Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Docs_e964291ee72d223ed8e5759fef5f04e4.doc"
- * File Size: 267459
- * File Type: "Rich Text Format data, version 1, unknown character set"
- * SHA256: "8d994c1ff8d9376b27d082d4d25b6e290705eb1da170e266193fc30c22c54d9a"
- * MD5: "e964291ee72d223ed8e5759fef5f04e4"
- * SHA1: "a6422ed781d65bebaca35b912aa41be788cc0c6e"
- * SHA512: "5a46678803c58ff86fa9cf0023d4215633a6cf9a2acfb1bc817978cb8381e218dc0d9c32a5399ba406ad862f33b683b63af0d2976a036fe8f773e8ebe5a40772"
- * CRC32: "015603E1"
- * SSDEEP: "768:s7Kf2sdrM3xaSybdRZXZWkWZNLe3NLT2y5mgMrlhAuIX+0jcVW2/i0ND3+bSExzt:sxxQW3yho2OimWQzNjYxuHhiFcwgu"
- * Process Execution:
- "WINWORD.EXE"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
- "Details":
- "IP": "52.109.12.6:443"
- "IP": "52.109.6.6:443"
- "IP": "72.21.91.29:80"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D"
- "Description": "A document file initiated network communications indicative of a potential exploit or payload download",
- "Details":
- "http_request": "winword.exe_WSASend_\\x16\\x03\\x01\\x00\\x7f\\x01\\x00\\x00\\x03\\x01$k\\x15\\xca\\xd0\\xcd7\\xc4\\x05\\x17.r\\x1ay\\xfburb\\xcf\\xa2\\xf0y8\\xc3\\x95z\\xc3a\\xbam\\x00\\x00\\x18\\x00/\\x005\\x00\\x05\\x00\n\\xc0\\x13\\xc0\\x14\\xc0\t\\xc0\n\\x002\\x008\\x00\\x13\\x00\\x04\\x01\\x00\\x00:\\xff\\x01\\x00\\x01\\x00\\x00\\x00\\x00!\\x00\\x1f\\x00\\x00\\x1coffice15client.microsoft.com\\x00\n\\x00\\x06\\x00\\x04\\x00\\x17\\x00\\x18\\x00\\x0b\\x00\\x02\\x01\\x00"
- "http_request": "winword.exe_WSASend_\\x16\\x03\\x01\\x00f\\x10\\x00\\x00ba\\x04c%\\xd2\\9\\xd8\\xe8%\\xcb\\xf8k\\x916\\x01\\\\xac\\xba\\x0er\\x02\\xde\\xdb(z\\x12\\x98\\xa1a -pc\\xd4\\xda_\\x89^\\xa9\\x97\\xf7\\xbc\\x99jx\\x80\\x03\\xcb\\xfd\\x8dyg\\xf7n\\xca\\x8al\\xb4^k\\xa2q\\x07\\xad\\xcf\\x14\\x03\\x01\\x00\\x01\\x01\\x16\\x03\\x01\\x000\\xea\\x9b\\x85\\x9e\\x17\\xed\\xc7\\xc7\\xd1\\xee\\xfc\\x9c\\x1f:@3r\\xb1\\x157l\\x96\\x94\\xc4\\xf3f\\xd9d\\x04\\x11_e\\xa2ac\\x02\\x98\\x07'\\x06\\xa7\\xdc$\\xeag\\xd8\\x08"
- "http_request": "winword.exe_WSASend_\\x17\\x03\\x01\\x01p\\x80e\\x8a\\x91\\xef\\xa5\\x01\\x98k$\\x8b\\x17\\x97\\x11\\x1ae\\xdf(\\x18\\xf9\\xff\\xc13\\x11\\x1a\\xd8\\xd3\\xac\\x87\\xfc\\xd3\\x8c\\xdb\\x16f4wo\\x8du\\x9e<ay\r\\xcez3u\\x9a,\\xc6\\xb5\\x92\r\\xfb\\xcb\\x00`5\\x98a\\xb6f\\xdajw\\x90\\xfc\\x8ak\\xd9\\x9di5c9\\xe5\\xaa@\\xf6c\\xdac\\x83\\x85\\xe1\\x16\\xc6k\\x90\\x87\\x85\\x03w\\x9cp\\xbe)\\xae\\x8a\\xf1\\xedqr\\xd9i,l\\xf4\\xddx\\xbb\\xb7\\x90\\x8c\\x1b\\xbc,\\x9e,s\\xd8,\\xec\\xeb\\xd5\ng\\xe3e\\xde\\xd8:q\r4fq\\xd3\\xe6\\xea4q,\\x07\\xc4f\\xd2\\x9b\\xa4\\x1d=\\xd0c\\xf8\\x8dz\\xf4\\xfd\t#\\x8d\\xd8\\xf3\\x8d\\x92\\x8d.\\x05n\\xa8\\x16do\\x10>8\\xa1'9\\x86p&$x\\x02\\x02\\x1e\\xb4\\x8f\\x88\\x82r'k\\xa8\\xe2\\xc4\\xdav\\xb2\\x05:6\\xe9a\\x00u\\xb3\\xa8\\xb2\\x98@\\xd8\\x0f\\x8f\\x96\\x18\\x17b\\xca\\xa35\\xca\\xab%\\xbc\\xd9h\\xcex\\xe4\"\\x9ao\\x906bo\\x9e\\x0c!/c\\xd1\\xe1\\xd5"
- "http_request": "winword.exe_WSASend_\\x16\\x03\\x01\\x00~\\x01\\x00\\x00z\\x03\\x01$k\\x16y\\x0fzx\\xfdc\\xa8m\\x98\\x84\\xb3\\xc5\\x07\\xdff\\xc6\\x00\\x165\\xa6\\x8ab\\x8c\\xf0 \\xf6\\xcb\\xb5\\x00\\x00\\x18\\x00/\\x005\\x00\\x05\\x00\n\\xc0\\x13\\xc0\\x14\\xc0\t\\xc0\n\\x002\\x008\\x00\\x13\\x00\\x04\\x01\\x00\\x009\\xff\\x01\\x00\\x01\\x00\\x00\\x00\\x00 \\x00\\x1e\\x00\\x00\\x1broaming.officeapps.live.com\\x00\n\\x00\\x06\\x00\\x04\\x00\\x17\\x00\\x18\\x00\\x0b\\x00\\x02\\x01\\x00"
- "http_request": "winword.exe_WSASend_\\x16\\x03\\x01\\x00f\\x10\\x00\\x00ba\\x04+\\x9b\\xd8\\x92\\xfe\\xf0:#wu$m?\\xd9o\\xf3d\\xe4\\xd5(m\\xaf\\xd1\\x17\\xf7:\\x97\\x7f\\xffao\\x12wo\\x187\\xc8\\x16t\\xbf\\xbc\\xc5\\xcc\\x81z\\xc8wkfa\\x80i\\xca\\x80\\xcc\\xf6\\x88|\\xb4\\xa0c\\xcc\\xe3\\x84\\x14\\x03\\x01\\x00\\x01\\x01\\x16\\x03\\x01\\x000\\xab7\\x92\\xbb\\xf4'\\xd3b\\xb4;\\xb0o;s\\xc0\\xf5\t\\xcbs5\\x9f7\\xfa\\xfdsu`\\x8c\\xfaa3\\x0blbd\\x95\\xb6\\x1d\\xbc\\xd5\\x913h\\x8f\\x16\\xa7st"
- "http_request": "winword.exe_WSASend_\\x16\\x03\\x01\\x00z\\x01\\x00\\x00v\\x03\\x01$k\\x17\\x1e4\\xf9=\\x89!saj4\\x05\\x82\\x1a\\xd9\\x9d\\x90\\xef\\x0e\\xcc\\xf6z\\xe3\\xd9~\n\\xect\\x0e\\x00\\x00\\x18\\x00/\\x005\\x00\\x05\\x00\n\\xc0\\x13\\xc0\\x14\\xc0\t\\xc0\n\\x002\\x008\\x00\\x13\\x00\\x04\\x01\\x00\\x005\\xff\\x01\\x00\\x01\\x00\\x00\\x00\\x00\\x1c\\x00\\x1a\\x00\\x00\\x17odc.officeapps.live.com\\x00\n\\x00\\x06\\x00\\x04\\x00\\x17\\x00\\x18\\x00\\x0b\\x00\\x02\\x01\\x00"
- "http_request": "winword.exe_WSASend_\\x16\\x03\\x01\\x00f\\x10\\x00\\x00ba\\x042y\t\\xc7\\xde\\x17\\xa7\\%\\xb1\\x9d\\x03\\xef\tv*w\\x8d#\\xd1-\\x8e\\xeb\">\\xf8\\x1b\\x0e\\xed\\xd5\\xbd\\x03\\x847wj\\xd9\\x1a\\xbe,\\xc5\\x944\\xa6\\x85\\xdc%\\xed\\x8e\\x90\\xb5\\xbc@\\xb8\\xa1\\xadqfh\\xcfe\r\\xcf\\xd5\\x14\\x03\\x01\\x00\\x01\\x01\\x16\\x03\\x01\\x000\\x19\\x8b\\xc0\\xc5x,\\xc4\\x03_\\xcd\\xb3tc\\x0c\\xea\\x8f\\x15\\x84\\xa4el\\xa4\\xf0\\xe5\\x00\\xf3$\\x1c\\xcd-\\xd8=\\x8e+n\\x9b\\xbc\r\\xa7\\xc1\\x18\\xda(\\xdd$\\x0b\\xb6\\xc8"
- "http_request": "winword.exe_WSASend_\\x17\\x03\\x01\\x01p\\x98\\x940h\\x9e\"\\x04\\xabi\\xd2\\xe5\\x8a\\xc6c\\x8b@p\\xcbu+=h\\xc1\\x8d\\xaau\\xcem\\xfe\\x9b^\\x9a\\xaf\\xee2e6%\\xfce\\xce6\\x8bn\\xe8\\xf7)?\\x89?\\xe0l\\x90\\xe3\\x0c\\xc2\\xfa\\x12\\x9d\\xf6m\\x97\\xa8\\x8d\\xecr\\xc6x\\x05\\x02\\xe8\\xcf\\xde\\x11\\xdd\\xb4\\x1f\\x93w\\xf2\\x9d+\\xed\\xbbh>\\xa1wsk\\xffs_\\xc0\\xfd)\\x919a\\x0f\\xa3/\\xf8~\\x08j\\xa7g\\xa471\\xed~\\xcc;\\xa8\\xd9\\x06\\xfc\\xad\\x97g0\\xfcmr5\\xd8\\xc2\\x9b\\xb4\\xcf\\x03\\xe4s\\x11\\xc1\\xd5l3ok\\x9a\\x8c?\\xcd\\xc3\\xea\\xe0il\\xb2\\xc9\\xf7\\xacro\\x85\\xc2\\x80\\xc0*\\xa3z\\x85\\x1cm\\xf7i\\xf1(\\xdb\\x95\\x7f\\xecg\\x841\\x82\\x94\\xf3a\\x7fa\\xd0\\x92\\xf9l\\x1d3\\xafnu\\q=\\x02\\x04gw.\\xe5\\x9d\\xdf~\\x8d\\x99\\xa0i\\xdae\\x84\\xd6rh\\x1ew\\xcdx7\\xd3\\x0cz\\xa7\\xd0\\xcf\\xbf\\x00e\\xdb\\xad\\x1d\\xdf\\xb7\\x8f\\x1f<\\x19\\xaf^\\xcev\\x13\\xd4m"
- "http_request": "winword.exe_WSASend_get /mfewtzbnmeswstajbgurdgmcgguabbtbl0v27rvz7lbduom%2fnyb45spuewqu5z1zmijhwmys%2bghunoz7oruetfaceai4elabvpzalrznpjlrv1u%3d http/1.1\r\nconnection: keep-alive\r\naccept: */*\r\nuser-agent: microsoft-cryptoapi/6.1\r\nhost: ocsp.digicert.com\r\n\r\n"
- "Description": "File has been identified by 31 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Exploit.RTF-ObfsStrm.Gen"
- "FireEye": "Exploit.RTF-ObfsStrm.Gen"
- "CAT-QuickHeal": "Exp.RTF.Obfus.Gen"
- "McAfee": "Exploit-CVE2017-11882.ah"
- "Arcabit": "Exploit.RTF-ObfsStrm.Gen"
- "Symantec": "Bloodhound.RTF.12"
- "ESET-NOD32": "probably a variant of Win32/Exploit.CVE-2017-11882.A"
- "TrendMicro-HouseCall": "Possible_SMBCVE20170199"
- "Kaspersky": "HEUR:Exploit.MSOffice.Generic"
- "BitDefender": "Exploit.RTF-ObfsStrm.Gen"
- "Ad-Aware": "Exploit.RTF-ObfsStrm.Gen"
- "Sophos": "Exp/201711882-P"
- "Comodo": "Exploit.W97M.CVE2017-11882.AG@843jmy"
- "F-Secure": "Heuristic.HEUR/Rtf.Malformed"
- "DrWeb": "Exploit.Rtf.CVE2012-0158"
- "TrendMicro": "Possible_SMBCVE20170199"
- "McAfee-GW-Edition": "Exploit-CVE2017-11882.ah"
- "Emsisoft": "Exploit.RTF-ObfsStrm.Gen (B)"
- "Cyren": "CVE-2017-11882!Camelot"
- "Avira": "HEUR/Rtf.Malformed"
- "MAX": "malware (ai score=94)"
- "Antiy-AVL": "TrojanExploit/OLE.CVE-2017-11882"
- "Microsoft": "Exploit:O97M/CVE-2017-11882.T"
- "ZoneAlarm": "HEUR:Exploit.RTF.CVE-2017-11882.gen"
- "GData": "Exploit.RTF-ObfsStrm.Gen"
- "AhnLab-V3": "RTF/Malform-C.Gen"
- "TACHYON": "Trojan-Exploit/RTF.CVE-2017-11882"
- "Zoner": "Probably RTFObfuscation"
- "Rising": "Exploit.CVE-2017-11882/SLT!1.AEE3 (CLASSIC)"
- "Ikarus": "Exploit.CVE-2017-11882"
- "Qihoo-360": "susp.rtf.objupdate.gen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Rtf.Dropper.Agent-7010984-0, sha256:8d994c1ff8d9376b27d082d4d25b6e290705eb1da170e266193fc30c22c54d9a, type:Rich Text Format data, version 1, unknown character set"
- "dropped": "clamav:Rtf.Dropper.Agent-7010984-0, sha256:8d994c1ff8d9376b27d082d4d25b6e290705eb1da170e266193fc30c22c54d9a , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\Docs_e964291ee72d223ed8e5759fef5f04e4.doc, type:Rich Text Format data, version 1, unknown character set"
- * Started Service:
- "osppsvc"
- * Mutexes:
- "Local\\2BF388D5-6F8C-40A0-A7EE-996D005C4E14_Office15",
- "Global\\MTX_MSO_Formal1_S-1-5-21-0000000000-0000000000-0000000000-1000",
- "Global\\MTX_MSO_AdHoc1_S-1-5-21-0000000000-0000000000-0000000000-1000",
- "5CAC3FAB-87F0-4750-984D-D50144543427-VER15",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Global\\552FFA80-3393-423d-8671-7BA046BB5906"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Docs_e964291ee72d223ed8e5759fef5f04e4.doc",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~$cs_e964291ee72d223ed8e5759fef5f04e4.doc",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Word\\~WRFAC18F57B-F078-475F-877D-37D99D051AD6.tmp",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Word\\~WRS97D355F9-D063-4C76-A5BA-6DB42359149D.tmp",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.Word\\~WRS2DC00A3D-1B40-4736-8E44-FA48A343B8EB.tmp",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Office\\15.0\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=10",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\6BADA8974A10C4BD62CC921D13E43B18_88614FFAD35D353421B8A7E1FE18FCE4"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Schemas\\MS Word_restart.xml",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Word\\STARTUP\\"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\StartupItems\\uj)",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\RemoteClearDate",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\Last",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\0",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\0\\FilePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\0\\StartDate",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\0\\EndDate",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\0\\Properties",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\AllUsers\\office15client.microsoft.com\\config15--lcid=1033&syslcid=1033&uilcid=1033&build=15.0.4569&crev=1\\0\\Url",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\Internet\\WebServiceCache\\LastClean",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Security\\Trusted Documents\\LastPurgeTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\ReviewCycle",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\ReviewCycle\\ReviewToken",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\ServicesManagerCache\\ServicesCatalog\\CacheReady",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\ServicesManagerCache\\ServicesCatalog\\LastRequest",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\DocumentRecovery",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\DocumentRecovery\\A0E02E",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\DocumentRecovery\\A0E02E\\A0E02E",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Products\\00005119110000000000000000F01FEC\\Usage\\OUTLOOKFiles",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\ServicesManagerCache\\ServicesCatalog\\LastUpdate",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\ServicesManagerCache\\ServicesCatalog\\NextUpdate",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Common\\General\\LastAutoSavePurgeTime"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\StartupItems\\uj)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Word\\Resiliency\\StartupItems\\\"0'"
- * DNS Communications:
- "type": "A",
- "request": "koirado.com",
- "answers":
- "data": "46.105.57.169",
- "type": "A"
- "type": "A",
- "request": "vemvemserver.duckdns.org",
- "answers":
- "data": "205.185.125.42",
- "type": "A"
- "type": "A",
- "request": "crl3.digicert.com",
- "answers":
- "data": "cs9.wac.phicdn.net",
- "type": "CNAME"
- "data": "72.21.91.29",
- "type": "A"
- "type": "A",
- "request": "dephantomz.duckdns.org",
- "answers":
- "data": "45.32.184.40",
- "type": "A"
- * Domains:
- "ip": "45.32.184.40",
- "domain": "dephantomz.duckdns.org"
- "ip": "",
- "domain": "koirado.com"
- "ip": "72.21.91.29",
- "domain": "crl3.digicert.com"
- "ip": "205.185.125.42",
- "domain": "vemvemserver.duckdns.org"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment