Summary | ZeroBOX

pepwn.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 May 3, 2021, 4:46 p.m. May 3, 2021, 5:06 p.m.
Size 100.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ee0a1ec859b753abc30847157d81f37c
SHA256 abf63fc54948cdd9d1bf46a2f59fcb081bb0ff10b595f0ba2faad392ad368922
CRC32 9E18C80F
ssdeep 3072:UlmICQuNwVOv/8I6WruEPJZDUXA2M1CUci6sUJW51TrFS83Fo:WmICRmgMtWruEhZDCA2M1CUci6sUJW5D
PDB Path
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
api.wipmania.com 212.83.168.196
IP Address Status Action
141.255.162.34 Active Moloch
162.247.74.201 Active Moloch
164.124.101.2 Active Moloch
185.215.113.93 Active Moloch
193.11.164.243 Active Moloch
195.201.103.59 Active Moloch
212.83.168.196 Active Moloch
213.32.71.116 Active Moloch
23.129.64.201 Active Moloch
45.66.156.176 Active Moloch
86.59.21.38 Active Moloch
95.143.193.125 Active Moloch
95.217.229.211 Active Moloch
95.217.42.50 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 185.215.113.93:80 -> 192.168.56.101:49208 2400023 ET DROP Spamhaus DROP Listed Traffic Inbound group 24 Misc Attack
TCP 45.66.156.176:8443 -> 192.168.56.101:49206 2522577 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 578 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49209 2520073 ET TOR Known Tor Exit Node Traffic group 74 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49209 2522074 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 75 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49209 2500216 ET COMPROMISED Known Compromised or Hostile Host Traffic group 109 Misc Attack
TCP 192.168.56.101:49200 -> 212.83.168.196:80 2014304 ET POLICY External IP Lookup Attempt To Wipmania Device Retrieving External IP Address Detected
TCP 192.168.56.101:49203 -> 212.83.168.196:80 2014304 ET POLICY External IP Lookup Attempt To Wipmania Device Retrieving External IP Address Detected
TCP 95.143.193.125:80 -> 192.168.56.101:49207 2520104 ET TOR Known Tor Exit Node Traffic group 105 Misc Attack
TCP 95.143.193.125:80 -> 192.168.56.101:49207 2522105 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 106 Misc Attack
TCP 195.201.103.59:3333 -> 192.168.56.101:49212 2522318 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 319 Misc Attack
TCP 86.59.21.38:80 -> 192.168.56.101:49214 2522742 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 743 Misc Attack
TCP 192.168.56.101:49212 -> 195.201.103.59:3333 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 195.201.103.59:3333 -> 192.168.56.101:49212 2018789 ET POLICY TLS possible TOR SSL traffic Misc activity
TCP 192.168.56.101:49214 -> 86.59.21.38:80 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49209 -> 23.129.64.201:80 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49214 -> 86.59.21.38:80 2008113 ET P2P Tor Get Server Request Potential Corporate Privacy Violation
TCP 192.168.56.101:49209 -> 23.129.64.201:80 2008113 ET P2P Tor Get Server Request Potential Corporate Privacy Violation
TCP 86.59.21.38:80 -> 192.168.56.101:49214 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 23.129.64.201:80 -> 192.168.56.101:49209 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49218 -> 212.83.168.196:80 2014304 ET POLICY External IP Lookup Attempt To Wipmania Device Retrieving External IP Address Detected
TCP 192.168.56.101:49207 -> 95.143.193.125:80 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49207 -> 95.143.193.125:80 2028914 ET POLICY TOR Consensus Data Requested Potential Corporate Privacy Violation
TCP 95.143.193.125:80 -> 192.168.56.101:49207 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 162.247.74.201:443 -> 192.168.56.101:49211 2520015 ET TOR Known Tor Exit Node Traffic group 16 Misc Attack
TCP 162.247.74.201:443 -> 192.168.56.101:49211 2522015 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 16 Misc Attack
TCP 162.247.74.201:443 -> 192.168.56.101:49211 2500120 ET COMPROMISED Known Compromised or Hostile Host Traffic group 61 Misc Attack
TCP 95.217.229.211:9001 -> 192.168.56.101:49210 2522809 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 810 Misc Attack
TCP 192.168.56.101:49211 -> 162.247.74.201:443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.101:49210 -> 95.217.229.211:9001 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 193.11.164.243:9030 -> 192.168.56.101:49213 2522302 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 303 Misc Attack
TCP 192.168.56.101:49213 -> 193.11.164.243:9030 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49213 -> 193.11.164.243:9030 2028914 ET POLICY TOR Consensus Data Requested Potential Corporate Privacy Violation
TCP 193.11.164.243:9030 -> 192.168.56.101:49213 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49212
195.201.103.59:3333
CN=www.3gg2v7jrf2gop4.com CN=www.gzazujcdd6f7t.net 35:7f:f1:a8:7a:9a:d2:0a:54:ec:b7:21:3e:eb:ba:d6:9d:08:cd:7a
TLSv1
192.168.56.101:49211
162.247.74.201:443
CN=www.adxrs6re5yxnwldtusi.com CN=www.j4utjsuqj6osi2monp.net bc:69:b9:d5:4d:1c:ca:2e:9d:67:fc:2e:21:c5:68:92:dc:10:0e:6f

