Gen.Variant.Barys.13489_a08ad57424
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Barys.13489 (AdAware), Backdoor.Win32.Xtrat.FD, GenericAutorunWorm.YR, GenericInjector.YR, TrojanDropperVtimrun.YR (Lavasoft MAS)
Behaviour: Trojan-Dropper, Trojan, Backdoor, Worm, WormAutorun
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: a08ad574248801585aadd8d10cc42d4b
SHA1: 3995b587f85a6a129a5f3cfe525292dc305b0bd6
SHA256: 5f7e3e152b05789fbfa3ff0465d2ff566408cfd44690d5591f0787ac3786410a
SSDeep: 12288:nQluhh7fuNZaN0fzhbTLt1N7 Aru whge42/YACGX9LSRMTwmqPVMQatasKZcxKE:nQMrubaufNfNyh/ZttQMQacsKZcEE
Size: 1091072 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-10-14 08:50:27
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Payload
| Behaviour | Description |
|---|---|
| WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer. |
Process activity
The Trojan creates the following process(es):
%original file name%.exe:452
00.exe:3400
.exe:3656
The Trojan injects its code into the following process(es):
CARDGE~1.EXE:956
iexplore.exe:1376
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:452 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\00.exe (2939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\CARDGE~1.EXE (11970 bytes)
The process 00.exe:3400 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\a33333.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LoMkjwQ.exe (673 bytes)
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe (44 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\a33333.xml (0 bytes)
The process .exe:3656 makes changes in the file system.
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\x.html (0 bytes)
The process CARDGE~1.EXE:956 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\w3ccss[1].gif (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\c_Y6_Ex_Vd[1].png (2572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\468x60[1].gif (3532 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 (100 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\h_Yjw_ZId[1].gif (182282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\close[1].gif (428 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9E4BE0042965AB3D0DE015F847D8AB90_03E448FF6BD55C02A6D9C1DD496E4276 (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MTW9W09E.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\pid[1] (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\stats[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\password[1].png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\bg_tile[1].gif (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\collapse_thead[1].gif (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\vbulletin_md5[1].js (213 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\vbulletin_important[1].css (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\final_banner[1].gif (11008 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6QLB5TNV.txt (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\GX1OvJc[1].gif (23453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4C7C.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 (2720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\whos_online[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\sa1[1].jpg (6204 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\w3cxhtml[1].gif (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 (1413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar362D.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\collapse_tcat[1].gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\banner[1].gif (6031 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\head2[1].gif (1160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\forum_new[1].gif (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\facebook[1].png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\clear[1].gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\NVJHO8PL.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\crckbanner[1].gif (183280 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_C7E630361CE489407CC0114009311154 (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\nav_bg_small[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\username[1].png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\nav[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\head4[1].gif (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\icon1[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\small[1].gif (81464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab6196.tmp (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4C8F.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LISK6Z0Y.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\nav_final[1].gif (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BC3EBA4E46329F29E449DFA191208FBF_BD64D75B80DFC94E25718464FE4C47FB (3318 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1BB09BEEC155258835C193A7AA85AA5B_F9E222772213E8AB26AD25ACDA31AFAB (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LMR7UUH6.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gdtmvRl[1].gif (8442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7B59DAYM.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\icon7[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\icon2[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\yahoo-dom-event[1].js (21224 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0060A9F9287878B15AB61E0E47645E5 (644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\QWRKLHO6.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9E4BE0042965AB3D0DE015F847D8AB90_03E448FF6BD55C02A6D9C1DD496E4276 (3346 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_727F58DC786B1E896AAB69F069684AB9 (279 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\OD4_KEVB[1].gif (92577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\vbulletin_global[1].js (11653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CFERAQO9.txt (120 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\ACF244F1A10D4DBED0D88EBA0C43A9B5_BA1AB6C2BDFDF57799E8116E4002D001 (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\mff_NTNk[1].gif (5740 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\74F831100DEB0B8799203064F3E38B68 (966 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\L3Zd0Sx[1].gif (10308 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\forum_old[1].gif (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\tcat_left[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BC3EBA4E46329F29E449DFA191208FBF_BD64D75B80DFC94E25718464FE4C47FB (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab362C.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F (3948 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_D004E5083B392DC7F7C7D16A878C03CA (279 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\gradient_thead[1].gif (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\twitter[1].png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5457A8CE4B2A7499F8299A013B6E1C7C_CE50F893881D43DC0C815E4D80FAF2B4 (2674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\icon4[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\subforum_old[1].gif (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\gradient_tcat[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5457A8CE4B2A7499F8299A013B6E1C7C_CE50F893881D43DC0C815E4D80FAF2B4 (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\vbulletin_menu[1].js (6412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\a[1].js (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_C7E630361CE489407CC0114009311154 (279 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\s[1].gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\head3[1].gif (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0060A9F9287878B15AB61E0E47645E5 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\source[1].gif (289438 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220 (1454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab61A7.tmp (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 (4048 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\X4DZBFM2.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4C7D.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\altenen_com[1].htm (758 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_7DC3E633EDFAEFC3AA3C99552548EC2F (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\max_banner_big_900_120[1].gif (29968 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\US26EDXK.txt (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_D004E5083B392DC7F7C7D16A878C03CA (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\ACF244F1A10D4DBED0D88EBA0C43A9B5_BA1AB6C2BDFDF57799E8116E4002D001 (13664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\leaksbannerov[1].gif (163316 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\connection-min[1].js (6176 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_7DC3E633EDFAEFC3AA3C99552548EC2F (1888 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\74F831100DEB0B8799203064F3E38B68 (746 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\larme[1].jpg (1887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L8Z4GR9W.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZU3OSJ64.txt (246 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\lastpost[1].gif (239 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar6197.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017020820170209\index.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\navbits_start[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JCZ65HM1.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head1[1].gif (1160 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F (936 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\altenen_com[1].htm (15684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\900[1].gif (47928 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C1F94CD5CA263ECFB1A4BAB1B832C909 (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JN31I3JO.txt (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220 (2688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4C8E.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar61A8.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_727F58DC786B1E896AAB69F069684AB9 (708 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C1F94CD5CA263ECFB1A4BAB1B832C909 (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1BB09BEEC155258835C193A7AA85AA5B_F9E222772213E8AB26AD25ACDA31AFAB (1112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZMECC7Y2.txt (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7Z4LLQJ1.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\Big_banner[1].gif (75764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\51[1].gif (3 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\US26EDXK.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\NVJHO8PL.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab362C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7B59DAYM.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016101020161017 (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4C8F.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LISK6Z0Y.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MTW9W09E.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L8Z4GR9W.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar6197.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LMR7UUH6.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar362D.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016101020161017\index.dat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab61A7.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JCZ65HM1.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4C7C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\QWRKLHO6.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4C8E.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\X4DZBFM2.txt (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4C7D.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar61A8.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\altenen_com[1].htm (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab6196.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012016102820161029 (0 bytes)
Registry activity
The process %original file name%.exe:452 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\"
The process 00.exe:3400 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process .exe:3656 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\XtremeRAT]
"Mutex" = "C6fjs5R2Pz"
The process CARDGE~1.EXE:956 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"cFormatTags" = "2"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"EnableConsoleTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017020820170209]
"CacheOptions" = "11"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"aFormatTagCache" = "01 00 00 00 10 00 00 00 55 00 00 00 1E 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"EnableFileTracing" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017020820170209]
"CachePath" = "%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017020820170209"
"CacheRepair" = "0"
"CacheLimit" = "8192"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017020820170209]
"CachePrefix" = ":2017020820170209:"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"fdwSupport" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"EnableFileTracing" = "0"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3F 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 84 E6 08 DD"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASAPI32]
"ConsoleTracingMask" = "4294901760"
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm]
"cFilterTags" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\CARDGE~1_RASMANCS]
"ConsoleTracingMask" = "4294901760"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following registry key(s):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016101020161017]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012016102820161029]
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F"
Dropped PE files
| MD5 | File path |
|---|---|
| 54a47f6b5e09a77e61649109c6a08866 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe |
| 8f50bbb29eb9f40c7aca521f672fabc7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\00.exe |
| ef87d6b587f71d7c2b865fbb27e97fcd | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\CARDGE~1.EXE |
| 8f50bbb29eb9f40c7aca521f672fabc7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\LoMkjwQ.exe |
| 54a47f6b5e09a77e61649109c6a08866 | c:\Windows\System32\InstallDir\svchost.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.
VersionInfo
Company Name: Microsoft Corporation
Product Name: Internet Explorer
Product Version: 11.00.9600.16428
Legal Copyright: (c) Microsoft Corporation. All rights reserved.
