "ip": "",
  1516. "domain": "geauhouefheuutiiio.io"
  1517.  
  1518.  
  1519. "ip": "",
  1520. "domain": "urusurofhsorhfuuhk.su"
  1521.  
  1522.  
  1523. "ip": "",
  1524. "domain": "geauhouefheuutiiik.su"
  1525.  
  1526.  
  1527. "ip": "",
  1528. "domain": "gaghpaheiafhjefijo.io"
  1529.  
  1530.  
  1531. "ip": "",
  1532. "domain": "gaouehaehfoaeajrsk.su"
  1533.  
  1534.  
  1535. "ip": "",
  1536. "domain": "befaheaiudeuhughgl.cc"
  1537.  
  1538.  
  1539. "ip": "",
  1540. "domain": "geauhouefheuutiiip.co"
  1541.  
  1542.  
  1543.  
  1544. * Network Communication - ICMP:
  1545.  
  1546. * Network Communication - HTTP:
  1547.  
  1548. "count": 1,
  1549. "body": "",
  1550. "uri": "http://193.32.161.73/a.exe",
  1551. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1552. "method": "GET",
  1553. "host": "193.32.161.73",
  1554. "version": "1.1",
  1555. "path": "/a.exe",
  1556. "data": "GET /a.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 193.32.161.73\r\nConnection: Keep-Alive\r\n\r\n",
  1557. "port": 80
  1558.  
  1559.  
  1560. "count": 1,
  1561. "body": "",
  1562. "uri": "http://185.176.27.132/t.php?new=1",
  1563. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1564. "method": "GET",
  1565. "host": "185.176.27.132",
  1566. "version": "1.1",
  1567. "path": "/t.php?new=1",
  1568. "data": "GET /t.php?new=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1569. "port": 80
  1570.  
  1571.  
  1572. "count": 1,
  1573. "body": "",
  1574. "uri": "http://193.32.161.73/t.php?new=1",
  1575. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1576. "method": "GET",
  1577. "host": "193.32.161.73",
  1578. "version": "1.1",
  1579. "path": "/t.php?new=1",
  1580. "data": "GET /t.php?new=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1581. "port": 80
  1582.  
  1583.  
  1584. "count": 2,
  1585. "body": "",
  1586. "uri": "http://185.176.27.132/1",
  1587. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1588. "method": "GET",
  1589. "host": "185.176.27.132",
  1590. "version": "1.1",
  1591. "path": "/1",
  1592. "data": "GET /1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1593. "port": 80
  1594.  
  1595.  
  1596. "count": 2,
  1597. "body": "",
  1598. "uri": "http://185.176.27.132/2",
  1599. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1600. "method": "GET",
  1601. "host": "185.176.27.132",
  1602. "version": "1.1",
  1603. "path": "/2",
  1604. "data": "GET /2 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1605. "port": 80
  1606.  
  1607.  
  1608. "count": 2,
  1609. "body": "",
  1610. "uri": "http://185.176.27.132/3",
  1611. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1612. "method": "GET",
  1613. "host": "185.176.27.132",
  1614. "version": "1.1",
  1615. "path": "/3",
  1616. "data": "GET /3 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1617. "port": 80
  1618.  
  1619.  
  1620. "count": 2,
  1621. "body": "",
  1622. "uri": "http://185.176.27.132/4",
  1623. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1624. "method": "GET",
  1625. "host": "185.176.27.132",
  1626. "version": "1.1",
  1627. "path": "/4",
  1628. "data": "GET /4 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1629. "port": 80
  1630.  
  1631.  
  1632. "count": 2,
  1633. "body": "",
  1634. "uri": "http://185.176.27.132/5",
  1635. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1636. "method": "GET",
  1637. "host": "185.176.27.132",
  1638. "version": "1.1",
  1639. "path": "/5",
  1640. "data": "GET /5 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1641. "port": 80
  1642.  
  1643.  
  1644. "count": 2,
  1645. "body": "",
  1646. "uri": "http://185.176.27.132/6",
  1647. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1648. "method": "GET",
  1649. "host": "185.176.27.132",
  1650. "version": "1.1",
  1651. "path": "/6",
  1652. "data": "GET /6 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1653. "port": 80
  1654.  
  1655.  