Time & API Arguments Status Return Repeated

CryptExportKey

buffer: ªDH1ÑÊÅM"®)Nbîáˆuˆ'ÛæúÉÔ}rh]@c¹÷O•ì„Í’À‚þ"/»ù#þ”$¶•gîð—â˜?º¼œX‡°ßR-2ΘÐ*¬pÇjSqD†He£{Ú祉Me,ÈaŽëy¾‰K,DsG.û¢Z!µ‹¯žÑ°“
crypto_handle: 0x003f2948
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1:ï¬5¤€¤á϶­ð3ç.p=.Óµˆƒ^:føu.5×ïFZùb‰J]:‡ÉVÁ•“3(ƒ*gï×`F"߬^AåWМ¹æYV@+¹îî`úŽ¹à Ë6YÂWm54¥(4E0$r¿@,)9lujrrÞø—5a8
crypto_handle: 0x003f2948
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1×[=…Ò\½Uvç¬?A¸[T—1Ÿ‚^ïÏ[©'úµãaˆqíóM¹ä«ÅÒÄî©)Ëá¾s½Ì¦¹zn>:¨êWß;  ~\"…r³»%lŸvG1Ù@°"5gŒGUùÃP&Òn…(„Eñk¿D¸;ïĖHµk·j
crypto_handle: 0x003f2a88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1[B®<ÞÝB›èò…Ý€ï½|¢WfœUƳùq!7âH*QÊs%D:û̱›wb’``…}ôôAøoÓK—©9ë¼|CÜmE”ƒ±3k)¤&÷h»²cÕÙ§Ê/ìâY 4¡¼i†Õ_`² ÿ?iƒÌÒÈ鈗”Òðlµš t^
crypto_handle: 0x003f2a88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1_ÐDD<ԇÏç¡3ã|{4¾ŸÌ¶Ã$¥¸ƒkmUâã Ëڍ[£9ŒîÕ=Uª¸‚Þ(æ(Ðb/Í èoÀ WÜ±JYŒ±8³ì{×õÃ}I¿F`ì%CÁ§Ç¯µ¥#Tñz ²0S@†´º\^:ZÆoC
crypto_handle: 0x003f2b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1CƒªË`½iê6–FW97U§¥S5ì—ìÌ;÷“ø•$uōWãq,½ùï1„ýL¦Ëóêû˜\fºŠa¬xßúY—£ðQ^Ê¿…Տ»aÈîa}Ñà¸|oTe?Çidý¹ ÷š a}@àv„‹nÛþV„Âì Ö)›íBŒÌ}ê
crypto_handle: 0x003f2b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1_í /ÑLÙ|ú΁¾ñŸÿ&îV Èõâ^ºþãU'͘ÅwÃÉÛ©ÇÚ2å(1"•¶¨è§I³•1¥:E™ Vª?›ñM·¢ØVÕH_ ̪Lx}+ø˜auùR9oŠüï‡Y‡äœÁøå*EjÝ÷‘ bd
crypto_handle: 0x003f2bc8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1%ùoOöãT‡9#`âßNR3ût8`9~è,“Ë %𤯕ïJ~¦%q;ïÿ¹$*H‹âá+•2Ȝ&” úë§i9[âL/¬E_#ss ÕFY|̘Rü¢®vvg›7®h3Àšú%yĜå¶FþÁݖMËS7¶¾OS]ä7êùÖN•7
crypto_handle: 0x003f2bc8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1}à9XA¹^Ÿqׇ¡ˆ„&(o䐶Vï ½7­‹Sž6c0±s÷[eac ‹:Xñ©ÿÝUÃM¸¾Õü®ûÏ­Óñ?¥z·$±ŽJ™Wªu* eÀ‚356t X ÿPX<¥dZO5aÁiƒ.ÌP Í÷%§N×{}&=…ã"c
crypto_handle: 0x003f2ac8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1EvEܟ)@{='³ZŒ'óc~ä\°Ö’>Žø»ÎÉé¢~ Aƒ3:v£Va;fnwöÐ8æ 4A„€'ó˜ð¢“"þåxÅ5_dÒیó çMG‘g›M‚I{P·@ê@œÙsÈ æM³_ôÿ )|šs#„Àò‹5k ?¦„…â
crypto_handle: 0x003f2ac8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1i=cwrnÐ6¤‘ºÈx›mU.搭V{ºˆ]`÷¬FÕHç÷9 Ó(³ˆ,&BŸ•LZ‚l"ÒŽwç%,š  &ÁÆìäړ`{Á»£ÃÐ=;´7 fé1Uã–ÇE›Žړ´sigìUžvÏ_ñú´ë!í–øI
crypto_handle: 0x003f2a88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1„¿ g*m礷‚îþ¶ùnÔHÔzAšäEŸ a䈓QÊàéÉÓF=¾)k?xP.Þ`Nù¿eZD·Þ}õ1ë#Ë2aUE¾l«Iã<Êù¼&‡a·ÇÅ çµd×0]ñ?YGRÝ›Ì ÷ÆGÞCØÌjœ‰ &”@Jñë
crypto_handle: 0x003f2a88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH19Â[PﶆJ$´Íia ë1èpÔ:®­‚|$Óp·Vi̼8ÚûAIÕDÁ¹8Žh¹ùE_ÜÓfʼn…³÷]à5áƒÖ™à,ÈÕáUžÿúÖUCöOþ^2ÞµVõ åyÕ³³rC³7eµ?µÇrˆ`°æ4y>Ý…¾·Á6
crypto_handle: 0x003f2b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1ŸrGÌÔ hd‡ë1žX>,È8¥Wƒ=”ÌÌZ\¼º çPº”B–‰·#?pPÀ m¶d̂qŽ¾=Ӗ¸.ïiºØ´Ž=øœ%Š„‘#Àç!qÝ[‰·ýÉÈ;MV4¨ýñªñtHÅõþ!äqB¨[‚ÄÊã;
crypto_handle: 0x003f2b88
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
pdb_path
packer Armadillo v1.71
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://95.143.193.125/tor/status-vote/current/consensus.z
suspicious_features Connection to IP address suspicious_request GET http://185.215.113.93/cc11
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://23.129.64.201/tor/server/fp/0011bd2485ad45d984ec4159c88fc066e5e3300e+005079a42356183cea5a3add239303f44f12e7ea+00cc4ac22501360c541185ee7e4466efb7032cae+00cce6a84e6d63a1a42e105839bc8ed5d4b16669+00e1649e69ff91d7f01e74a5e62ef14f7d9915e4+019feb22ce04cbd0489b7f24be038518b64fa223+034168fa4180b8662439fc714e4bdd7c6b39f5df+041646640ab306ea74b001966e86169b04cc88d2+05051aa95fb65c64e6a99fc0963cedeb211c88ba+05499507da8b381370e0858a784c3afe13dc927f+0a3c9ebb64ee062aa170bb9bf2b84ffb02da88c9+0a4ed4c74020740a904f3a9936030b7a4c6170bb+0b19bbfdc498ccea23027b1d7bd8e20121b95e60+0b37ec8be844f5c20e5b84a885608de0c7dbea47+0c93559d6d7e95b41561424345b0b176fbe66f00+0d2d4b1d27468806bb1edfb02715eee91e1ab94e.z
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://86.59.21.38/tor/server/fp/d5f09497548a39071d14ac9e9aa926a0f8a748f2+d5f5502c1762a0b737a81a6bdb78ddbf7efc7725+d60c2d85ead93d23f1c00874d334bbf8a96cd529.z
suspicious_features Connection to IP address suspicious_request GET http://185.215.113.93/cc22
request GET http://api.wipmania.com/
request GET http://95.143.193.125/tor/status-vote/current/consensus.z
request GET http://185.215.113.93/cc11
request GET http://23.129.64.201/tor/server/fp/0011bd2485ad45d984ec4159c88fc066e5e3300e+005079a42356183cea5a3add239303f44f12e7ea+00cc4ac22501360c541185ee7e4466efb7032cae+00cce6a84e6d63a1a42e105839bc8ed5d4b16669+00e1649e69ff91d7f01e74a5e62ef14f7d9915e4+019feb22ce04cbd0489b7f24be038518b64fa223+034168fa4180b8662439fc714e4bdd7c6b39f5df+041646640ab306ea74b001966e86169b04cc88d2+05051aa95fb65c64e6a99fc0963cedeb211c88ba+05499507da8b381370e0858a784c3afe13dc927f+0a3c9ebb64ee062aa170bb9bf2b84ffb02da88c9+0a4ed4c74020740a904f3a9936030b7a4c6170bb+0b19bbfdc498ccea23027b1d7bd8e20121b95e60+0b37ec8be844f5c20e5b84a885608de0c7dbea47+0c93559d6d7e95b41561424345b0b176fbe66f00+0d2d4b1d27468806bb1edfb02715eee91e1ab94e.z
request GET http://86.59.21.38/tor/server/fp/d5f09497548a39071d14ac9e9aa926a0f8a748f2+d5f5502c1762a0b737a81a6bdb78ddbf7efc7725+d60c2d85ead93d23f1c00874d334bbf8a96cd529.z
request GET http://185.215.113.93/cc22
description lsass.exe tried to sleep 239 seconds, actually delayed analysis time by 239 seconds
file C:\Users\test22\AppData\Local\Temp\1476310495.exe
file C:\Users\test22\AppData\Local\Temp\1476310495.exe
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
buffer Buffer with sha1: 2fd868d94c6dc063ca49c767c873505fbc87dcd9
host 141.255.162.34
host 162.247.74.201
host 185.215.113.93
host 193.11.164.243
host 195.201.103.59
host 213.32.71.116
host 23.129.64.201
host 45.66.156.176
host 86.59.21.38
host 95.143.193.125
host 95.217.229.211
host 95.217.42.50
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Host Process for Windows Services reg_value C:\181703055310012\lsass.exe
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Host Process for Windows Services reg_value C:\181703055310012\lsass.exe
registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
Time & API Arguments Status Return Repeated

connect

ip_address: 162.247.74.201
socket: 1772
port: 443
1 0 0

send

buffer: ZV`®´¥eè6à˜jÜ´`\Êü„Aù(ÅûQӊ\qï÷/5 ÀÀÀ À 28ÿ  
socket: 1772
sent: 95
1 95 0

connect

ip_address: 162.247.74.201
socket: 1768
port: 9001
1 0 0

send

buffer: ZV`®´¦â-Ë ¦ˆøØk%Õ¨¤ 8È$?na§/5 ÀÀÀ À 28ÿ  
socket: 1768
sent: 95
1 95 0

send

buffer: FBA @ìõdUOï¼ÈGǪü9þé}¯ØõݱUMYÿ†”n×ó» {n¹çã–54ÄOGŠ¾$xÓ6ڈû›0'ÏÏp]¸–fÆ^–£K]QþÊIä2øÎÃ*:P|©¶Kí¼ßæOj ¶ÝÅøQ(
socket: 1772
sent: 134
1 134 0

send

buffer:  Œ•¾¿ÜåðP‘ÈÛb¡¥ ›É:„¬Bdä7uü
socket: 1772
sent: 37
1 37 0

send

buffer:  د3ە¶ š¤‘ÞÚá]¶J3>¾ñüu0‘¦›”htJc¤Û™xØd­E9#…K¹…©(Ÿ ˜Fxö|áæ0è9è+¶Üßéoßß1š";h-4‰¼ÊØÿ@®‘¥=kÒ—ÕÀüüà2.Á“Ö©–¿#j=—öô4ýVšoXT–™³ѦÖæ? Öv•)y¶7N-Â<bêÊgÑäRà‰ÌE:(aöÔwša¥’Q²)SS›È¡ë' ­y[FÜ(bSÎQËס–í|½°ÔÕÂð—à²ÒæôYè÷¶áµgò-ÿ©>ê çÙ-ÔÉè(„¿¶¾w$°Úot+ ¡¦Ý𠒶ñÜdQ¤j‚“š¼èfüåë÷æé…6T"Þ· ±Ìû¬d‹• T#áÕu3£/á6lpÙVµn‹GSbÀz‘µ¹J¨ŠóÏ´Þ!£/¾µ¸*mEàî֬󿑝þPÎ*¦ñ¾Wk%o}¼L ës¤Š#¦g‚u:xçM‘ÅÕ'q›š ë†êêŠ 8"“Ä=ýÆè·xNIª[tÕ¢ø`µËÈ­ ÂZ«€_ý©™2ÕElÿ0›Û h(¨º€QÜiGlóB €Ò‹Ô6Èxtê·Œ¾Ec.ÎYh xÿ~d­a?}4•¤_e'÷f^‡î].Pƒ÷©a\‘\•ZYP“œô &-vÓgþ3ÿ
socket: 1772
sent: 549
1 549 0

send

buffer:  +õt9?Ãꊹ—½ô$¡†r¥~֋/ÿ¡ä[~–uU®½tþñρWìÿÌhnâÏOÀÙµ…}eq”ä%LÙ…ØÐ~ /Ö’‡˜ Ñ`½Ý/Fˆ6ë9*%:I¸‘†YáOb°ÎpÁ/@ÔƳä|Z:þ)uT†_¢úMBìÞec«Ÿd<ž›¥¸&Ã+‡RI^Œü÷Šì¨åÎGÖÌL>Õc(S£œË5ò±ï’ð4t.²|mþÕlC¼¡FþJ<p‰q JàìjšÑÕq•’|àœ´æ/”Kàezا}÷éQg|á üþÚ· [ÿf݊‘ŒÒu ÙÔÿ•æ¿JºÃäÝÃhÀŠ3,[†O‰Ý y°âÃß`Ý2È_Ê%؛ßLcñWz@ȶñgªhÊÒ1Nu ¶Ñ°¨Ëc]Ą ‘Ê=8qƒ& Ól¿î¿÷ô¨ Ð趡šZêË%„èﶽzñÊÕ¡™÷—Ý–°KúööfÀÎ+<6࿅xvn/ ™Ûž¢F(c°c¸Î$¢E@ôC08¯á )¦G“ziŠÈdÏÊ\Ø1Ív"Îyï#ðEáö·ÇZӚ ՕP³­?ùÕڂk,qìВ_›c% BÏ•ú¸.y R뙏ž4Á¢ ²Ng3¤Sb¡ÏÕã Øw‚gUíɕ(ÃPд8¨·Äæjþ
socket: 1772
sent: 549
1 549 0

connect

ip_address: 195.201.103.59
socket: 1804
port: 3333
1 0 0

send

buffer: ZV`®µË“… äî—uÇ)m &#Ô2ßáÝ5æ'¹çkV%/5 ÀÀÀ À 28ÿ  
socket: 1804
sent: 95
1 95 0

send

buffer: FBA¨R5¶ºáŽªCÄ¥7ÎÊ'˄€e§ž>‹r’k-ߝš~ªÙ65äƒÒÙ¡Ç¡˜4º@lN?®\x„V¸O0ZÆ4Š'Øõ鮹ât*ß9r©‡úÏ.촁nØ, ÀSØñéçÿ{’]ÿ{
socket: 1804
sent: 134
1 134 0

send

buffer:  9K! #†5AxWætȝÉÀ·90æ睢¨Çqô«„¿à
socket: 1804
sent: 37
1 37 0

send

buffer:  N |¨åO?‹Õ†>‹=zX¬:…cÌó㸱²¡ššL1I*ƒ[a-Þž]ªœü1ûÌ£iÍ{úˆJ—1a7o¯ ÇçOs6Žñú¹-¥ÓᓻW±Ÿ®ç¶*/È+‘"“Gºo·  ÓpƦ´$ÜPï>Ûú7®†sõ²‹§š[T5”üD`Õ³`ï™eˆjÁ†9²p`*’˜Êè«Ç:)Rƒ·Ñ矯‹žñk•Vr)-bw… Ô(íN¯öæ9v¡´Pyø Š=SÕLy1MêôéßJ—Ü(¡ž¼FMWJ—"Ž!f¥ ô¶ë?' 4ùËRÄìÐ^¤Çdî(ÿ2ï#bþÁïSð%;N3x‘îGL„T);`þR›„t+¡>rልÄÙbȉ´tŠûÄéKãœhŗñ¥?É  óÚï)²Û2_gëÈJö€ê⌚2Ì.Â2Øíºì ·"ìrjþɄ ã5óÕRkŽ­­é;T8á̜|Zuÿ)7&vÄÕåL{µž´ òÓµ¿GŽõPíU Ÿ!2á¿ÅóáՄ«ª'ËíÂÁÈ£¡7kX;OQ²³dò2|u"ãáãe h4}…|þ‚Ç£jP…ûÕäý×ÀîMHC/תŠìÿa€ø?¾ ‡É?m$Gºpα_W¶QMXi6Òx X”öqœÒGôètÚs\’šwKè›Ik
socket: 1804
sent: 549
1 549 0

send

buffer:  oU~'Ñ7ÖGp)ï3¯×½—ìDªŒªóxµÊؤžÇ)…>l]á%ˆ\„2ú÷É¿xHJ#4e\ª8Ýo©äBCôåÑéöGCÍpväqªY•ÂáÑX­PY3£ŠŽì&‹¢²”™X¹.$fÛjm ÝÉ7ÍG1µû;³ôŠš8Õm|ô>衑ÓÓ৳Ìlíæÿ¤”n"Òg]Ô7Y\k ×Ç2Ó_êúƒHêN2[x®PG¶­„¢¿;¹ªðœžƒ†·ì¶hS¤ÅªË۶òð8DPË2†ðŠ¡W’ý”N¶³Kã©ÐkÃmû„ù ÙLóõ{c}@¬\—ñ°ÓxSDŒK],øZ¤?>:Éúñ ¤¶[äbäµ02ÝH@R¬ ùE´§Î›$3ñ»b˜mBaò/ož€½×VOŸᤧâ÷U/sú:«Šö©Ï´}yÎʃ“õh³ ãu€MŽZ#ð#[ü_þÚ]|hFl¤–°/cBw «S oš+èt>ƒº°Å„å‡#öƒúíW ¸ž)‹Uú mÚ'â‘Ü»ыßǟت¸.Êʅk/…)Ø%¯{_¯Ì#çÁ‚“ó’:xã* ðu_<Ñ&002,çe)A‰L srçZj€Î#m°Ò½TÔôM^c‘³m),¥]! j»i.ô} ;}+jÍø
socket: 1804
sent: 549
1 549 0

send

buffer:  †7<Ä+xT†Î6ííùÓ¥Æð›ÚØ.•¬ˆXCóD/Ÿ?”ÅÆb ×ÞàœY~^|ýà¿[ÌÊ{s ë|©çÛ˘^‹R´¶çB¿¡kɒºÃ!”׉’Ñ.:ͼIjOí¥ÿf‰@I0SåÉÓõ®¾Í7 )áßtJW͌‘d£`áLSRY±? ÙUN× éÀ¶x×ÐO¢î@ń.¿GéÕ ”¿AJ΁ϮÒH"T¤ØsQ«ÀvMð%2p;їB‰sà5ü–ßRj†Ì %5Ê ¦9S¯«zžìhUMßC,Ÿf´lÏt±ÓªÍ mŸG1õ±FS• ÷]º†Žw×±äûRºè®áí@ jv´:̉pD¡ÆR#tÁ% ±;êèŽl²JҔ'ÀÒïpwŽc–Ò&A ¼—­ôØM¹ð4an'Ñß©—%`ÒC`Ü}Yä4è!æšPwuÔq&¤÷ÊqF˜xë O»¹íeÚæ$¡ºÖ–³¸ñ¢ÛZGMgív؂à x÷¡Û›ð‚dMPïLP{AW}QðYϝW‚H1ó,Çãx9¦A!SrÔl•“š~kù5ŠÅÉÙÀЎ°õሺ[xð²èIöC4ÙàØ¡™Ýé`ã“)6Ç%ׁtŽf™õÞa«šÜï³ù~</êåѳ‹âôUuÖÓç v¤üØã"N
socket: 1804
sent: 549
1 549 0

send

buffer:  ÝÍiÁSqœôPÞS 1 ¼„›ÊohÆÜRŸåz˜` Ît¸Ï—q›@“™æÅv­b©•BÊðȃÎIì «öM€²®’T\b\Ín” ÓYHÏ0CšúìÍe}XWd]“Mѧ]¬Ù½•Íö…Æáú`â &[Fù%¸8ýIü±Lê¼BßK)ÖÄÂÍ@Àtó2â‡Ûo<fj‚ЍÇlõÓª~Tŋp\š”$œhráëh߈< ÇO¯‹?½ K1p!L†7ÞÏíͺf$’+ù17»58ö½ÑpۄHhƒóøDà–Wkv ·Ÿ0ƒ]íWûUύì…ð"¬vŠá^°j½VÞë¨Uéñ&ô%¡]L4›Iúq Ü –“é´7÷ԑM.ÑWyn¹âBaƒD¿×žìI˜®é4¹ÑxÉô×),j-spŸw>‚@NŠ„FJ&æ~6ÏŸè#oA)EÕûÛö–ùèᭇæ«XOÉÎÛºc°ÝŒR·ÍJy„òPR âÞ8¡.‹±nS<þ¶*®ä R‘ëÝޛ@6Áh,,ÍÛn¡šY Íd¡<Ì͎§IKµCzg@¨}q³Ø´ÜP•Ð&݁žºu€¿¸ÛQ´% @Ë,SÊ|CÙáA‰!à^ dãËAñ¤ò
socket: 1804
sent: 549
1 549 0

send

buffer:  ð³5¦žŠýÒ·b_@½‰x£–qÓ¸ï#Ñ%;..&È¿GÔrþ÷÷ñý¡¢ýk]ó‚z ~åP¤¨Þþù8¤ðá·L¨?ÛœtI!õ ²`ÀaÍÃ¥PÐÅvŠã2dȊ[ÒfÐXÔØIÌ4«ÏŸ™°ÓCøOC(áÕ|LÑg‡À‘=®,W‡»©Ö)_)¥‘í¢HÔÙs3FeÅ&jî÷”•pþ­ÂP¡ðGŠÔÏ$Ï阂=*òß5ÁZ²õï›þAªº¦ŽÒeº_nR@ðDzå&ƒ~ ¶#~Íq+ªåþÇí|ýõÁ)?ª=ÉûB†Al“¶[  àæ ¾#z!{V/€X­Õ#½¯•g ɸ"áØApÏ{ñ¯ ±²bNtQÞ ¶{€‘¢jBكģQQhB'eá§v6ÊåÞyð÷T@ u#=T¥€kn*âJÁ¿TSŸ Ç5‡ðíÃë§]ˆí»}G™ÂˆÎ®ú܇<ÖZ§Â«…™·ìǐqX‘ဤú2!w¢ê2—ùR¼ðåü?ÎþT •ÈG/*­«kyIgy-¥Æ½{çßˎÙ×|¤½0ÕõnxŽ0ÌQ0ýÓCœÇ— ðhUKtìGŸáþëò ôt€,63úooo÷}Ì(9S'áa§ 5º $:r Ø-¢”GÀ=ŒG
socket: 1804
sent: 549
1 549 0

send

buffer:  ³µØ}jøg&WLšãNmâ*–‚‘ƒfÿ:È6âÁo¹¾×4”JÞ ÀÁê«B¶ì´Àr2‘ë(šæZj»¹‚¦MábSÜÐè"ËB|žß5³4Ö —!Öp”/ül™ª®äfÒ;–,ý«wè;„5á·Œ§±<!BC͚km¼%Ê50 <lQqúí91ã{MC> ðjž‘%úßKRÎImVfNžúQõTÐýX?j´P«<³²,ÇÐ5E¹.ٶ˨í~.;{э½¢-QFÕxŒl&q­oò_‘U.\Rȵ? à„V•€ä‘&ï‚ve§‘‘nõð9ç@-ÍÓS•+÷ÅÐg{/œæuØã0as+Lî`ÊiµGÔxÛU‰8i¡ïs)þÑãLÁ²ÈtÔº‰+’}nŒ[Z^uÿV´àz¹B fä|¤\ž¯¬d%»´¼™ _&åXºxŽˆTÙ§±·÷ºô–qBÀ¯üÙ6¥çéÜÓ:aY¼_ƒØ@ݾJ2øwþp/©êß~ã³RfO¥÷ýð¯™µŽò¸jÉéù ¢ ¶vÎמ?G¬ž}Y¡*"ã4%u·iHV1÷QÍ×]@?bK‘ðÆË`ñ'$³ZÔÓ5o\ -–ë5kTª! 5l×Ùè~SHp™ä=øàºõëú½­,`€Æ¬ƒ¢ u
socket: 1804
sent: 549
1 549 0

send

buffer:  ™ŠdY‘:u8Gxx”Kmù‚(J3¼]ÁUãþ>j>ÿ’ny!Ž'°æKÐo†¡AµYîéB©äOóðëJûœîD®Ÿ,±âè²q+=?÷\lƒôÐU¸vñíHøe9ë÷®Mÿ6ªît•šéÃÝ9òýd9d°”â¡í{e°ÇÐJm1"h-5Ìä=Yí‡ÎÆé\–ömcßAž$±ž59K(òÙh´åûk±`½f”6Ú£Sè0]i«3 ¯gƒXÃ~_²háÍÀPŸb £Z–Ûqâ°ìèo¹˜$]ȧH^tŸ­Q×èGgÿ„7q£n-”Î/[(ßFèʆŽ0x8KX‰ÒG%ݶ™Ÿ÷.MËظë¨ ê[1Òx•q· ñï2£Ž…Jn+¢}ßõt˜~=Õ!=Ù¾Rî³ÃG١ۀâ$’eŽÇéYñ䟌,7a›™ïyoB÷èA—Ès˺΄`£]Oܜ¬¾°·8vÏ&™¿6Ž¶Y,å;KÈZ¢Võb¦±Zê¸Q`†šï69ÍÐ,@~Àgí[†2èÆíÉMŸáGCgïr†Ù£O~eR›PŠŽ¼<‰jß?-:'"’LüÇxæ¥nА™¤|à"&¶cÑ #¬dÙm‰*ÈÊ}TA7ó3Gð©V£“$ ˽ĉûhԞ„Œ@™ë-¸
socket: 1804
sent: 549
1 549 0

send

buffer:  €¶¿^¬îÙ}ªæszyb,ÿÅBwÅHÃížä;£ï7Ÿš*Z54Ò!´95®éó¤ Ɇu¾ örÎ2­SF¼¸‰è ½6Áy8"8T‹èÜ1Pª™*ÎäY½0Å$ù=´{š4ìmF"žs~Þ¿ÄÂk»#&]˵YôºÁnågY5 [ÂßbAñôEzc(Å|¶®õ¢b¤ð¡Ÿjñ6<Çg¡š§‘BÿwèÁØ`Ž‹;¬< ‡· ÂåÛ¦‚Žwm_5Ýl?Aӛr8LæX…wFþ¼…}zq—fŸ\Ô c[j¹Rýl2֝ç™G^|-ü@ÅpÂÞòPiR9‘yH¸]{5 u„ïü«3þÜ>7î­ÓʶÇeÝ÷¯¿ÚZKûG•Éœk~½8B=½‡ÿª?½Lš¢¨/;S+"QG·\ù3¯„"*Oà5aԏ®Šb·¬4¤«‘Adž®ï¸”¼~~ð÷Î܇J©xÂ:ûꤽ§?y쪤ÎèoÉÈNo|·é)§›™gÛÿB6öç ¨Ëvå–Ò@©qþ»Ã,a¤u;H/¾èQ ÷øBô áÛì‚?Z*Á°²cJè˜ SZˆEsÈ:Ê!JÉò¦¼–a‘Wû®§¾Y³õyšUŠö`ü©‘1ݟŠ&“fT"Ïӈ:ŠÙÃQ?¶.NowÓ*
socket: 1804
sent: 549
1 549 0

send

buffer:  ÄéU’áÜdzWÁd5òêMr~t=0ÿ‚]öùJ4µ@ÊÇég4Þ gm™+YºlìùþÌ*ÎËZê#‹[,Üήó„Zý|}ÏQ jx·«Ñ)U)¾HԙG_½aNßú߂Þ7€ê—ågKßoP&YMCº² D¯˜ç•ZG  ø½5ÛˆÿƒRPŸ©Êf‹å>ï¾Èûÿ¿c-õBû–’{£I'râNò ÿ] BeñÆ 8Èâ½gÒk+¶GE—󏃘Ÿ©Ýå°y ñ[ÛÛFž\÷c¿W¬QˆÀw£c¥&,©ÿ¥Àë;«ƒ­ŽÙÜc²V"/½ûÛUŽIÃT×æ=­]Ʊ+ §Ë-è»8ÏWÔ¼E„NY~Í]Q ñ&c pfŠÕ!ȗ†HS OK1‹bOÕòƒY5,bAìã¥S¥C÷²$sªü}Ákh1EK/øYZFä)Øð‹x¸?ývd÷¿>]?wþa*w!Ù-ÍńýÀÇ÷ò˜ lØáD²€™½ iQäe< æ6‰ïHËòˆ+3 ü„,ê&Z_æ’[æ¾#Ö'šRá{LŸé ·°¡Ž‡ëÊ;¤¦y¥P¦Ö¨Œ²YÓÈ[Î,€ÒTñ\ñ€­•®rèíP|W‘ÐÕz! ËÍ!›ë8òÕmtv%°£±øFuKuó_ßV¿¨¢P(ß
socket: 1804
sent: 549
1 549 0

send

buffer:  ¸\ÐÜ<¼•š)êßQoªûÇe÷Ew­PŒd?Ð§§ªl]óƂí©¢¡Nâ!%áq5jM²Îi…¿{mÈã×O)Z-ߔ‘E`hpBcŒÚè#É@/,AñDGÑa¤X|½Ò†2øÓA5•©‡Z?Î^ñ KHd'†Ú\6Bn™³ó‹Áï_þÎ9‚ÂNæ÷6Z¬qTdÌ-â=&Ðâ×Ïum,¦zY[ªËÇ^V0â,~ &û}¥9~Úeßè"óé„Dô—pAËv“°É¬b›ˆ‚DÓWÙûÈk³ä°œ’×1EÂr<pCM¬ö.ÊàS¾G‡yÓÜï`5‚ Ö¬s»N…Ž%%6Vú–Ã3½þ¸B(”ÜÆwü´¸.à"Œ?«Eñ/»3/£1cðò´½vð[»Uí^Á/æ“5ȾþÄq(Ó`TRqLUÐú Š®lÀäãÙHýŸ ˜Tõ¦ÓÓ£é{z¢5¦å˜ *2Àvlv—›Ör?öux’rÐYŠÿ¯Ìtø?óͼ÷j`™A¢Áq#4̵!¶ÞpJŒe&ÚmåÏâÆái×;Hf®ŸÄna×t¾jË2R W^fÅÓò8ÁHVÇÿ9¹º]IÁ‡çÅÅ\<OàÃz}¸Ž~Ý¾R^‰ÈY¦ª¨áˆ,³¦Â°¯œÖ39¢ù kdy»?áLQ~ Zس&_ÚV@‰Wˆ2±
socket: 1804
sent: 549
1 549 0

send

buffer:  Èi×[‡qh„“MÍ/ç<à!lbÐPéY§q 9Å~{‡Gîu›<q}¡žhâŠ#•=7M,êøždÐ3zÁ ¨²è|}'j@ÛfëøÖ1«b}xp¸þŠz8Nñb ¯ ÇóÕHˆ/»l}ò/Á»Ý٘yŽŽ©(2ïe¤¡fmúg^ ڋ/’'NFêˆRNþȞ³nILZ µÕ!ù]˜ƒUá¢þ“úÚbDÅDuÕÞ-o nòŸ xÇubê/ØsY'¾æly(âÖNþ,՘ÇTD(×¼w0«lì"Lod5Ŧ1¼KÊN pi>{$qÙÚ|$ÉϟZ“o:bùR ÿìÚâjöûo&œÿ¤!̲‚šŠŽ½ f&­_•¦Hµo•³4®Û^ÊQ`®@÷OoWÑu¬ßæ}Åäєw˳Gkà Y2â.ڍ€Ü‰dÒߋ›Á65Í^ªe‰âq͗gÉE¶Ì[LɆáâAbÙ«“YOÅ÷³ˆíݾ‹‡mçhS„vü2|E¡ñøcZl2[Ø.qPÞl`Ø>Žª†Ü¥1/d‚¨E]‰´\m¤œSA®" 3r¾)oúÏsÚ?çʶ­~ûàÃìS½›ºå9Šµ9þ‚,ñé-÷¸í Dj”3+œnmÌ:Gpãì»ãíú÷!Ö(‘I£¤Ür‹éu#„¶;ß-ò: Û¢&±ôÿ
socket: 1804
sent: 549
1 549 0

send

buffer:  þw®¥Âڃ>\ZÈs»`X4EÜ ¾§;Ȳ.IÄ¡û֞ÕÁ“^: kE±÷šþåÈ&ù½†ž‰Èç,Ã2å°‘ÐÈk‘S0e6eû¦]™Y!$œ ÿ‚G}ƒËÒ(ƒeŒ4\‹‰.¯\5`QåÇÇ«÷Å~xR­\^Ñ|fô‰ÍQANœÔEaÌçÙÆШó&ë«Òx?œÑì:¹¡5'Þ]éáüq5IÀö£R$fZMºU5ó@K {;¹0 s}uìÂÚÿä(U4h‡`õù(T(®Ÿõ¤W%xè;œ«¥ìû¬Ô‚푦ïbVyÅþF÷×;w 튒wJŸðëÒðÎmIµ>…ÉÏÃȜ·¥ÃP¹¼K\qeêÅ@@òÏXj“quzè^2_C>'ü©—!—µ4;ª†J̨Ar¤ù3p"b[Ž­cõŠ¥Ø¤©å¿<7ˆò©)PÝrec1ŸMÞú¥¢L6Zéò2›2-³‚‘f‹ÿOâ¡ß n É¢)jK5›ºÁ:®+Í&ªºdÎ4=ÔR ×M‡|½Yé8MW¦¼ÄË#“ƒ[‚\^ 0ûžpÒy™ÖäLUÀ:Tys‘Ää_=?ø 7ÚvS–Ìn”ý¯ösô<«ºu=sšÁ©K'0`Pñoó„ý-ñZÕÈýÜf`1Ö«ƒ^Ð.馒
socket: 1804
sent: 549
1 549 0

send

buffer:  ÊÿRÉ?›ô-õ ¦–¼²-æ'z'Õí"Íã>þSßÊEœÐC5Ø-Y&Žoç™ùõ®çÇlX褽SIsî´K@jŽ©HÑpah¬e}ìÛE}m%~2öQjµë폫‰öb*†çYgh'z‡–¸~þ£å†Úö-ÝÇeB¤§£}÷ȶ"Â<÷g0jy7îü’‡j(HTAò{WOþdÑ«Q_@èŒpa½Ü¦©þÕÿ*ãô„Ÿ:B¼rqcÕßfV%ë¡RSÙ{ô½«Ìw›¾E©9[&8*pÐú©ìIoÑ¥¢ßɁBÐÃÔªw¯»ŒÉw§#vÛzé}™0Z"s÷Þ~Ș¡p*uªË4[«L$ÿ¸U£|֪ݳbœ¡<^ØÃûý â3ƒ¦TÔNR$®@¾I”¨²ÿ¹w.Þ¶ãRê=_Ìf zîM˜@T¬çîF½Gš¥×¯’÷ƒw²%%/U6Ž–+1Àø8dˆ4Boá1°œ  ÌË7eb2¹ª δõC¶UQá¯3°•e+˜vǑŸ>éw?…¤³|ÂÛ© MâlžËº3þ»µViäï…=Uº9¨¿¦J‡Zi…Ì*7ÁGTɺ]˜w˜öÖ+ÃÌ»gÅ¡zˆèš¢I3±_¡Éa ¤F悠ö¾«Þ†‹(j°9ãMHãLð·QÇ*^ØTë¯Ä$Éؽ
socket: 1804
sent: 549
1 549 0

send

buffer:  T‹¨ÈExÎE…¥6w' ՕŽZ!ôúì›3—¶ (Û½a£’ÇóŸÐ_¦= ´*UÑÊ7eàhi¢Ó˜›LÊã´§*`ìZMÛ¥—¤Ÿ»O—³­‹‚¡Sî§XÂJœ‚»ú êT ßÜÌ4>å°}þù¤³°D놘ùªFí¥T” p‡}z"vÀû_Ôf½-¼¶Úã‹”Û,{ƒÀg z ¯Ÿ>ÁYˆ>̔ÑêL8×&#pÉÖÈ­®¡hg{¯Æë²bø7}G'F?Ì`¤¾ï£W.Ē/[GµßU¯Ò­…n ƒ‰Ãn´¬Îj?[‚ü%&ÿÝ{ƒ«†¡ÖªÂs­çú  l›¸£œµI7淎R_eæ…Ó5ÞË(7˜=:›Eœþup.[=E¢b[ÒiSŽ?½§,n‡C<±Ã¦¥æ¡.—ë`€6‘Zös‚\2u³EÅdhºxŸjÚa7÷H çÐL&mQ8©ã‡ýŽ–Ú‰ ¢ØjY©õ„C©s¼ûÓGÕ ð8¼LÉDË)¨$}ÉbãåéOìꔘ×gN ٙû¡…:—LØIÂDÏØð€D¤- ñËÕÑÓLÃv²ú¤1$AeôñÉ?͒{ÀAËÕwÛÙb—ªZù-•n™¸Ê]™¬¼ L IgêægdUÄßl°"l7!ý›¸åëœ
socket: 1804
sent: 549
1 549 0

send

buffer:  ñ¶âð‡ õ`.OchVš·Ä÷ÉfOvjCv-ԔŠ&%»±“C sœ¼30(áƪY‘ù1@p¢¦Ï1vÃo¬ÐÂìâ-”äì¿DÐLMÇÖòE¤ºU$)ÝX3ƟP.f¤¤Nó´»Wjò\g€§ëÿuB¬¾Šñ[†MÏa"£=¡V¡M-ežep¤båÆ=̅$g©yš˜úÞrµ³˜Ê7ûádx½j¤Xô.õѺz–¤®íÅˇ«åÒcßÂtTšì½¼-vÚ¼¨Ù Ùjž•Zɐ«•çXI¿&4P(˜öpãIб÷6ÅäÌçüuýBç»ZEéò˜jŸÏïÓև¥Xƒ¯oNΌÚ]Ý=„³<ƒ€±Ôo/(-Dgˉ|t¶¢ïZ*Zf_UUÕB;žô{rŽÝæ`rºó•ú£z4ã¼Ï¬¸µZOߝ“ŸiC`ý‡¿1ôž%”¯ôô×Ò¶„€²2ÒQúž ¿ÊlG?*K‹ ͸!}â;mwç*Ù¶qN‹u&³"Ž®ôà^©êFKñ°Žo¦­MÂÆ>‡îyÿ¶!a; Zçk<¬:N€èƄ~s…Á0lÉR@Ù?êä]>ڈ“&“«²«9çÄØj…KÀRÝ:j48¹DyOÔIÎo„ï“j‰î× FnxÅ¢_µý†¬r4¾½Ð0»¹0ž—ê6æGÈÒrýüC
socket: 1804
sent: 549
1 549 0

send

buffer:  êÚ*hƒàå*w[«Ý¾P²4vø®&¤HoCö ͯ(Ď㔝 \¥°ë‹kBSÓnÞàÞ`RA$éÊ«±­úSqî)›šsZÑtwÁ¤<r Ô-µ™¥Î)#)¦J󆑡Kϯ…C6ØoÜF½!A«{<Ø|}|s+A÷êMÃEyèÀbŒ£½lpÆ/ /9Ñ;aŠÉbúÒ´ÞX¹kÐwWM¤ag:}çèƒ2»äÏ-ýjÁ„ip؊Ö[QË5nè¥Å`'ÄnvÀ7n>ÿAßìu~ŠÂ®}=¥b®Ëÿ :Λƒøç§Þ¹ÌÖN€¾~œÌOc#INá6PØÉFÌM½²vüÂ4a´wAÿó…\Pô]¸r×&AÌI¯Æî/{éüny”À¡gS^à àXÿ{à€óÅU”«›qH~ýÂp@£i x§­YT&ʃiÍ\ñ¾b!¿ˆc.–Ѧé,^Ÿñúˊ]¼ìcãÉa_aÚ$å@¹Û܏òkÞýÑó`¹ÀûçN ×Ëʧ b“2ÿK/*wÎÐ ¶íc)háZKåå AM-4ùÝÞ¥¡]»”EÀ ΞBFLqOcne°`\*Z­¬p†¶\ÙÏ {è1Páé´4í‚7»ÚÙ#Œœ3Nq¾qiB•2uCMœÎà4°?¬?õ
socket: 1804
sent: 549
1 549 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesOverride
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiSpywareOverride
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesDisableNotify
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusOverride
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallDisableNotify
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusDisableNotify
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallOverride
process pepwn.exe useragent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
process lsass.exe useragent
file C:\181703055310012\lsass.exe:Zone.Identifier
file C:\Users\test22\AppData\Local\Temp\1476310495.exe:Zone.Identifier
file C:\Users\test22\AppData\Local\Temp\pepwn.exe:Zone.Identifier
description attempts to disable antivirus notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusOverride
description attempts to disable antivirus notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusDisableNotify
description attempts to disable firewall notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallDisableNotify
description attempts to disable firewall notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallOverride
description attempts to disable windows update notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesDisableNotify
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
DrWeb Win32.HLLW.Autoruner3.3323
MicroWorld-eScan Dropped:Generic.Malware.SFYd.1047967C
FireEye Generic.mg.ee0a1ec859b753ab
McAfee Artemis!EE0A1EC859B7
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cybereason malicious.859b75
BitDefenderTheta Gen:NN.ZexaF.34686.guW@ae1FM0ki
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Phorpiex.V
APEX Malicious
Avast Win32:CoinminerX-gen [Trj]
ClamAV Win.Malware.Zard-9793613-0
Kaspersky UDS:Trojan-Banker.Win32.ClipBanker.gen
BitDefender Dropped:Generic.Malware.SFYd.1047967C
NANO-Antivirus Trojan.Win32.ClipBanker.iusbkc
Paloalto generic.ml
Ad-Aware Dropped:Generic.Malware.SFYd.1047967C
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
Emsisoft Dropped:Generic.Malware.SFYd.1047967C (B)
SentinelOne Static AI - Malicious PE
Avira HEUR/AGEN.1132833
Kingsoft Win32.Heur.KVMH017.a.(kcloud)
Microsoft Trojan:Win32/Hynamer.C!ml
GData Dropped:Generic.Malware.SFYd.1047967C
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.SFYd.C4442145
VBA32 BScope.Trojan.Skeeyah
MAX malware (ai score=81)
Malwarebytes Trojan.Phorpiex
Rising Worm.Phorpiex!1.CA88 (CLOUD)
Ikarus Worm.Win32.Phorpiex
Fortinet W32/Phorpiex.V!worm
AVG Win32:CoinminerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
dead_host 45.66.156.176:8443
dead_host 95.217.42.50:1067
dead_host 141.255.162.34:8080
dead_host 213.32.71.116:9030
dead_host 192.168.56.101:49206