GET http://www.sisbom.online/pta7/?UZ=9K+XUf37kaVDuc0IEb/en1sQBc6oG59LX1JpxUbzLe92mNGRZFlQ32afb7pO3FMoswo/Nr7Bt7+lgxXjhaaHcK0lGMXqPnmX0dOCo/8=&E5x3=-G8E_Sw
suspicious_features
GET method with no useragent header
suspicious_request
GET http://www.maytag36.com/pta7/?UZ=I+8B7hWWd8/aZc0LyOI98FU2kxxJYUgzWPkNKI3Xu1M4KTmr5ikbSLVEKd5DC7LZ6l0Rcp22A4fkoHEesbNwOWp7sSOEDutN8WpeiG4=&E5x3=-G8E_Sw
suspicious_features
GET method with no useragent header
suspicious_request
GET http://www.selfstorage.koeln/pta7/?UZ=nRxaeJY0qwDQ0+6frQxSN5E2QFq7X4AyNJuuilycF0k/wVU2rXenu/JIKS0/EAOQo/d8R3vVu9XtC/4/t+jNl01+sEHp/xYpCFlSqjU=&E5x3=-G8E_Sw
suspicious_features
GET method with no useragent header
suspicious_request
GET http://www.cosmicearthgoddess.com/pta7/?UZ=13fhjxEBwouEnUsG2Zptbc3oT5vv/DEuG4iFtfSUwau/qJ9Hv2KIb5nyZ/MG0WCg1U40rxerqpJjqyPhopVWfuMIqg+QB/xDsz3LaOk=&E5x3=-G8E_Sw
suspicious_features
GET method with no useragent header
suspicious_request
GET http://www.yh66985.com/pta7/?UZ=r0Znjcl108fWq3DW2uMZlKkUpEOS0il4WTIwHqnkDlhXNTmyDe2k/moWxs1adkJw8OOtkgeu00hRWSJDuXN3qGN9obJjMdXlYosByRw=&E5x3=-G8E_Sw
suspicious_features
GET method with no useragent header
suspicious_request
GET http://www.playcups.life/pta7/?UZ=owQQ/LdvYhr1hQA44RH9bUiltN1V9/nW3nzbuZ7AnukoApd9+FtfvWC4rKSj4oUCaFCHPCKOWRRPvWiBpKGkSpFpDTHalZsc88EWemY=&E5x3=-G8E_Sw
GET http://www.sisbom.online/pta7/?UZ=9K+XUf37kaVDuc0IEb/en1sQBc6oG59LX1JpxUbzLe92mNGRZFlQ32afb7pO3FMoswo/Nr7Bt7+lgxXjhaaHcK0lGMXqPnmX0dOCo/8=&E5x3=-G8E_Sw
request
GET http://www.sqlite.org/2020/sqlite-dll-win32-x86-3320000.zip
request
POST http://www.maytag36.com/pta7/
request
GET http://www.maytag36.com/pta7/?UZ=I+8B7hWWd8/aZc0LyOI98FU2kxxJYUgzWPkNKI3Xu1M4KTmr5ikbSLVEKd5DC7LZ6l0Rcp22A4fkoHEesbNwOWp7sSOEDutN8WpeiG4=&E5x3=-G8E_Sw
request
POST http://www.selfstorage.koeln/pta7/
request
GET http://www.selfstorage.koeln/pta7/?UZ=nRxaeJY0qwDQ0+6frQxSN5E2QFq7X4AyNJuuilycF0k/wVU2rXenu/JIKS0/EAOQo/d8R3vVu9XtC/4/t+jNl01+sEHp/xYpCFlSqjU=&E5x3=-G8E_Sw
request
POST http://www.cosmicearthgoddess.com/pta7/
request
GET http://www.cosmicearthgoddess.com/pta7/?UZ=13fhjxEBwouEnUsG2Zptbc3oT5vv/DEuG4iFtfSUwau/qJ9Hv2KIb5nyZ/MG0WCg1U40rxerqpJjqyPhopVWfuMIqg+QB/xDsz3LaOk=&E5x3=-G8E_Sw
request
POST http://www.yh66985.com/pta7/
request
GET http://www.yh66985.com/pta7/?UZ=r0Znjcl108fWq3DW2uMZlKkUpEOS0il4WTIwHqnkDlhXNTmyDe2k/moWxs1adkJw8OOtkgeu00hRWSJDuXN3qGN9obJjMdXlYosByRw=&E5x3=-G8E_Sw
request
POST http://www.playcups.life/pta7/
request
GET http://www.playcups.life/pta7/?UZ=owQQ/LdvYhr1hQA44RH9bUiltN1V9/nW3nzbuZ7AnukoApd9+FtfvWC4rKSj4oUCaFCHPCKOWRRPvWiBpKGkSpFpDTHalZsc88EWemY=&E5x3=-G8E_Sw
buffer:MZERè Xè ÈÀ< ÁÀ(ÿá ¸ º ´ Í!¸LÍ!This program cannot be run in DOS mode.
$ y =`gó=`gó=`gó¦¨ó:`gó¦ªó<`gó¦«ó<`góRich=`gó PE L üöF à ö Ð @ @ .text tõ ö ` base_address:0x00400000 process_identifier:2924 process_handle:0x00000268