  1656. "count": 2,
  1657. "body": "",
  1658. "uri": "http://185.176.27.132/7",
  1659. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1660. "method": "GET",
  1661. "host": "185.176.27.132",
  1662. "version": "1.1",
  1663. "path": "/7",
  1664. "data": "GET /7 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1665. "port": 80
  1666.  
  1667.  
  1668. "count": 2,
  1669. "body": "",
  1670. "uri": "http://185.176.27.132/8",
  1671. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1672. "method": "GET",
  1673. "host": "185.176.27.132",
  1674. "version": "1.1",
  1675. "path": "/8",
  1676. "data": "GET /8 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 185.176.27.132\r\n\r\n",
  1677. "port": 80
  1678.  
  1679.  
  1680. "count": 2,
  1681. "body": "",
  1682. "uri": "http://193.32.161.73/1",
  1683. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1684. "method": "GET",
  1685. "host": "193.32.161.73",
  1686. "version": "1.1",
  1687. "path": "/1",
  1688. "data": "GET /1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1689. "port": 80
  1690.  
  1691.  
  1692. "count": 2,
  1693. "body": "",
  1694. "uri": "http://193.32.161.73/2",
  1695. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1696. "method": "GET",
  1697. "host": "193.32.161.73",
  1698. "version": "1.1",
  1699. "path": "/2",
  1700. "data": "GET /2 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1701. "port": 80
  1702.  
  1703.  
  1704. "count": 2,
  1705. "body": "",
  1706. "uri": "http://193.32.161.73/3",
  1707. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1708. "method": "GET",
  1709. "host": "193.32.161.73",
  1710. "version": "1.1",
  1711. "path": "/3",
  1712. "data": "GET /3 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1713. "port": 80
  1714.  
  1715.  
  1716. "count": 2,
  1717. "body": "",
  1718. "uri": "http://193.32.161.73/4",
  1719. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1720. "method": "GET",
  1721. "host": "193.32.161.73",
  1722. "version": "1.1",
  1723. "path": "/4",
  1724. "data": "GET /4 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1725. "port": 80
  1726.  
  1727.  
  1728. "count": 2,
  1729. "body": "",
  1730. "uri": "http://193.32.161.73/5",
  1731. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1732. "method": "GET",
  1733. "host": "193.32.161.73",
  1734. "version": "1.1",
  1735. "path": "/5",
  1736. "data": "GET /5 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1737. "port": 80
  1738.  
  1739.  
  1740. "count": 1,
  1741. "body": "",
  1742. "uri": "http://193.32.161.73/6",
  1743. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1744. "method": "GET",
  1745. "host": "193.32.161.73",
  1746. "version": "1.1",
  1747. "path": "/6",
  1748. "data": "GET /6 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1749. "port": 80
  1750.  
  1751.  
  1752. "count": 1,
  1753. "body": "",
  1754. "uri": "http://193.32.161.73/7",
  1755. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1756. "method": "GET",
  1757. "host": "193.32.161.73",
  1758. "version": "1.1",
  1759. "path": "/7",
  1760. "data": "GET /7 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1761. "port": 80
  1762.  
  1763.  
  1764. "count": 1,
  1765. "body": "",
  1766. "uri": "http://193.32.161.73/8",
  1767. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0",
  1768. "method": "GET",
  1769. "host": "193.32.161.73",
  1770. "version": "1.1",
  1771. "path": "/8",
  1772. "data": "GET /8 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0\r\nHost: 193.32.161.73\r\n\r\n",
  1773. "port": 80
  1774.  
  1775.  
  1776. "count": 1,
  1777. "body": "",
  1778. "uri": "http://193.32.161.73/update.txt",
  1779. "user-agent": "WinInetGet/0.1",
  1780. "method": "GET",
  1781. "host": "193.32.161.73",
  1782. "version": "1.1",
  1783. "path": "/update.txt",
  1784. "data": "GET /update.txt HTTP/1.1\r\nAccept: text/*, application/exe, application/zlib, application/gzip, application/applefile\r\nUser-Agent: WinInetGet/0.1\r\nHost: 193.32.161.73\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1785. "port": 80
  1786.  
  1787.  
  1788.  
  1789. * Network Communication - SMTP:
  1790.  
  1791. * Network Communication - Hosts:
  1792.  
  1793. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment