Source: unknown |
HTTPS traffic detected: 180.188.25.9:443 -> 192.168.2.4:49750 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 43.154.254.89:443 -> 192.168.2.4:49751 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 60.221.17.65:443 -> 192.168.2.4:49757 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 60.221.17.65:443 -> 192.168.2.4:49761 version: TLS 1.2 |
Source: |
Binary string: \Bin\lander.pdbX G source: SecuriteInfo.com.FileRepMalware.6479.21607.exe, 00000000.00000002.1725819778.00000000026E9000.00000004.00000020.00020000.00000000.sdmp, dqwhj_errwd.exe.0.dr, nsv2F3C.tmp.0.dr |
Source: |
Binary string: \Bin\lander.pdb source: SecuriteInfo.com.FileRepMalware.6479.21607.exe, 00000000.00000002.1725819778.00000000026E9000.00000004.00000020.00020000.00000000.sdmp, dqwhj_errwd.exe, 00000001.00000000.1691701850.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe, 00000001.00000002.1722241929.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe, 00000002.00000002.2934068778.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe, 00000002.00000000.1723459271.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe.0.dr, nsv2F3C.tmp.0.dr |
Source: |
Binary string: \Bin\iconTips.pdb source: SecuriteInfo.com.FileRepMalware.6479.21607.exe, 00000000.00000002.1725819778.00000000028DC000.00000004.00000020.00020000.00000000.sdmp, nsv2F3C.tmp.0.dr |
Source: |
Binary string: \Bin\iconAnimate.pdb source: SecuriteInfo.com.FileRepMalware.6479.21607.exe, 00000000.00000002.1725819778.0000000002890000.00000004.00000020.00020000.00000000.sdmp, nsv2F3C.tmp.0.dr |
Source: |
Binary string: \Bin\lander.pdbX L source: dqwhj_errwd.exe, 00000001.00000000.1691701850.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe, 00000001.00000002.1722241929.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe, 00000002.00000002.2934068778.00000000004B1000.00000002.00000001.01000000.00000008.sdmp, dqwhj_errwd.exe, 00000002.00000000.1723459271.00000000004B1000.00000002.00000001.01000000.00000008.sdmp |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.6479.21607.exe |
Code function: 0_2_00405E61 FindFirstFileA,FindClose, |
0_2_00405E61 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.6479.21607.exe |
Code function: 0_2_0040548B CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
0_2_0040548B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.6479.21607.exe |
Code function: 0_2_0040263E FindFirstFileA, |
0_2_0040263E |
Source: Network traffic |
Suricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49738 -> 163.171.133.72:80 |
Source: Network traffic |
Suricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49730 -> 159.75.141.43:80 |
Source: Network traffic |
Suricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49748 -> 159.75.141.43:80 |
Source: Network traffic |
Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 4.245.163.56:443 -> 192.168.2.4:49747 |
Source: Network traffic |
Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 4.245.163.56:443 -> 192.168.2.4:49764 |
Source: global traffic |
HTTP traffic detected: GET /httpsEnable.gif?t=1730391733433 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: my.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /TCaptcha.js HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: turing.captcha.qcloud.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /1/tcaptcha-frame.5e0f125a.js HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: turing.captcha.gtimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /template/drag_ele.html HTTP/1.1Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: turing.captcha.qcloud.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /1/dy-jy3.js HTTP/1.1Accept: */*Referer: https://turing.captcha.qcloud.com/template/drag_ele.htmlAccept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: turing.captcha.gtimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /1/dy-ele.16bf5dd7.js HTTP/1.1Accept: */*Referer: https://turing.captcha.qcloud.com/template/drag_ele.htmlAccept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: turing.captcha.gtimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /dy-jy3.js HTTP/1.1Accept: */*Referer: https://turing.captcha.qcloud.com/template/drag_ele.htmlAccept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: turing.captcha.qcloud.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1 HTTP/1.1Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: gameapp.37.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1.css?t=1730391723 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/js/client/game1.js?t=1730391723 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /2017/06/19141848xsCpC.jpg HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img2.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /js/sq/lib/sq.core.js?t=20140304 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /js/sq/widget/sq.login.js?t=20230803101600 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /controller/client.php?action=register&game_id=417&tpl_type=game2 HTTP/1.1Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: gameapp.37.comConnection: Keep-AliveCookie: PHPSESSID=r8n5i200li7ekleljhb17avtb1; sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1/rem_on.png HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1/kv-ico.png HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?game_id=417&tpl_type=game2&thirdlogin=1&refer=wd_37cs&uid=921614&version=3000&installtime=20241031&runcount=1&curtime=20241031122201&showlogintype=3®times=1&pagetype=1&thirdlogin=1Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1.css?t=1730391727 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/js/client/game1.js?t=1730391727 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /2017/06/19141848xsCpC.jpg HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img2.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /js/sq/lib/sq.core.js?t=20140304 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /js/sq/widget/sq.login.js?t=20230803101600 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1/reg.jpg HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1/dot.png HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /www2015/images/common/third-logo-24.png HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /js/sq/widget/sq.tab.js HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /js/sq/widget/sq.statis.js HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /js/sq/widget/sq.clientclass2.js?t=1730391727 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /controller/istat.controller.php?platform=37wan&item=u3tfl5ftfl&game_id=417&sid=&position=1&ext_1=4&ext_2=wd_37cs&ext_3=921614&ext_4=&ext_5=gy&ext_6=&login_account=&browser_type=&user_ip=&refer=wd_37cs&uid=921614&page=4&t=1730391732770 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: a.clickdata.37wan.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /www2015/images/reglog/200x42.png?v=1 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /www/css/images/common/dialog2/bg-dialog-avatar.png?v=1 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /js/sq/widget/sq.dialog2015.js?t=1730391733146&_=1730391733146 HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /proxy_yk.html HTTP/1.1Accept: image/gif, image/jpeg, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: regapi.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /www/css/images/common/ico.png HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /1/ HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: cm.he2d.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /js/sq/lib/sq.core.js HTTP/1.1Accept: */*Referer: http://regapi.37.com/proxy_yk.htmlAccept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: ptres.37.comConnection: Keep-AliveCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /sys/?u=uK4jZ7lpa5IBAAAALNcr&fdata= HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Connection: Keep-AliveHost: cookiem.37.comCookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1/btn-log-short.jpg HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /jzcq/css/client/game1/btn-reg.jpg HTTP/1.1Accept: */*Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=417&tpl_type=game2Accept-Language: en-CHAccept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: img1.37wanimg.comConnection: Keep-Alive |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: C:\Users\user\AppData\Roaming\mk-jzcq\dqwhj_errwd.exe |
Code function: 1_2_0047DFE0 _memset,InternetCrackUrlW,InternetOpenW,InternetConnectW,HttpOpenRequestW,HttpAddRequestHeadersW,HttpOpenRequestW,HttpSendRequestW,HttpQueryInfoW,HttpQueryInfoW,GetLastError,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,CreateFileW,InternetReadFile,WriteFile,CloseHandle, |
1_2_0047DFE0 |
Source: global traffic |
HTTP traffic detected: HTTP/1.1 200 OKServer: nginxDate: Thu, 31 Oct 2024 16:22:03 GMTContent-Type: text/html;charset=UTF-8Connection: closeSet-Cookie: PHPSESSID=r8n5i200li7ekleljhb17avtb1; path=/Expires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0Pragma: no-cacheSet-Cookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522417%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522921614%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A5%253A%2522game2%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220241031%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; path=/; domain=37.comSet-Cookie: client_type=3; path=/; domain=37.comContent-Encoding: gzipserver-timing: inner; dur=79Data Raw: 1f 8b 08 00 00 00 00 00 00 03 b5 5a 7b 73 d3 56 16 ff bb cc f4 3b a8 62 5b 92 82 2c c9 76 e2 b7 3b 34 94 60 86 d0 10 28 29 9e ce 30 57 0f db 8a f5 42 92 ed 38 29 33 30 b3 b4 dd 6e 69 e9 ce f6 c5 32 db c7 2e 1d 66 bb 6d 77 a7 33 6d 77 4b db 0f 43 9c c0 5f fb 15 f6 9c ab 87 25 5b 81 50 40 26 96 74 ef 3d e7 fc ce b9 e7 71 ef c5 d5 67 14 4b f6 86 b6 ca 74 3c 43 af ef ab e2 8d d1 89 d9 ae b1 1b 1d 16 1b 54 a2 d4 f7 31 70 55 0d d5 23 8c dc 21 8e ab 7a 35 f6 95 33 47 b9 22 cb f0 41 a7 a7 79 ba 5a 1f fd f2 cd ce 57 df 56 79 ff 2d 46 66 12 43 ad b1 2d c7 32 3d d5 54 58 46 a6 0f c0 a6 43 4c 10 14 b1 d1 Data Ascii: Z{sV;b[,v;4`()0WB8)30ni2.fmw3mwKC_%[P@&t=qgKt<CT1pU#!z53G"AyZWVy-FfC-2=TXFCL |
Source: global traffic |
HTTP traffic detected: HTTP/1.1 200 OKServer: Byte-nginxContent-Type: image/pngContent-Length: 912Connection: keep-aliveAge: 2505797Cache-Control: max-age=2592000Content-Encoding: gzipEtag: "59438b1e-764"Expires: Fri, 01 Nov 2024 16:18:50 GMTLast-Modified: Fri, 16 Jun 2017 07:39:10 GMTVary: Accept-EncodingX-Bdcdn-Cache-Status: TCP_HITX-Request-Id: 0a19ff7cb6bc940fd8c4beaba853c0a9X-Request-Ip: 173.254.250.77X-Response-Cache: edge_hitX-Response-Cinfo: 173.254.250.77X-Tt-Trace-Tag: id=5Date: Thu, 31 Oct 2024 16:22:07 GMTvia: pic03.hnxxcmData Raw: 1f 8b 08 00 00 00 00 00 00 03 ed 53 5d 6c 14 55 14 3e cd 36 c5 40 9a 10 9f 40 1e bc cc 82 d1 c4 dd d9 d9 76 4b 77 e8 42 ba 3b bb ed 46 a6 94 ed 46 ab 2f 74 76 e6 b6 3b 29 f3 d3 99 db ee 6e 83 51 8b 62 c0 3f 4c 48 fc a1 a6 12 45 22 08 44 8d 08 56 d0 28 3e 90 2c a0 46 08 3f 35 d1 04 21 e1 85 07 7e da 20 e1 7a 67 e9 96 c4 b8 c6 27 9f f8 92 99 7b cf cd f7 9d 7b ce b9 e7 6c e9 ee ea 68 9c ff d0 7c 00 68 4c 77 4a 19 b6 2e 61 df 82 07 7c ec 7f 78 aa e1 36 5b 16 93 64 2f e9 b1 fa 49 41 71 30 b4 6b 56 0e a3 b4 a1 0c e0 0c 56 b4 d2 d0 71 dc 06 e0 f3 eb d9 5e d2 2b af 11 55 cb 08 2a 1e 27 58 34 6c f0 d0 b6 ba 68 2b ea 20 26 28 87 07 74 33 c6 5d 9d fc 86 43 ba 16 e3 9e 8a c8 21 d9 4e e0 bc de 39 ea e0 9e d1 ae ac 3a 3a a8 46 35 6e f5 2a d4 56 14 99 03 03 13 05 15 8d 0d a6 2b 16 63 5c c5 af c8 f6 de 31 cf a1 0a 85 0c c6 b8 bb 41 f5 ca dd 28 61 39 18 45 82 91 80 1a 12 9a d1 8a 68 50 88 08 cd ad c2 e3 28 1c 12 9a f8 50 13 2f 34 05 84 b0 18 8a 8a 42 04 cd 82 63 b7 39 5a bf 98 91 52 b3 77 31 2b c6 e5 09 b1 45 9e 2f 14 0a c1 42 53 d0 72 06 78 21 1a 8d f2 a1 30 1f 0e 07 18 23 e0 96 4c a2 14 03 a6 eb af 7a 90 b0 ab 3a ba 4d 74 cb 44 9e ad e4 ac 61 12 e3 b8 6a 0a 86 3d e7 d6 74 67 cb c4 0a c6 17 15 9b 17 82 21 2f a5 2a 51 96 ff 9d 6a 18 73 6c 97 64 f0 bd 78 ff 91 ed 66 4b 36 e6 33 d8 b5 86 1d 95 3d 5c bf df 13 db 62 c2 c1 0a b1 9c ac 65 6d a8 56 b1 3b 6f 11 cb cd 5b 36 4a 24 d0 a3 b2 a2 ea a6 67 3f 56 11 c8 b2 98 36 5d a2 98 2a 4e 4b 31 8e 9d 04 75 5d 13 c3 52 24 d2 1e 4f 49 2b 84 e6 84 20 24 9b db 59 f1 5b e3 d1 96 96 16 a1 35 1c 4e 09 55 ad 64 a9 c3 06 36 49 55 ab dd d3 26 6b 6a bd 5e b8 ab c6 8e 3e 82 b5 94 63 19 a8 92 b3 a8 d7 8e 25 5e d3 df ac 56 ab 1d 4b a2 a6 96 67 c1 f0 7f 7b e9 ea 11 6b 1f 6f 3b d7 b7 cc 98 eb 7c 6c b2 76 77 58 5f 4f 1e ed d9 c8 c6 05 ba d7 64 93 6c 36 28 c3 cf 40 7f 01 7a 06 e8 49 a0 a7 80 1e 87 4b 9f 01 fd 0e e8 31 b8 f2 29 ec db 04 74 12 e8 d7 40 0f 02 3d 0c 74 3f d0 cf e1 f7 71 a0 |