Legal Trademarks:
Original Filename: WEXTRACT.EXE .MUI
Internal Name: Wextract
File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 26060 | 26112 | 4.42567 | e9bf1a1e456a9a811b1b86e6602e3636 |
| .data | 32768 | 6796 | 1024 | 2.20139 | 317f8a934ee443eee01c2a315bde9ca1 |
| .idata | 40960 | 4216 | 4608 | 3.49941 | d8675ba112ef922c6057a02546757a1a |
| .rsrc | 49152 | 1053159 | 1053184 | 5.04358 | efb141115de994ecce2daa6a6c6c7a9b |
| .reloc | 1105920 | 5038 | 5120 | 2.58043 | 83de2f9b2c95be6fea06bced7e8a058e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://www.altenen.com/ | |
| hxxp://www.altenen.com/banhammer/pid | |
| hxxp://www.altenen.com/clientscript/vbulletin_global.js?v=389 | |
| hxxp://www.altenen.com/clientscript/yui/connection/connection-min.js?v=389 | |
| hxxp://www.altenen.com/clientscript/vbulletin_important.css?v=389 | |
| hxxp://www.altenen.com/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=389 | |
| hxxp://www.altenen.com/clientscript/vbulletin_menu.js?v=389 | |
| hxxp://leakswith.pro/bannerov/leaksbannerov.gif | |
| hxxp://paysell.bz/Big_banner.gif | |
| hxxp://vipcvv.net/images/banner.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/close.gif | |
| hxxp://www.altenen.com/clientscript/vbulletin_md5.js?v=389 | |
| hxxp://www.altenen.com/images/smilies/51.gif | |
| hxxp://www.altenen.com/images/head1.gif | |
| hxxp://www.altenen.com/images/head2.gif | |
| hxxp://www.altenen.com/images/head3.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/nav_final.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/navbits_start.gif | |
| hxxp://www.altenen.com/images/head4.gif | |
| hxxp://www.altenen.com/images/bluefox/buttons/collapse_tcat.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/tcat_left.gif | |
| hxxp://www.altenen.com/images/bluefox/statusicon/forum_old.gif | |
| hxxp://xslt.alexa.com/site_stats/js/t/a?url=altenen.com | |
| hxxp://www.altenen.com/images/icons/icon2.gif | |
| hxxp://www.altenen.com/images/bluefox/buttons/lastpost.gif | |
| hxxp://www.altenen.com/images/icons/icon1.gif | |
| hxxp://www.altenen.com/images/bluefox/statusicon/subforum_old.gif | |
| hxxp://www.altenen.com/images/bluefox/statusicon/forum_new.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/w3cxhtml.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/w3ccss.gif | |
| hxxp://www.altenen.com/jpg/twitter.png | |
| hxxp://www.altenen.com/jpg/L3Zd0Sx.gif | |
| hxxp://www.altenen.com/images/icons/icon7.gif | |
| hxxp://www.altenen.com/clear.gif | |
| hxxp://www.altenen.com/images/icons/icon4.gif | |
| hxxp://www.altenen.com/images/misc/password.png | |
| hxxp://www.altenen.com/jpg/gdtmvRl.gif | |
| hxxp://www.altenen.com/jpg/GX1OvJc.gif | |
| hxxp://www.altenen.com/jpg/facebook.png | |
| hxxp://www.altenen.com/jpg/sa1.jpg | |
| hxxp://www.altenen.com/images/misc/username.png | |
| hxxp://www.altenen.com/images/bluefox/buttons/collapse_thead.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/whos_online.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/stats.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/bg_tile.gif | |
| hxxp://www.altenen.com/anger1/head4.gif | |
| hxxp://www.altenen.com/danger1/head4.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/nav_bg_small.gif | |
| hxxp://www.altenen.com/images/bluefox/misc/nav.gif | |
| hxxp://www.altenen.com/jpg/larme.jpg | |
| hxxp://www.altenen.com/images/bluefox/gradients/gradient_tcat.gif | |
| hxxp://www.altenen.com/images/bluefox/gradients/gradient_thead.gif | |
| hxxp://xsltcache.alexa.com/site_stats/gif/t/a/YWx0ZW5lbi5jb20=/s.gif | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj/6qJAfE5/j9OXBRE4= | |
| hxxp://cdn.globalsigncdn.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx | |
| hxxp://cdn.globalsigncdn.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCDkbwjNvPLFRm7zMB3V80 | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI= | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrJdiQ/icg9B19asFe73bPYs+reAQUdXGnGUgZvJ2d6kFH35TESHeZ03kCEFslzmkHxCZVZtM5DJmpVK0= | |
| hxxp://a692.d.akamai.net/certs/ca.crt | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69+Aj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc= | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEHQcVg+I29Zftz+dMPk8jMI= | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEEodSUVLAF4g9EGIz+A1XoU= | |
| hxxp://c-0001.c-msedge.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab | |
| hxxp://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEQDKocXPk7YxqrHoH1imS68J | |
| hxxp://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR64T7ooMQqLLQoy+emBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEEr1tl+/qet2RM6TJ0qOsO0= | |
| hxxp://crl.comodoca4.com/COMODOECCDomainValidationSecureServerCA2.crl | |
| hxxp://crl.comodoca.com.cdn.cloudflare.net/COMODORSADomainValidationSecureServerCA.crl | |
| hxxp://a36.d.akamai.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICEGpdw+U7Tk/Qe2kepfzsZGs= | |
| hxxp://a36.d.akamai.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FOAcSwv/jIZ5NEnOcz+q2TDK8CECCIbc7NSRKoi/mPAmncjMg= | |
| hxxp://gpla1.wac.v2cdn.net/CRL/Omniroot2025.crl | |
| hxxp://e8218.dscb1.akamaiedge.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= | |
| hxxp://ocsp.comodoca4.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEEodSUVLAF4g9EGIz+A1XoU= | |
| hxxp://aia.startssl.com/certs/ca.crt | |
| hxxp://crl.comodoca.com/COMODORSADomainValidationSecureServerCA.crl | |
| hxxp://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx | |
| hxxp://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI= | |
| hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | |
| hxxp://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCDkbwjNvPLFRm7zMB3V80 | |
| hxxp://ocsp.comodoca4.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEHQcVg+I29Zftz+dMPk8jMI= | |
| hxxp://ocsp.startssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FOAcSwv/jIZ5NEnOcz+q2TDK8CECCIbc7NSRKoi/mPAmncjMg= | |
| hxxp://ocsp.comodoca4.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEQDKocXPk7YxqrHoH1imS68J | |
| hxxp://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= | |
| hxxp://ocsp.comodoca4.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrJdiQ/icg9B19asFe73bPYs+reAQUdXGnGUgZvJ2d6kFH35TESHeZ03kCEFslzmkHxCZVZtM5DJmpVK0= | |
| hxxp://ocsp.trust-provider.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj/6qJAfE5/j9OXBRE4= | |
| hxxp://ocsp.startssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICEGpdw+U7Tk/Qe2kepfzsZGs= | |
| hxxp://cdp1.public-trust.com/CRL/Omniroot2025.crl | |
| donald-trump.party | |
| bitxh.com | |
| s29.postimg.org | |
| i.imgbox.com | |
| s11.postimg.org | |
| media.giphy.com | |
| redspider.cc | |
| ah-antihacker.ddns.net | |
| s24.postimg.org | |
| sync.1dmp.io | |
| s23.postimg.org | |
| s28.postimg.org | |
| s30.postimg.org |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69+Aj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:50 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 4FB46E45ED28C524B079B1AA9BD05CAB42CF29A0
Cache-Control: max-age=530032,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 727
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0........~.=...<....8...22...2017
0207123043Z0s0q0I0... ........^..hl\.....W....r.=.....~.=...<....8.
..22... .n..u6l..n..|......20170207123043Z....20170214123043Z0...*.H..
...........@...H.#..?P.T......U.. X..\?=.z...GlwH.lVD.y..uq.T..?27....
i............2..#H% ..$1.........t!?-..c...aV #=h0...b2N...bL.i_...b.8
..8KQ...HD.$@&.v.8k.'M.g|.b....E .Z.*:.!..NQs.....2...K........M......
~........`....i@Xg...]..<.M.n.4I........aO[.et...K=....7...2.\...KE
x3 `..].i.:T(..8...u.r..F..0-K.s<Y1...g!.`./K.8..`.X..>.Dx.....@
...n}.9......E*y .....I.!.).UK........I.-.U...-.C.m.....F..A..9..-..wY
_.d9.b..Y.......z}.%x.L"TT-~B.....IO.-r*>t.....<V...........X._.
..0..'..b2/F.....y...]d. ..V.]...r.....i.._...S...
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEEodSUVLAF4g9EGIz+A1XoU= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca4.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:55 GMT
Server: Apache
Last-Modified: Mon, 06 Feb 2017 09:21:57 GMT
Expires: Mon, 13 Feb 2017 09:21:57 GMT
ETag: 1A0C51257C1A74DA15BF91A8CAAF5B85BD0BD9CF
Cache-Control: max-age=432301,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 279
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0.....0..0......@.ag...qO...,o.. v=...201702060
92157Z0s0q0I0... ..........3.....>v..1.9S......@.ag...qO...,o.. v=.
..J.IEK.^ .A...5^.....20170206092157Z....20170213092157Z0...*.H.=....H
.0E.!....p..(.3.k.L.@.I_F.......v^..~.. (/...@..P....#u.m.D...g.....Z.
.V..
GET /Big_banner.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: paysell.bz
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:37 GMT
Content-Type: image/gif
Content-Length: 1439404
Connection: keep-alive
Set-Cookie: __cfduid=d6b9d0e649fa3dde7f2e43d0d5d97d4cb1486544797; expires=Thu, 08-Feb-18 09:06:37 GMT; path=/; domain=.paysell.bz; HttpOnly
Last-Modified: Tue, 31 Jan 2017 12:42:39 GMT
ETag: "541117-15f6ac-5476344792a8c"
CF-Cache-Status: HIT
Expires: Wed, 08 Feb 2017 13:06:37 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: cloudflare-nginx
CF-RAY: 32dded39b4e55a0e-VIEGIF89a..x......V..#pp..(3m.6*.."....%.....`...O....%....o.l...""...M..
..uP....".#...V#....Pm...........Odqu......Rf.q'f...Lf....WT....3Gp..m
..."..h...T.w.T.."t.......i..Vl$l...2H$..........u..%...q...Uz"......s
..DO.O.r.....O......jkg....'....kw.3E)F/P T...gr..)$FS..RS.......(.DZ
P....ig..H&R......1Sc#...w&(mq.s.a_.....I1..gJ..P...o%....w........BW.
G.n$..U...2..U....$..#.....K....v..$U..|K...N....}.."....|Q9lNQ..H....
.x.....3....."....."..3..f..h~...."..3.....".....3.......m...3........
4.."..3..3..3.."..U..D.."..".......""..".....U...."".....3.."....."..V
.."....!3.."....""..".."....""....7...U..D.."...."3....."..D..D.....".
...5"..3..D.....V..".."..3..3.."....".."..:D..3..D..D..3.....U..f..3..
..;............3....4..73..3.....8.......;:..>....8V..."!...3......
..............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="...
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:m
eta/" x:xmptk="Adobe XMP Core 5.6-c132 79.159284, 2016/04/19-13:13:40
"> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-s
yntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns
:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorToo
l="Adobe Photoshop CC 2015.5 (Windows)" xmpMM:InstanceID="xmp.iid:961A
15C7E73B11E6AB398C80DC03CC4C" xmpMM:DocumentID="xmp.did:961A15C8E73B11
E6AB398C80DC03CC4C"> <xmpMM:DerivedFrom stRef:instanceID="xmp.ii
d:961A15C5E73B11E6AB398C80DC03CC4C" stRef:documentID="xmp.did:961A<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69+Aj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:50 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 4FB46E45ED28C524B079B1AA9BD05CAB42CF29A0
Cache-Control: max-age=530032,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 727
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0........~.=...<....8...22...2017
0207123043Z0s0q0I0... ........^..hl\.....W....r.=.....~.=...<....8.
..22... .n..u6l..n..|......20170207123043Z....20170214123043Z0...*.H..
...........@...H.#..?P.T......U.. X..\?=.z...GlwH.lVD.y..uq.T..?27....
i............2..#H% ..$1.........t!?-..c...aV #=h0...b2N...bL.i_...b.8
..8KQ...HD.$@&.v.8k.'M.g|.b....E .Z.*:.!..NQs.....2...K........M......
~........`....i@Xg...]..<.M.n.4I........aO[.et...K=....7...2.\...KE
x3 `..].i.:T(..8...u.r..F..0-K.s<Y1...g!.`./K.8..`.X..>.Dx.....@
...n}.9......E*y .....I.!.).UK........I.-.U...-.C.m.....F..A..9..-..wY
_.d9.b..Y.......z}.%x.L"TT-~B.....IO.-r*>t.....<V...........X._.
..0..'..b2/F.....y...]d. ..V.]...r.....i.._...S...
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj/6qJAfE5/j9OXBRE4= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.trust-provider.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 5907E30F032C051F75CAAEB6ABD5F2B380B5ACAC
Cache-Control: max-age=530037,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0.........z4.&...&T....$.T...2017020
7123043Z0s0q0I0... ........|.fT...D.b&...e{.z.......z4.&...&T....$.T..
.CR.?..........DN....20170207123043Z....20170214123043Z0...*.H........
.......,.....y...{.J....<ox.*{.`rU....=.1.v]'..Tq.V.....O.2..!....s
..!#^..DGC..6.Xo..h...}...>..q...*Z..[[....^r%.1......p~.K...}..<
;.....H..X"Z..A..&.....x....&..O..uN....4"..l...i.W..? ~.....A?..]..ZX
.h.........7..$......tv.N&."_].b".....Qr...........'I.{..m@U..
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.usertrust.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 6F025C3022E0D67186FDB650BF8A81E7E712AAA2
Cache-Control: max-age=530037,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0.........z4.&...&T....$.T...2017020
7123043Z0s0q0I0... ........|.fT...D.b&...e{.z.......z4.&...&T....$.T..
.'f.V.I....p...."....20170207123043Z....20170214123043Z0...*.H........
.....2.]-..W.....0.?.zW....j...)hM ..q.......z..6.....1..|.z(..#Q..`..
"#<.V...A;W..D.\..Ud:OJr^.....juw.m..0T.."..v.(...6....(..S.p|....l
......^.Nw..<[..@...r...V...5. .7.....Lz{'..0.B.Z...r.j...\'y.z-.'q
... ..r.f)l.'dH.5..1S...k).}d).....\.. ...F9...@.."$......
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSpuCE3aK3GivZPzGQJ6L5BRyZofwQUl9BrqCZwyKE/lB8ILcQ1m6ShHvICEAKQll6RM0DNpmNM7zH3/Qc= HTTP/1.1
Cache-Control: max-age = 547348
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Tue, 19 Nov 2013 21:12:41 GMT
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.verisign.com
HTTP/1.1 200 OK
Server: nginx/1.10.2
Content-Type: application/ocsp-response
Content-Length: 1664
content-transfer-encoding: binary
Cache-Control: max-age=457186, public, no-transform, must-revalidate
Last-Modified: Mon, 6 Feb 2017 16:02:36 GMT
Expires: Mon, 13 Feb 2017 16:02:36 GMT
Date: Wed, 08 Feb 2017 09:07:25 GMT
Connection: keep-alive0..|......u0..q.. .....0.....b0..^0.............V.m......E!....2017020
6160236Z0s0q0I0... ..........!7h....O.d...AG&h.....k.&p..?...-.5......
....^.3@..cL.1.......20170206160236Z....20170213160236Z0...*.H........
........".n.3.....W....,.ZW...eO......T..;......D.#J....N ..H..)V...r-
.,.........q.......:..g....9*.YS.;#...c..$}......G..Z[.u.:IH..H.F.....
.N.....W....8c..J.5...HZ....*..z....,Km.i......K.w...q......=.........
.~..`...RN.S.</_......}...c...E........:........L......0...0...0...
...............[Df..{.,0...*.H........0..1.0...U....US1.0...U....VeriS
ign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at h
ttps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Sign
ing 2009-2 CA0...161213000000Z..211231235959Z0F1D0B..U...;Symantec Cla
ss 3 Code Signing 2009-2 CA SHA1 OCSP Responder0.."0...*.H............
.0.............2q..J..:...3....X.?.....9K.G....,......e.c,..9YI...z.qA
0....9...CG......6.qX>.Xo.....g..=..B.E.......qB..W.|..>.qT.4Z|
....H. m...m..qy]Gi...0N.T.....N,.U.WJ5.f...r..@..8.b.......=..G.0....
.y4N"mK.J...."..".......ju.....k...x........P.]S=t....*..'............
.0...0...U.......0.0f..U. ._0]0[..`.H...E....0L0#.. .........hXXps://d
.symcb.com/cps0%.. .......0...hXXps://d.symcb.com/rpa0...U.%..0... ...
....0...U...........0... .....0......0"..U....0...0.1.0...U....TGV-OFF
-640...U.............V.m......E!..0...U.#..0.....k.&p..?...-.5.....0..
.*.H.............C.....S>F ..u.=KA5..@...`........a0s.M......JH.X.Y
..E........CX../......f5j..a......k...:.r/.J5..G...h...~.".A.]...2<<< skipped >>>
GET /site_stats/js/t/a?url=altenen.com HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: xslt.alexa.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: application/x-javascript
Content-Length: 3153
Connection: keep-alive
Date: Thu, 22 Sep 2016 19:33:14 GMT
Last-Modified: Sat, 11 Dec 2010 00:35:34 GMT
ETag: "f4022b30d2ad8a3755b6e53f31c63252"
x-amz-meta-s3fox-filesize: 3153
x-amz-meta-s3fox-modifiedtime: 1291757166000
Accept-Ranges: bytes
Server: AmazonS3
Age: 41944
X-Cache: Hit from cloudfront
Via: 1.1 300b920cc4a53d2daec2ba8180596d82.cloudfront.net (CloudFront)
X-Amz-Cf-Id: 1ESSUN8RCQlNF9l-KSsLDtiVYhtSQbek5CrHZ-ycXoYoCFIteNBzxQ==function AlexaSiteStatsWidget(){. var keyStr = "ABCDEFGHIJKLMNOPQRS
TUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 /=";. var jsUrlRegex =
/http:\/\/xslt.alexa.com\/site_stats\/js\/(.)\/(.).*(?:[\?&]|&)url
=([^\?&]*)/i;. var jsAmznIdRegex = /http:\/\/xslt.alexa.com\/site_s
tats\/js\/.*[\?&]amzn_id=([^\?&]*)/i;. var imageSrcPrefix = "http:/
/xsltcache.alexa.com/site_stats/gif/";. var detailURLPrefix = "http
://VVV.alexa.com/data/details/main";.. this.replaceScripts = functi
on replaceScripts(){. var scriptElements = document.getElements
ByTagName("script");. var thisScript = scriptElements[scriptEle
ments.length - 1];. var scriptSource = thisScript.src;.
if(scriptSource != null){. var urlMatched = scriptSource.ma
tch(jsUrlRegex);. var decodedURL = decodeURIComponent(urlMa
tched[3]);. if(urlMatched != null){. var ass
ociatedMatched = output = "";. var chr1, chr2, chr3;. var
enc1, enc2, enc3, enc4;. var i = 0;.. do {. chr1
= input.charCodeAt(i );. chr2 = input.charCodeAt(i );.
chr3 = input.charCodeAt(i );.. enc1 = chr1 >> 2;
. enc2 = ((chr1 & 3) << 4) | (chr2 >> 4);.
enc3 = ((chr2 & 15) << 2) | (chr3 >> 6);. enc4
= chr3 & 63;.. if (isNaN(chr2)) {. enc3 = enc4 =
64;. } else if (isNaN(chr3)) {. enc4 = 64;.
}.. output = output keyStr.charAt(enc1) keyStr.c<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrJdiQ/icg9B19asFe73bPYs+reAQUdXGnGUgZvJ2d6kFH35TESHeZ03kCEFslzmkHxCZVZtM5DJmpVK0= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca4.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:50 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: CD4E411028F5966AE35940E7A80D2D957332E76F
Cache-Control: max-age=530032,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 312
Connection: close
Content-Type: application/ocsp-response0..4......-0..).. .....0......0...0......uq..H.....AG...Hw..y..2017020
7123043Z0s0q0I0... .........%...' ..}j.^.v.b..x..uq..H.....AG...Hw..y.
.[%.i..&Uf.9...T.....20170207123043Z....20170214123043Z0...*.H.=....g.
0d.0...`..,3l.s.zT.M...h..&.F........C^..jdu..e..\.G.0H.dD$nk..Z.E.!.b
.!.O.2.Y.<......]8M.c.{r.d..-.....
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj/6qJAfE5/j9OXBRE4= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.trust-provider.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 5907E30F032C051F75CAAEB6ABD5F2B380B5ACAC
Cache-Control: max-age=530038,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0.........z4.&...&T....$.T...2017020
7123043Z0s0q0I0... ........|.fT...D.b&...e{.z.......z4.&...&T....$.T..
.CR.?..........DN....20170207123043Z....20170214123043Z0...*.H........
.......,.....y...{.J....<ox.*{.`rU....=.1.v]'..Tq.V.....O.2..!....s
..!#^..DGC..6.Xo..h...}...>..q...*Z..[[....^r%.1......p~.K...}..<
;.....H..X"Z..A..&.....x....&..O..uN....4"..l...i.W..? ~.....A?..]..ZX
.h.........7..$......tv.N&."_].b".....Qr...........'I.{..m@U..
GET /clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-8f14"
Content-Encoding: gzip3265.............}k[...... 0{.^2..3.J..'\.......|"D...7A....~....N....
..k.$}.....[_......q9.......L......z..t...M...=..(.O.\..=...T....7t'.;
J=MF.,5.wS.N)U............}v..Gw.[".....-..=Y=7_..zvg.7..S.s....z...w.
./...m.gW[-..l....#c...Ds...d...z....yp.Gg.....p.`3........;....'O.1 .
. Y..Y.....G;7v'w.{.....sU...........co.1r.i.95E..<S......f....}...
.@.x.A...~a0..w........:s.O.I.l.Z........lV.h.D..o........;wf....t.k.
...dU.......u....M..;.....=..YI.W.......t.4v}.Z.U.. b.;..=0W....H.....
<y..>...8.[U^.."V....u.51..L..U...6<.*...T.W.T?....g......Lxp
.Iq..>/k.|...#..L.....a.r...N.......y.^...............LA3)A....3.9.
.0M@m.2...@..). OD....}!I..Q0.....^...-......E....>......;.:..o..Wo
.....o..i.8..R...P.....y....t.{..`...b6.Cf...m.......@VsU.....z.9..|x.
......g...._.e..]..w...@.t.........w..Sg...,..jP......D..A..9pZ...W.iB
{{.w.9.....FK..hz.....Nb-.....A....l!..W>4..M..M,.PR.o......y..F.V.
.3Ti.]..lt.D.9#.}...W...9O.....D..&...."0..L.|..D.....1....1..1......I
R.......B.i.f.s].]...[..".eZ ...$.X..gO....s.]. . .8/.....f.:_...\...
......K......d2.I_...#n..7...y......`.0.H..T..(-.8...H...}c>..g....
.......1.DW.O..A..@Z.9U)...\B....ze._.N..3I.&...e..Q..:..?.V..5A.%....
..B.7..{..P)#........{...YB.L%... ....).B...i..R[.<......!......W).
x.w] ...#o.......y.....`..;a..^ ....e...^A.>.;.2..y..2 ...<6....
.^'dE...1.u^..W..`.iH.C.5.*;'`......l.-5q.....t..U....8b)....... ..Xu.
.............s..3sS.d8~....Z....H_*V5...$|...t.I.f....A...4...H...'..C
2Ot0....Z.._..[...-S.b..(.....{.o}..g.o.K.D`...I.)..*.H....2Z..<<<< skipped >>>
GET /images/smilies/51.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 3066
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:14:06 GMT
ETag: "56fd148e-bfa"
Accept-Ranges: bytesGIF89a*........... mU.@4.$$$.............. ...eP.........y............
.......q.ye<ue8.....}.........aaa.i.q]0iL.]H.....................a.
......u.............000mL..............}.......qqq.....e....}.......!.
.NETSCAPE2.0.....!..Built with GIF Movie Gear 4.0.!.!Design by Aiwan (
aiwan@yandex.ru).!...d.>.,....*......@.pH,....r.l:...tJ}.....@.*..0
..=..hl..N..k.{......~....uUmti.pQ..cS..^............ .k.8*.........,.
k........5.............e.3........)4.k.......%..e'..$.....$...1'k.(...
.......)..(.q/.D(h...)..".X."....<@..@...%(x.......@.`.!... ...H...
..B.......8s:...!.....>.,.............p8< .H.b.d..N.0q....!...F.
>.,..............@.....P.D2...2.T.4A.!.....>.,....*.....?@.pH,..
..r.l:...tJ.Z...v..z...xL...h. p^....`.&.}.5C.0..~>oi.\A.!.....>
.,...........@.pH$..C#.@l:}....|>....Z.z.\........:w......K`..x*1?.
:0.......... .\.8*.........,.\........5.M..>...........C.....3.....
..)4.............%..B....'..$....$...1'D.....(...........)..(.....x.@.
...*5P.!.......0.....$(P .B...>. ..E.. XD. .....)..`"...!.d0....L!A
..!.....>.,.... ......@.pH$....1Yl:..h.#.>...V.}..[fW..W.....Y.s
k..*...x$Q....aC....|>..u....C............. .E....B.8*.......,.....
...........5.M....>............C.3.......)4.cB........%...X'..$....
$...1'.].P`........ .."B....ay.@.....hh..B.....(...... H.........<.
.... XD. ....O.f....D..!B\.`...>B...!.....>.,...........@.p.....
..@l:..A p.,..g.....F....j..o.;...Ot..>..W.P>_..HxyDWRSuW2o...v.
..VdD|Hu...oe[...N...q....Z>...d..5....S..........FN.3........)<<< skipped >>>
GET /images/bluefox/misc/nav_final.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 652
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-28c"
Accept-Ranges: bytesGIF89a.."..T.5..9..B..C..N..O..R..S..V..W..Z..[..^.._..b..f..g..j..n..
r..s..v..w..z..{..~...................................................
......................................................................
................. .&&. .--.00.22.66.99.==.??.BB.FF.KK...............
......................................................................
...............................................,......".....CDFGLNQSBC
.K.SABEFJMPS@ACEHKOR=?A.I.;=>AEG.8:<..K578;.G23469<@D.01.79@*
,./.59$&) ,.4 !"#' -1... "%),....!......!....................nC....D..
.@..... @.....-N.......6r(..$....:.`a.....f. "...-?....B..%.(.@!...'.,
X.......L0:.....b...`@........;HTTP/1.1 200 OK..Server: nginx/1.11.5..
Date: Wed, 08 Feb 2017 09:10:52 GMT..Content-Type: image/gif..Content-
Length: 652..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012 0
6:41:12 GMT..ETag: "506e8108-28c"..Accept-Ranges: bytes..GIF89a.."..T.
5..9..B..C..N..O..R..S..V..W..Z..[..^.._..b..f..g..j..n..r..s..v..w..z
..{..~................................................................
......................................................................
.... .&&. .--.00.22.66.99.==.??.BB.FF.KK............................
......................................................................
..................................,......".....CDFGLNQSBC.K.SABEFJMPS@
ACEHKOR=?A.I.;=>AEG.8:<..K578;.G23469<@D.01.79@*,./.59$&) ,.4
!"#' -1... "%),....!......!....................nC....D...@..... @....
.-N.......6r(..$....:.`a.....f. "...-?....B..%.(.@!...'.,X.......L<<< skipped >>>
GET /images/bluefox/misc/tcat_left.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 1034
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-40a"
Accept-Ranges: bytesGIF89a........CD.*»B.*&.BB.($.AC.AC.;:.,(.)%PPP.-)444.78.79QQQ.-*.BD
....*&....@B.AB'''.AB.78.//.,)..,.,'. &~)$.....-. '.?@~ $.>>.68.
-,.@B.:9.-'.:9.. .BB....,'.-,.BB....- ....67.CC..........AB....--....,
(..........*%.BC.......CD.......>?..,.-,.AB....>?.>?.86.@A...
.=>. &.- ....?@.BD..,.. .-(....BC..-.@A.,&..... .@A~)#yyyccc.21~~~.
97.31...===..../-..,....==.BD. &.@@.......??.BC.......75....=>....:
8.20.@B.01..*.......?@.AA....CDZZZfff.,(....64.?A....AA..,nnn./.. &&&&
......vvv....53.?A.0/..........BC.BC.......*$.........................
......................................................................
......................................................................
......................................................................
................................,...............0p......\H.....#:.....
.. \.xqc.. *..I..I.?.5Xy...'{.@XI.....0\.0#...].hj..(..)...1..SR..PZ..
.....M.:... B....u.....UX....>8.uI.v.?.c . %... vr<..o..........
`.[. .t.P.?......-. A.D...M .M.:-......f..A;...k8I...Q.......;...,..B.
..........;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Wed, 08 Feb 20
17 09:10:53 GMT..Content-Type: image/gif..Content-Length: 1034..Connec
tion: keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT..ETag:
"506e8108-40a"..Accept-Ranges: bytes..GIF89a........CD.*»B.*&.BB.($.
AC.AC.;:.,(.)%PPP.-)444.78.79QQQ.-*.BD....*&....@B.AB'''.AB.78.//.,)..
,.,'. &~)$.....-. '.?@~ $.>>.68.-,.@B.:9.-'.:9.. .BB....,'.-,.BB
....- ....67.CC..........AB....--....,(..........*%.BC.......CD...<<< skipped >>>
GET /images/bluefox/statusicon/subforum_old.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 348
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-15c"
Accept-Ranges: bytesGIF89a...........................................yyyxxxtttsssrrrqqqppp
ooommmllljjjiiihhhfffeeecccbbbaaa```___^^^]]]\\\[[[ZZZYYYXXXWWWVVVUUUT
TTQQQOOONNNMMMEEECCC???>>><<<;;;444000***(((........
.............!.....8.,..........y@.pH,.l0.R....4....r>.....D..p.A).
....R. ....%<Y&.C ..wVB&...{....8$$''.....*B"$%%....%S)B !R.R'..B/.
."..#..5C0!...'3F.CA.;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Wed
, 08 Feb 2017 09:10:53 GMT..Content-Type: image/gif..Content-Length: 3
48..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:10 G
MT..ETag: "506e8106-15c"..Accept-Ranges: bytes..GIF89a................
...........................yyyxxxtttsssrrrqqqpppooommmllljjjiiihhhfffe
eecccbbbaaa```___^^^]]]\\\[[[ZZZYYYXXXWWWVVVUUUTTTQQQOOONNNMMMEEECCC??
?>>><<<;;;444000***(((.....................!.....8.,
..........y@.pH,.l0.R....4....r>.....D..p.A).....R. ....%<Y&.C .
.wVB&...{....8$$''.....*B"$%%....%S)B !R.R'..B/.."..#..5C0!...'3F.CA.;
....
GET /images/bluefox/misc/w3ccss.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 177
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-b1"
Accept-Ranges: bytesGIF89aG...... ......:::!.......,....G................0.....f.E.X...(
..... ..9..N....pzD.(0..(..N.......j.jXKe.Iy..B.U...{.d..t^.h3]k.o../m
.w.vF.S&.v...U.(.."9....I.......iP..;HTTP/1.1 200 OK..Server: nginx/1.
11.5..Date: Wed, 08 Feb 2017 09:10:53 GMT..Content-Type: image/gif..Co
ntent-Length: 177..Connection: keep-alive..Last-Modified: Fri, 05 Oct
2012 06:41:12 GMT..ETag: "506e8108-b1"..Accept-Ranges: bytes..GIF89aG.
..... ......:::!.......,....G................0.....f.E.X...(..... ..
9..N....pzD.(0..(..N.......j.jXKe.Iy..B.U...{.d..t^.h3]k.o../m.w.vF.S&
.v...U.(.."9....I.......iP..;....
GET /images/icons/icon4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 1019
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-3fb"
Accept-Ranges: bytesGIF89a.........4..5..5..4..3|\...5..5}\...4..:..8..'..8..4..:..*.|$.}#
Z[d..7gX...8...........5..6..8..6jny..7_[a........7?5...7.j?^`k..7..:.
.8`]].p<.q;.u7..1NQX........6..9..$..$VA.........>..)\S@~\.llv..
7..%~^.K@.TK?bag..5or....1*......5..5..8}]...7.. ..7..6..9..:..8vc;..8
.t"..9..&..6..6..-........6..6...qq}..:...VK.2,.ZL...-.|D..8..........
p:..8..:.....8.....9z\...B....f }gBtbF...LB3..8|\...7..4YUV..(...cU4..
2YX^.r!........7......................................................
......................................................................
......................................................................
......................................................................
......................................................................
.................!.......,.................M.2..*L."........ ......P..
F...}\.!...;.@......,YL`$....=k8,.q....#..I... ..A..r E.3..P.1!!....(@
"D....Z...d...cH...$..#0...q`..9\.A. @....V`...../e*.. `../....0 .."."
.0. ..B7..xA......$......|..h...m.....Rg....;....
GET /jpg/GX1OvJc.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 302184
Connection: keep-alive
Last-Modified: Sat, 27 Aug 2016 06:07:26 GMT
ETag: "57c12e1e-49c68"
Accept-Ranges: bytesGIF89a..x.................K...fRu..YV.3J.........[..s......a,..I....rO
..U....)0.l................u.....Klr1Mi...P..l...EiVWX ARvvw......bdew
..K.............0...445.....o....J'....O6ACD.{.$%%..6......CWp[.uh..h.
....0'.RD.[.u.y.............V.....9i..n..........dT..........wi,.....-
S..V...EOl...!....sd.R..... ....Vy....o.u,6.......<..........T....-
.."57LF#*........$..............g.>...S..u........vpIQ.............
.x..cX).....Zp....s.....:0ajDg]..Q.3)...~HTM..'....)....cc...*{.l..s..
...FRW.......(::.]f.#.....:...e...lAEHV......D..4.OK.........4;kkm...,
..ew|c.....q...y....3Y|../.=3r.7a6.;4.xVl.....E....Ei..A.{.}zc........
......@......X{nWCS.............dp..... M..;#9.19a..8i_.\.1).\WA..!JJJ
;VO......................................................;......!!=|..
@....n...`.......!..NETSCAPE2.0.....!.......,......x........H......*\.
.....#J.H.....3j...... C..I....(S.......0c..I....8s.......@...J....H.*
].....P.J..T ..X.j......`...K..Y.V..].....p...K....v.............w....
. ^...c...K.L.....3........C..M.....S.^.:4...c..M..]..s.....o.....N..q
... _.......K.N..u...k...........O.5....._..<.....'.~.....#........
._...h`z......J.`..F(.n.Nh....Va..v..c.~(..$..b.(...Y'....0R.b.4.h.P3.
...<.w^.@.).M9.i..#....LN.d.PFY..RVi.}T^........`..e.d....f...ph...
......t.&g.x....z...c|.)....J....eh..6....F*.m.Vji.^^...rA......i.....
...........I.......J.................z.K..s....j*...a:...ZJK..QZ...Hj.
..Az...:.K..1....*....I....n.K.................b.K..K.....)....9....IL
...Y....i....y.....L...................L...................M......<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICEGpdw+U7Tk/Qe2kepfzsZGs= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.startssl.com
HTTP/1.1 200 OK
Server: nginx/1.7.2
Content-Type: application/ocsp-response
Content-Length: 1769
Content-Transfer-Encoding: Binary
Last-Modified: Tue, 07 Feb 2017 10:12:34 GMT
ETag: "658B432C180941E40F87FC9AA7A10F0CB27A092F"
Expires: Wed, 08 Feb 2017 09:07:01 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 08 Feb 2017 09:07:01 GMT
Connection: keep-alive0..........0..... .....0......0...0...I0G1.0...U....IL1.0...U....Start
Com Ltd.1 0...U....StartCom OCSP Responder..20170207101234Z0s0q0I0...
........As....j....k..b90pi5..N....@[..i.0.4hC.A....j]..;NO.{i....dk..
..20170207101234Z....20170211102234Z0...*.H....................I7._f..
....#..R*....b5..'..uZ........X%...."?A%.'.=.6..du."`m...<.B.'p....
...&!xW.|..j.........S.3.........HF..lVBwv.b..Cv..e.P..4.......{.<.
..g.......^b.HU.N. .EL........~.........-H..B.N.......>W.#.....JKo.
:&..RE.M...j..no../|.(.?.R..a.../..f|...D....0...0...0..........t.P..M
7O.">F.v..0...*.H........0}1.0...U....IL1.0...U....StartCom Ltd.1 0
)..U..."Secure Digital Certificate Signing1)0'..U... StartCom Certific
ation Authority0...160920000101Z..170920000101Z0G1.0...U....IL1.0...U.
...StartCom Ltd.1 0...U....StartCom OCSP Responder0.."0...*.H.........
....0..........W.-..Z.\.....u..6.F~....~>IXqW..h)..{ .C..k.wL..e..{
.k.o........%...l\..=......b...,a....9..4.....6..'.h..ca[....[.>...
e.vdpm..)...e..-....6/.e...ay...T.c.}..a25...'A...x.S..<.#... ..xl.
...D....p..5........L.o. G!....Ld\.!..)o..GK..i.w...b.....p.S.r.......
......0..0...U........0...U.%..0... .......0...U.......0.0... .....0..
....0...U......_tY."....!\.n..&..*.0...U.#..0...N....@[..i.0.4hC.A..0.
..*.H.............-..x5i...H...$Y.....y....2r.!..W]T....z.5..w^...[.1.
...H`..N...|.3...(d<.8..4..l.*.@...:.GV...........=.n.... ...y.WK.x
..~1.%...j....d..../R..p<.mR...Ii.%....d.5.P.Z.s.... ..p.7.W_.9.*.T
......... ..l>M.=...w8.K~.).uU...n.Q.@^.cR.a...5X...]'.P.Yf...0<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FOAcSwv/jIZ5NEnOcz+q2TDK8CECCIbc7NSRKoi/mPAmncjMg= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.startssl.com
HTTP/1.1 200 OK
Server: nginx/1.7.2
Content-Type: application/ocsp-response
Content-Length: 1816
Content-Transfer-Encoding: Binary
Last-Modified: Tue, 07 Feb 2017 10:44:35 GMT
ETag: "3D1C5E12C715FC028EB11588AED61DB9C3424F92"
Expires: Wed, 08 Feb 2017 09:07:06 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 08 Feb 2017 09:07:06 GMT
Connection: keep-alive0..........0..... .....0......0...0......0..1.0...U....IL1.0...U....St
artCom Ltd.1)0'..U... StartCom Certification Authority1503..U...,Start
Com Class 1 DV Server CA OCSP Responder..20170207104435Z0s0q0I0... ...
.....Qh.....:U.`."....0=)....N......g.D..3....... .m..I......i.......2
0170207104435Z....20170211105435Z0...*.H...............g..^%-.q.......
2....).b*.....#..=.. .}'.@t..X.]....%....^.....|k.:/i.0......".ru.....
o..............I...r<.O.]...H..f.....I...%........y.`k.X...A ...I..
e.ZL....L.^2.F...!.c.I1o.Y.L...V.....#..o;.{GOQ<.o"...Y..f.y..S..k.
$c.."..E..U..^T....C........I]6.8d.....0...0...0..........T...._fA....
.v..0...*.H........0x1.0...U....IL1.0...U....StartCom Ltd.1)0'..U... S
tartCom Certification Authority1&0$..U....StartCom Class 1 DV Server C
A0...161210034431Z..170330034431Z0..1.0...U....IL1.0...U....StartCom L
td.1)0'..U... StartCom Certification Authority1503..U...,StartCom Clas
s 1 DV Server CA OCSP Responder0.."0...*.H.............0.........Y..J.
?V..F.r..,.:..{{o@.O....$bC...s7!..J.h..T...jY....V..c.\$.(q.{O..L..u.
X89U....{.K.?}..,(.S.>F<`].`...yJ.......2.v...&."><.f.....
..CK.....}.k.8...[....Rg.t..x...z....(..?..9xT..Z.\|}{........>....
.....a.2.G.'..h....!I.....:..<..h...5.H$.\.>PI.....JY..........3
0../0...U...........0...U.%..0... .......0... .....0......0...U.......
0.0...U......o...iOM...:...S....T0...U.#..0.....N......g.D..3.....0o..
........c0a0$.. .....0...hXXp://ocsp.startssl.com09.. .....0..-http:/
/aia.startssl.com/certs/sca.server1.crt08..U...10/0-. .).'hXXp://c<<< skipped >>>
GET / HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:51 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: BHC=; path=/; expires=Thu, 01 Jan 1970 00:00:01 GMT
X-FireWall-Protection: True
Content-Encoding: gzip1b1.............R...0... .:,...N),]Y)....tais(...{...%W..,%..Q.'..[.0.
...i..t..y.Q5.....k..U.........Z.c..,../........."...`.h...*.....?x..k
.G.u.Vu8...f.....hX.j....%N...D..6.#w1x.6........CGX^..J...2`R.nz.1...
...M.....\.P.......R0.v.x..P.).TGmy..)j...t...$p~..aX...t6.......T....
g.._.....0.(...f.........y.0w....!...V...h.O..5...c~NL)_.....<u.A.W
e9.... ...\.&..`..H..........<h.kI;....Iz.....KvI.^).U../z......g..
.%.*.)..}..]._.....d......0......
GET /banhammer/pid HTTP/1.1
Accept: */*
Accept-Language: en-us
Referer: hXXp://VVV.altenen.com/
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:51 GMT
Content-Type: application/octet-stream
Transfer-Encoding: chunked
Connection: keep-alive2c..Veomjaa39d3XO9CWJMFdLVAlIcQ=_146298751437...0......
GET / HTTP/1.1
Accept: image/jpeg, application/x-ms-application, image/gif, application/xaml xml, image/pjpeg, application/x-ms-xbap, */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: BHC=Veomjaa39d3XO9CWJMFdLVAlIcQ=_146298751437_
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: text/html; charset=ISO-8859-1
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: BHC=; path=/; expires=Thu, 01 Jan 1970 00:00:01 GMT
X-Powered-By: PHP/5.6.19
Set-Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; path=/; HttpOnly
Set-Cookie: bblastvisit=1486544796; expires=Thu, 08-Feb-2018 09:06:36 GMT; Max-Age=31536000; path=/
Set-Cookie: bblastactivity=0; expires=Thu, 08-Feb-2018 09:06:36 GMT; Max-Age=31536000; path=/
Cache-Control: private
Pragma: private
X-UA-Compatible: IE=7
Content-Encoding: gzip917...............w.V...N....Vf:........,..ek,'..;...$HB\...$.{.......
)^...i.......p..uk.V...z..../.O.a<.;.?>~.....;8..z|p.....o/...v.
.%.}.N#?...;>8x.f.............Uu?......\...|8.r/.}r...v.}........4:
.B..n....8=?<.....3v....o.........O{{.4p.nw.9C~.....g~7.b....=....y
.s......t.i.M...i.g>...l......zQ.#{e...2..c...8.......iO?n!.x../f^.
n.].........#/>|y.v.....Q~o.`.N....7.B7.X...\>...^.O..~k..L...}l
.-...._.w..B..u..Lv.ov..pw.vG..............^.u.^....,...;..f.*...`.A..
z.]7..N......p. ....dX.A.....3a..l...q......?.....<...E<........
.9L.gE...g3f.Q..{N.......F.0.W_~......../gAr..8n'....{...,.l..)...~...
..u.73.'....g.. ?...|.......|].._~w......V/.GY@....x......7...=....y.T
.....}.`..8.O.$?....M~.L.......Gqw.D.a.98.o.8pJN.r...3.8.N0...,$3w....
..;./..IV... .<vBo......>T:ap.y..yQ..}...7..0..s.T..^;A./o...K..
....Q.....z:.E..lt.w.1{t.........pr...'..|...8...".......{....c/....._
}.z.<.:....|.%ay~...<...v...O.;...c...w.]=.=.t..)...W...H7t9....
w.`.{....|.0.......u..:.qv...."...;.{.vg....kC.b.co:...#.dH.{p..L..}.k
o..F.}.%....t.......!.-.J....H8;...;..v~...| ......y:7....Q......iF.N.
...o.1.....ipl._..9R.6'j.....~........l?..y..Nr...pXfW.O....?^..}.....
....._.v.Cs....`8>pw6..?|=...0>..5...0....|Z..S~.|;u/......l&<
;....7^l.w.;'.....C?..W.....f...n.?^..d.....$...y.7>..o,.O....d..._
t...}...........pg.m.J...oYm..c..N...~.......w.G..qnX....lr.^.....7L..
.{..../;..............N..]H.c..2..D[...)-.....02...jJ.X.c.........D...
k.. a..............!.....G.%.\{//.Kg......oz.. ..*.*.a.._...W8.9..<<< skipped >>>
GET /clientscript/vbulletin_global.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-659e"
Content-Encoding: gzip1faa.............<kw.F.......F.2.O.`..$`fv..c'.=.p.j.2 .I....t.....
.-...&'c.~TWWW...u.........6......j...U.q.........S.g^x....V....}...Y.
.O[...i...2.E.Xga..V.]4m........./4.....9..y......-..Z.g...%4..,.'...5
.y;..E...p.........O.............|........em....]|.\........<.V....
....D..9.......E8.QJ..l.(@.E.:.......k..6......R .fs$...aB'..........?
.E.....Y.3b....o.]..s.'...$....SX......{.\..,.. ....x..%.?.`..#..%..kV
I.<R<a.Q.:N.D .[...!.\.h....FX...kp..F..:."....v.E.....w.>...
.md. ._.....m...z.F4 ..t.........../?...Q...WAQ.....j..)-`..R.....$...
..7. .q?..8..6..vO..?.qF.s?I.k..RV..g4.o..i..e..qBg.ne..._....2..dM;Eo
...oc/^..,....57!.].I6F..#.1.......l|....3..=..V...q........Si.e.,~...
....i..xE..6......I....o.....M._.Z....0S.@Avc..`0kz... ...G.q;o..*..C.
..u.H.$_`l.. .....2...N..q....c^.J_U".Z..i.#..^.._..).....X!..8......)
.p.b..)*.Os. .....P......_.." ..BMeh ......BJ.E.Q...Z.J..(a"e.2...IB.:
.U....O.I...`.rN.>.......^...fM.QY...y.ri....f.$.0...._1.0........N
.q2L....."cb...a-....2..O_}G..z...8>.NQ^.O.....o4.A..{*.{.....c>
..RL9.|.3.1D....=k. .7..k.[...y}......L........aU.HY .T<.e96.y..Y..
.~..zgn.k4.......^.=.....bF.v ..].l:...?.438..x.^"..h._P|t...9...CoN7.
..X.... g..........<.".Q|...S..Y...k3)..TtP>.X0W.N.._......*....
J..'Y...&....Ey...*.5f..ON.).Yn..o...hL...9.....9Bo......b-..V........
.)*[.Hj >...f..s....9.w..p.D(Y(.`D:...g..#.>.......X.&.2l>...
0..' `.-....^.~..7."....?M.T.....qm.P...~...........u.6...X..}.\..lL..
..pw.....0.l...s.$..@?e5.......F.......:r\4K..i6.. ..9..8..s0.`.U.<<< skipped >>>
GET /clientscript/vbulletin_menu.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-24d3"
Content-Encoding: gzipa58...............r.H.}......H.....4.@.... l....%....F..%.........SB.{
.......2.......Y~?|.f...}.....T.f..C.H...................,.L....~.....
.V.^.p.....6.|Ss.P....v.S.lp`...K.js.bm.m..2m....$e.....4@y...A.-%....
.EL.......8.e...7....6.....j.W..v..b..s5...p.X|vrr{{knf.^.OW..u.$$>
.Rl..*,Q=.^??...|S(.......1.m. ..........K.`...#.....~..:v/.(.q....4j.
.Gn.p...}.\.{...^.b....Mm.SI...jN.x[....M;...&a3N(.l.c..1.........X>
;X'X...E~3..L.... .Q..dd..B.^....$4.9.."&..it#.R`y.....x.6.?:.....1.9.
s.A.kp.?MA.d..:...I...)..>....A...i.....G. ...z.E'|..:P......~2e.S
....`.N"..}T.K.T$n.........1....Xt#..l.b.. ..b.3q7q....N.1!x0..O/.S...
.m...~A.}~.d.3.Fx/....[....48PW.cb.....=...Q......k.r..J........4..(.D
...M.....3.U*UY.......r$..0W...|...c./]:.7..^...... '. n).......{.q..V
3<(y. ....E.....X..Tl.!..X.C............Z`y..}..='I..K.....M.y.w.vl
4..6.4....Q..w.~."P..s...........;..O.n......k..3....S|..Qp.....y1h/..
.".50.C....0e@10.=Wl.Vf4. ......b.!x.B..rP.........rr...f....%n..NP..2
..NR..1%.DvW..!....vaCcnri..J`W.[.HV.b1......8.=`."p6../.6...%.Rb.R..&
lt;._...@>..E$..6..V.``.W...B.;..LUw..j....;...... U...............
..(.w._..Wa...t..<d....\{&....`Tb........x..8.....=.{>a[({....v.
..D....6:..eY=.....@....].W5..p\....P...WoP7.........q.`Kk...c..B v.5m
..P.../........?....tqc....*...Mc..*a..w:.3.F........:R....|......._.
...~U..fOC.f.....q.=..Rn.de...~....].....kD_.....E....C.....R....@9i.x
Q.0.P.%.e.....k...l..Q......"..C..&.....-........6>.@...@.L..n.....
\AY.kQ.S.[.!7.....N..o.......7.[..9...O...=9....(....{..)k._.p....<<< skipped >>>
GET /images/bluefox/misc/close.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 428
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-1ac"
Accept-Ranges: bytesGIF89a.....?.....j9......./..<..KJ.zI......zyy....],....PP.......S"
.6...S.mml]]hff.......N.....nn.SS..........,..D..M1....&.. ...........
E..>&.X&.;;.*".K..Q../..``....77..j...qdd.80....?..D.....J..mm.....
.!.....?.,..............f...?.K..!{...sD.V0. !..&"..B..$..G..L.$Y .r.,
....z3P...(...\?.,.... .....H#.*. )....NB>.". ..3..Is.......G?.....
<!!.%;M.....0.99..../.)%..0!.(1j.:. .... ...8.%.'.....6.....'..G..
..:,@.`....Fh.`.G..;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Wed,
08 Feb 2017 09:10:52 GMT..Content-Type: image/gif..Content-Length: 428
..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
..ETag: "506e8108-1ac"..Accept-Ranges: bytes..GIF89a.....?.....j9.....
../..<..KJ.zI......zyy....],....PP.......S".6...S.mml]]hff.......N.
....nn.SS..........,..D..M1....&.. ...........E..>&.X&.;;.*".K..Q..
/..``....77..j...qdd.80....?..D.....J..mm......!.....?.,..............
f...?.K..!{...sD.V0. !..&"..B..$..G..L.$Y .r.,....z3P...(...\?.,.... .
....H#.*. )....NB>.". ..3..Is.......G?.....<!!.%;M.....0.99..../
.)%..0!.(1j.:. .... ...8.%.'.....6.....'..G....:,@.`....Fh.`.G..;nt>....
GET /images/head2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 30760
Connection: keep-alive
Last-Modified: Mon, 29 Sep 2014 11:30:44 GMT
ETag: "542942e4-7828"
Accept-Ranges: bytesGIF89a"....................)..{..........dY....C;...vupw...........7..
f..F...#..JCV..'...........................pn....~w.......... %.ZS....
..*))....jd.zs. ..kd....|y.......sl....QK.un.'#.94....72..........HB..
.._V.............0*....3,....C=..../ .UO..............................
.......HGc))............. .gBA.`[. ..(/......................# .......
...............!....d.....|}{..................!..NETSCAPE2.0.....!..X
MP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:B65E0B12B647E411A
4ECB674E47D8C8B" xmpMM:DocumentID="xmp.did:E2D2E1FE47C211E4AE82A20A9E7
72400" xmpMM:InstanceID="xmp.iid:E2D2E1FD47C211E4AE82A20A9E772400" xmp
:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:B65E0B12B647E411A4ECB674E47D8C8B" stRef:doc
umentID="xmp.did:B65E0B12B647E411A4ECB674E47D8C8B"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....................................................................
..............................................................~}|{zyxw
vutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;<<< skipped >>>
GET /images/head4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 8085
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-1f95"
Accept-Ranges: bytesGIF89a0...............................................................
..................}..z..v..r..f..a..Z..M..J..E..A..=..9..2............
...........a..\.....e.....a..z..g..U..2....................y..`.. ....
......................~..u..p..l..Z.....U..F..B........N.....}..J..&..
#..G..6.."..%.....I.....R..N..>..:.....X.....2..O........P.....1..(
..#..!...........\..S..5..&..;........I.....*..B..!..............,....
......................................................................
......................................................................
..5.....!..D........)..#..... ..(..!.....0..#.. ..&..@..=.....N..Z..:.
.......3..9..B.....U.. ..(..%..#.. ...................................
......k..^..Q..5..R..I..?..|..)..D..... .. .....R..?.....-..).........
..............!.......,....0.............3Y.tu[UJ..p..y.'...F...;.*T%.
....X@....H.*.rQ..&.h.....T.dA..-..T........F.B.%..@IQPE.,...A4w..C..[
.n........q........]..j....].O.1...N.j\..../l8q.V.R....Z.T....2.=.4...
.i........O.W.f.r8...]......V.f.Z..7GNY...:...3..w.A.R,U.p....:..D_..i
...Z.l.^..Q#g..A...'...64..}.....n...jJN..Z.d..6..`.0.|3...x..E....q.,
b.{.4V...l..zLI..8..h.1..s....c.<.~C.].zB.K..r.>.u..7....,..S.*.
...6.....[<..5.tS.x3Ng.g..B@7....7..3K8j..\H...$..X..;..cM6....,...
.f.:E@"^.C 8.q#.,9!.....s.c.T.M7.......5.9.. .T..B.8....,.x.J,.....Q.
..#..5.8... "....~..c.#....5.... ...kY...R".D.."z.0.F.&RW...4.#...M..|
..=....D......(B.",9E.(w...]..,W"..s..b~.....Qo.ki4..S...(....\.."T8..
...Y.....Q,.'.@E.RJ......U.E....(.p#.3..#.6$rsf8...p..E...C.e....3<<< skipped >>>
GET /images/icons/icon2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 1058
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-422"
Accept-Ranges: bytesGIF89a.................................v...........~.....|...|.......u
....c*.O4.n9..u..J..j.`...............}.2'..v.....v.....].....X..z....
....\..]..C..R..e..g........S.....^..V..s.|?@.i@.f..p..g..`.....x.O8.!
..k)$.a....f'.bA..a .a...q...`.....v...5..~..m..].e0..w..z..o..~}....S
b...S&.....k..N..m.......d9........z........L.B/...........o..c..l.K..
............\ ..]..\p....g.....X..T..........?'...y......nH.....d.x@..
J.....6..2..b..F.{Z..n6u\...........g..W.A(.....h..\l.....n....r......
.uL.lC..A.^3.....l).fByZ.....l.j9....T...............>..4..........
....`..A..9..G....qA..................................................
......................................................................
......................................................................
..............!.......,............{....J...D.\....X.0.8.H.&.*.Q.B....
7J.!4...B..$)p.....(H.. ....NA!....?Oj.Z.'.)........ .L.X......ed.....
.#..`.....Jk...C ..4s.4*..A.U."..A@..=r.....U....p.....2]. 2a ..3.....
f.$/.:......8=.Tp........j....Y>.........=-qrb..K......a S...0.....
....ug. 5....;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Wed, 08 Feb
2017 09:10:53 GMT..Content-Type: image/gif..Content-Length: 1058..Con
nection: keep-alive..Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT..ETa
g: "56fd1393-422"..Accept-Ranges: bytes..GIF89a.......................
..........v...........~.....|...|.......u....c*.O4.n9..u..J..j.`......
.........}.2'..v.....v.....].....X..z........\..]..C..R..e..g........S
.....^..V..s.|?@.i@.f..p..g..`.....x.O8.!..k)$.a....f'.bA..a .a...<<< skipped >>>
GET /images/bluefox/statusicon/forum_new.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 21048
Connection: keep-alive
Last-Modified: Tue, 30 Sep 2014 08:10:28 GMT
ETag: "542a6574-5238"
Accept-Ranges: bytes.PNG........IHDR...3...!.....t.......pHYs................OiCCPPhotosho
p ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE.........
..Q,......!.........{.k........>...........H3Q5...B..........@..$p.
...d!s.#...~<< ".....x.....M..0.....B.\.....t.8K....@z.B..@F....
&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH..
...........0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(.I.
.6a.a.@..y..2.4..............x.....6..._-...."bb.....p@...t~..,/...;.
.m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<..
....$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..&
gt;.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..?..
..D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/.@.4.Qh..p...U..=p..
a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2...
.G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,..c.
."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.X
H,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!.[.
.b@q..S.(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i..t.
....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....J.&
..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.._.
.. .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....).).
.4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....Dw.
n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC].@C.a.a....
..<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2.......<<< skipped >>>
GET /jpg/L3Zd0Sx.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 150541
Connection: keep-alive
Last-Modified: Sat, 27 Aug 2016 06:07:30 GMT
ETag: "57c12e22-24c0d"
Accept-Ranges: bytesGIF89a..x......7....&......c.....................iE.40!...fW....HA1QI5
.di.....x...ulS..............k.........[S-.l.J1....efe.kG.....R...id3.
sAlU1.nD.........|}|.}H}U8..X..k...wd8skF.....8../..4..2.....6....u.#.
.e[E...3%....S8$..........._..m..!........7WI(XQ>.....g."....../.X;
..s...../..b.z^.......sK....u}......wg. ... .KB".D..% ...uK3.....g..!.
..........Y..L.)-.tZ.wXwq5..&...c....fmbM.....7..d..s..!.!%.....u..0z^
?....|U..-.|2..~0*...#..t.a@.....X....$.TH....@)........S\."!........&
..\.DG=4..<H.....i~tB.....)..d.&........!...o..........6=C.......s*
....|..L....zP..$......LC.................._.~I.#&.....u...rrri>,[:
(.DJ..).IQ.....$..j.ah....%........k<.......(-.......,$`8(..$...c?*
<:(....-4..... .................^....."........ ..q..............&.
..UN<........1............!..NETSCAPE2.0.....!.......,......x.....Q
..H......*\......#J.H.....3j...... C..I....(S.......0c..I....8s.......
@...J....H.*].....P.J..T ..X.j......`...K..Y.V..].....p...K....v......
.......w..... ^...c...K.L.....3........C..M.....S.^.:4...c..M..]..s...
..o.....N..q... _.......K.N..u...k...........O.5....._..<.....'.~..
...#........._...h`z......J.`..F(.n.Nh....Va..v..c.~(..$..b.(...Y'....
0R.b.4.h.P3....<.w^.@.).M9.i..#....LN.d.PFY..RVi.}T^........`..e.d.
...f...ph.........t.&g.x....z...c|.)....J....eh..6....F*.m.Vji.^^...rA
......i................I.......J.................z.K..s....j*...a:...Z
JK..QZ...Hj...Az...:.K..1....*....I....n.K.................b.K..K.....
)....9....IL...Y....i....y.....L...................L..............<<< skipped >>>
GET /jpg/facebook.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/png
Content-Length: 6642
Connection: keep-alive
Last-Modified: Sat, 04 Oct 2014 10:23:20 GMT
ETag: "542fca98-19f2"
Accept-Ranges: bytes.PNG........IHDR...@...@......iq.....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx..[y.T...o.....z.7.....U.E[Ea.%n...K4:....3.H4.h..3..O&.L&
lt;.....arTp#"B ...4K....wUw.^o...^U.B..29.<x............}-..I|H.Dg
y.v..Ln`....t......;..........8...,YB../....b'...;.P.....r..>.s..c.
`&.K#.`..r.hQ.GA.q.SN..S.uJ$......w.y......i....4>..p.\...3........
.....222$M..;j......1.H..K.3I.,#.-.....'.|....nqaa..H$.?00..........p.
...h4J===....s..i..N...C.j.us.M.V....~...N0.2~.....gW<..../))....0.
.l6r..TVV.......~...#I.....g...mR.E...U.8..........~...n.....uww..9...
.......6''.X.d7..0L..\..`._~..w.yon..}].....c._; ....l.... 7.....{pU.}
........E#......x.........kj...~R.... (77.N.A.dP...B.7g.\.....!.J.....
.(.....".....U..K.e..5."..`...o...%.p...?....Z:..Oy.. ..7......#.5.y4e
L.M......TZT...HR......>x......9G....d..z.c.x<~....>.W.{..q'r
....D....?..yC.A.................vRe...A.Z.i...r(...{......RM.e.....=.
.G...nZ..g~..P0.a.%9.. .7L.......{p..`$.....;J......B.)S.TO.>...H..
..>?.3\.. `..d..$Y%.}......v...SK...h...6....L.8..&....\1...$9..../
...hNq...-]..z...?....g..#..[.... ,..VP.U&<...4.].......$..QwO..v."
..$#.&. !.%I....[7SL B%......../Lm.....:h8..].o..u....n..?.]..MT......
0.I.N..(.g...<./..b.......%.\............UT\Rb..........t. ...!....
.$...H..9....n..=.!C..Z..Q.&.@.A.e............x._A..@\........4......
.....8..O=S..a...<.....`.#....1.~\.233)....u...Z...'....].:-'X.SJ..
n.d0...b.=....#B.MM3..P....)F.6.jkC..q.d....%:Fv...\........Qe!....veM
M.r.UW9`....(J......".......$H.*%..Cv.....7..R.....6.Q....)..R.n..<<< skipped >>>
GET /images/misc/username.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/png
Content-Length: 728
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-2d8"
Accept-Ranges: bytes.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e&
lt;...zIDATx..S_HSQ....{..Y..@...h..2)}..P)l.^zX.P..Q........QA.......
jO... .....0.....?.....9..y...w.w..;..;.;. ..`hp..........V.u..wJSU.r.
))...z|.S)..3..766.......D..i..E..J.......L...0.f......3....*.Y.UE.K).
J.;.T){...`..*|N..N.e^...Q..t...9.; ..n.F...... ..>q......'.{.._...
.T.f..h.a.o.Z..........oo..........5;n...[](..!q.H..F....g..cy.M...v..
..;.-...D.......n.m..|.6:....`O......xj.#^L.ccc/..y"...&..z.R..f..8.N.
.i|$.... T...{9.....E..J..|>....%..Y.....y~..r.... I.......b....6X7
...b.e.v.....:...!..........2!....V........Qs..#.!..43{.......t:m..j;.
.F..`..%..p........:...lo......Ba..e...5.m..c...=2....AxD.<hnOGG'..
-...Q..D4...B.........=.........IEND.B`.....
GET /images/bluefox/misc/whos_online.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 1604
Connection: keep-alive
Last-Modified: Mon, 29 Sep 2014 11:33:14 GMT
ETag: "5429437a-644"
Accept-Ranges: bytesGIF89a3.!..$.....33.......ww..........ff."".UU.......DD...............
.mm.......rr.zz.............YY.xx....ll.``............................
.................................................................!..XM
P DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> &
lt;x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011
66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="ht
tp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf
:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="h
ttp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.ad
obe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:14AA8BCE47C211E4B80BBC9CF0
4D72AD" xmpMM:InstanceID="xmp.iid:14AA8BCD47C211E4B80BBC9CF04D72AD" xm
p:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFro
m stRef:instanceID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B" stRef:do
cumentID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&
gt;...................................................................
...............................................................~}|{zyx
wvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:98
76543210/.-, *)('&%$#"! .................................!.....$.,....
3.!....@.pH,....r.l:...tJ.Z...v.=........G..:-....!.m@....p.G..t.rxGnx
o.D}|....oG.x.x.{.j....bGw"..pGkF.x..."F.x..o...E.o.$.F.".$...l.....x.
.E.o.$..F.E.j ..D.u.xzC.D.j.x..D....g.D.k..E......D."..@..>W...<<< skipped >>>
GET /images/bluefox/misc/stats.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 1626
Connection: keep-alive
Last-Modified: Mon, 29 Sep 2014 11:33:14 GMT
ETag: "5429437a-65a"
Accept-Ranges: bytesGIF89a3.!.. ....<<<.33......333....wwiii....ff...fff....""---
.............DD.UU..........RR........................................
......................................................................
....!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9
d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core
5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmln
s:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Descri
ption rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns
:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="htt
p://ns.adobe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:D6B22C8247C111E48
6859D7D00F07B4E" xmpMM:InstanceID="xmp.iid:D6B22C8147C111E486859D7D00F
07B4E" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:D
erivedFrom stRef:instanceID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B"
stRef:documentID="xmp.did:B85E0B12B647E411A4ECB674E47D8C8B"/> <
/rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket
end="r"?>..........................................................
......................................................................
..~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>
=<;:9876543210/.-, *)('&%$#"! .................................!...
.. .,....3.!....@.pH,....r.l:...tJ.Z...v.=....'Q!.=..:-$...!..@....p.G
..t.rxGnxo.D}|....oG.x.x.{.j....bGw...pGkF.x....F.x..o...E.o. .F... ..
.l..o..E.. ..F.....D.u.xzC.D....D....h.........E..x.gh.k........s.<<< skipped >>>
GET /anger1/head4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 404 Not Found
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzipbb..............1..0..w..pv.i...........9.@.....{.ZA.........6u^.g...R
$.<....H.vt.Z..(..d.!.CcZ............F)l.....'{........W...*?.>.
.....c....v.@".....p8........!....}..#.|a...G.:..J..\;.....0...
...
GET /images/bluefox/gradients/gradient_tcat.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 1453
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-5ad"
Accept-Ranges: bytesGIF89aN."..H.^.._..b..c..g..j..k..n..o..s..v..{..~....................
......................................................................
.......................................... .$$. .22.44.66.??.BB.DD.I
I.KK.TT.VV.[[.]].``...................................................
......................................................................
...............................................,....N.".....G......F..
.G....F...E.E........F....ED...C...C.........B.............?.@........
...@?.......A.><.==<..................;9..987.......o`.......
#a>..#..A....22..xq.F.5B...Q$...7..(2...-m.......7].h.S'N.9}....(..
>..=.....F..0..*..)......W.*.n..V...g..M!v.[..iY.`A..\.!@....o...C.
.<./..!...1........L......X....f..?w.p.4.../.V.!....c...A..../[..A.
....C..!.o..../.......?g.\.....g...;o.....O..x...7h`.<.....o.......
...`A....(....h...*.`..6.....P...Vh...Nh...n.!....a...X..'............
".-...........H..?....6..c....@..L29..G....4..#......3r...\....0....6.
.f.7.0..C..'./.Id.v.y..7..g...H......./2Y....j!.K.8h..R......h...h...z
.....:j...*.....@.."......j..F....6._......... ..>.........0....2.^
....-..u....Z{-}.P0......u..;.t.B......[..6g...V..... p...;p...,0..(.p
.....l...V.j...Y..s..l...A.$.L...i...&....-..2n0....1w.r.,.L.....s.-..
X...-4.G..W... ..TW-.a.U...!\-..T_.u.`..u.S.=6.T.`..%.`B.%.M..&.]w.t.m
w.r.m7......'....(.....#~.........-...7N.../.....>..x;..d.7^9.y...a
}. ;...N8...N...3&.. x..`..V<..#O..%{ <.y1.<.......g.v.....&g
t;clk-.....<.j/.}....;..<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=df58b7b1dcf92ddf9102afae2d1a2aa0c1486544804; expires=Thu, 08-Feb-18 09:06:44 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded6582a859f0-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=df58b7b1dcf92ddf9102afae2d1a2aa0c1486544804; expires=Thu, 08-Feb-18 09:06:44 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded66f36259f0-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=dd85f70245f5d5866369cbe4032e6eae51486544805; expires=Thu, 08-Feb-18 09:06:45 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded69448359f0-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=df58b7b1dcf92ddf9102afae2d1a2aa0c1486544804; expires=Thu, 08-Feb-18 09:06:44 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded65a2b559f0-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=dd85f70245f5d5866369cbe4032e6eae51486544805; expires=Thu, 08-Feb-18 09:06:45 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded68c43a59f0-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /clientscript/vbulletin_important.css?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: text/css
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-68c"
Content-Encoding: gzip26d.............TMO.0.=._1..R..-*..q.R.J|Hm..TBN2i.u..q.V....r.I)]..V.
.....{~..;......l.....M......h..S.........h..........~..u....^.....J.'
0...WB.....`.z....5Ky.....[.T.B..1/..ai0..Q...JC...'<b.@....h}..O..
..F.......8...h.........>........WU.-..cz..`.....G(..R..wV-.:o..|..
;p....6.*.\.....N.t./.A.........yu..B.6...P:...V.S.=I.X.N.4n.........K
.%.la.,Q..P.L...d<..6.R..-......c.4.d..E..2.P..).. t..7......q...4.
..2...T..P.:.4{.6".....%t...P....VUsR''.J.v..^8....`..j(..[.]...(.LJ_K
^...$tJrQZf.J....v...s.e^....{."..aN*:...x.2......o<{_...~.....@..U
.........UIr;....,..N`..p.4....v~5...4...pj'.1..G..m.......k`...../..
).........0......
GET /images/head1.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 25780
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-64b4"
Accept-Ranges: bytesGIF89a...................w...35.PQnAB................%(~-/8..K()......
............|.....e...lp.........t.....l.....d..\........T..L.... x..D
..h..,$%<..X..4..,..J..$..8........(................,..............
................4D4.......................(.....H.....................
...(%.....................)..<............................. ....m..
...X.........O......X9...........v....l:..|.:".....l.H#..b...'.H..k.(.
..O..U.........|....>..0........?.$.....i..|...8.,...U04..X..9/-...
.#.<...yw....'.D.....T.....L.....|..t..l..d..\...'.................
..............'......... ..:24...FD..............................|..t.
.l..d..\..T..L.....D...........<...........4...........,..|..t..l..
$..d..\..T.....L.....D..<......*),..W...C@$......>=I.....a/....H
44.ccWGG...H??...dYY............!.......,.............aK...9....L...C.
..>L(.....-ZT...C....#...A.2".[.N.C..GB..1.K..I....`..#}....... u..
.r!C.7..|:.bS.OaF,x..6h........w...k......L..'........J..G....H(..`.:I
.....ch.L..I....A.7v6..5n..c.&......j....T.U'b...'hh....<......QcV.
.......(p4h.T ..n80.....,i.45.....Z...t..x..^.gfr..-....cj.KC.|#q^.7L.
.^{..ZL..._c`.u^e.=..A.(c./o...7.5..h......agb`M!..m. c.x.qs.W....t..4
.m.0.N3.-..l"=w.WC.E.U....F....7&A..H.5..z..D.4....q.4C.F..._.D..../.H
..(......3.2.R.\:7.$ZmmZ.SP.6..g..g’`..&GR..A..E.JQ.f.k1..M....RjXb.
XhT...7.$.3.qo...6h...@..T.F.5.*f...XF.!F..>.....J......U{..e#8/HvC
.:.....@..C.8s.A0.H%AM...u.>...*.f...*.U.^...z.p..1..*./.8...h.Z.^T
e.......u...]..qC.N0..U.....TXn......&C..P../.@.//@g.J.Y.lz....S.*<<< skipped >>>
GET /images/bluefox/misc/navbits_start.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 1073
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-431"
Accept-Ranges: bytesGIF89a................~*#....)#|'". '~)#}(#.,'.($.*$|*#|)#.,(~)$} $. &
. &. &.,'./,.0)./*.2,.40q1(.73.60p2)s4,.?8.A;.E@.PF.TJ.SK.\QXG3YH4..|.
.}......................*(.*(.,,. (.-,. (.0/./../...-.*'.53.0/.... ).
).--.,*.-,./,.11.//.10.2/.>=y5/v4-p4 s5-.A?.FB.EBl?3`B2^K8UN:......
....00.54.11.--.?<{61...MN>.........EFB.........................
...................................wwwqqqpppnnnLLLDDDCCCBBBAAA@@@???&g
t;>>DDD.........................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................!.......,........@......$h........P..5."J
.......<. #.O.;g..|"a...&..4pDJ.Ap$...fP...e...C...W......@=nf.T.ga
..Jg...4...7|h.......P...gf..0...@.B..C..lH%...x.Ta....5n..^3gO.......
.q..u....f.c...Pe..2...!:.. A...e(pP.c.. hd.A[..0[x4y..2...4...".....8
)..O..P.dp. F.....Y".O B..M.1BdB...( ...P@.;HTTP/1.1 200 OK..Server: n
ginx/1.11.5..Date: Wed, 08 Feb 2017 09:10:52 GMT..Content-Type: image/
gif..Content-Length: 1073..Connection: keep-alive..Last-Modified: Fri,
05 Oct 2012 06:41:12 GMT..ETag: "506e8108-431"..Accept-Ranges: bytes.
.GIF89a................~*#....)#|'". '~)#}(#.,'.($.*$|*#|)#.,(~)$} $.
&. &. &.,'./,.0)./*.2,.40q1(.73.60p2)s4,.?8.A;.E@.PF.TJ.SK.\QXG3YH4..|
..}......................*(.*(.,,. (.-,. (.0/./../...-.*'.53.0/...<<< skipped >>>
GET /images/bluefox/statusicon/forum_old.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 20498
Connection: keep-alive
Last-Modified: Tue, 30 Sep 2014 08:10:28 GMT
ETag: "542a6574-5012"
Accept-Ranges: bytes.PNG........IHDR...3...!.....t.......pHYs................OiCCPPhotosho
p ICC profile..x..SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE.........
..Q,......!.........{.k........>...........H3Q5...B..........@..$p.
...d!s.#...~<< ".....x.....M..0.....B.\.....t.8K....@z.B..@F....
&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH..
...........0Q..)..{.`.##x.....F.W<. ...*..x..<.$9E.[.-q.WW..(.I.
.6a.a.@..y..2.4..............x.....6..._-...."bb.....p@...t~..,/...;.
.m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<..
....$.2].G......L......b...G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..&
gt;.5..j>.{.-.]c..K'.Xt.......o..(...h...w..?.G.%..fI.q..^D$.T..?..
..D..*.A....,.........`6.B$..B.B.d..r`)..B(....*`/.@.4.Qh..p...U..=p..
a...(....A...a!...b.X#......!.H...$ ...Q"K.5H1R.T UH..=r.9.\F..;..2...
.G1...Q=...C..7..F...dt1......r..=.6....h...>C.0....3.l0...B.8,..c.
."......V.....c..w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.X
H,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9., .......3...!.[.
.b@q..S.(R.jJ....4..e.2AU..R...T.5.ZB...R.Q...4u.9...IK......h.h.i..t.
....N..W...G.....w.......g(.....g.w...L......T071......oUX*.*|.....J.&
..*/T.......U.U.T..^S}.FU3S......U..P.S.Sg.;...g.oT?.~Y...Y.L.OC.Q.._.
.. .c..x,!k...u.5.&...|v*......=...9C3J3W.R..f?...q..tN..(...~....).).
.4L.1e\k....X.H.Q.G..6......E.Y...A.J'\'Gg.....S.S.....M=:....k....Dw.
n.....^..Lo..y....}/.T.m...G.X...$.....<.5qo<./...QC].@C.a.a....
..<..F.F..i.\.$.m.m..&.&!&KM.M..RM..).;L;L........5.=1.2.......<<< skipped >>>
GET /images/icons/icon1.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 1032
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-408"
Accept-Ranges: bytesGIF89a...............................|....................kop}........
...........................255...VX]........................'))..."%%.
.................HLM.....................efm......8:<..............
.uyz............??D.................. ,/......ABG............oqx......
...Z__.......................................BCG...............?AB....
................................489............................... "..
.............* .......................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............!.......,............ .:d.J.!.FH...L..o.....L...1bxX....
i.8i.'....8.H.....k 1j.q.G;....C"..@,..0...".@>..0.@.1..p.....AE.h`
...... ..B...G.2N...@..V............0E..'e.P.................%.....4.t
. ...F..y4. ...-/$d.....(.c.......G.<..'.T#A6..s..#&.....;HTTP/1.1
200 OK..Server: nginx/1.11.5..Date: Wed, 08 Feb 2017 09:10:53 GMT..Con
tent-Type: image/gif..Content-Length: 1032..Connection: keep-alive..La
st-Modified: Thu, 31 Mar 2016 12:09:55 GMT..ETag: "56fd1393-408"..Acce
pt-Ranges: bytes..GIF89a...............................|..............
......kop}...................................255...VX]................
........'))..."%%..................HLM.....................efm......8:
<...............uyz............??D.................. ,/......AB<<< skipped >>>
GET /jpg/twitter.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/png
Content-Length: 7053
Connection: keep-alive
Last-Modified: Sat, 04 Oct 2014 10:23:20 GMT
ETag: "542fca98-1b8d"
Accept-Ranges: bytes.PNG........IHDR...@...@......iq.....tEXtSoftware.Adobe ImageReadyq.e&
lt;.../IDATx..[....u...>v....V..Xt#...$$...AT.v.a*Nb.B.p..Rva.C....
r..e...(.....0H i...v........3=...3..]..B...z......]....{4.4.e.t|../..
...#G....-.....x.AV.i.Hx.w-.L....i...M.u.OGbQ.u.\.....f....S...2.. .#V
..\..F.5.#{..s...........j....sND..s.:.h.c"..r..(....x............"...
)I..Hk..a(dR<'...x...2GQ....6l...;v...|1!p.....r...B..%.vZ..c^..*..
M....~....xn..LqY*........o.i..J.d....t....9u._..h.L|..'U...q?F..phh(.
.6..Nz8''g%..t$.)..o2.g....C..........p8.{....:QTT.*I.0.Lp8...2`.X`.=.
$<... .S.U...v.}M&N9.$..I..*-\.n...x6...R .]..h``...`.....#...H.;QZ
>".)........\.^.H.]CZ.....i.....;..2..L<Bb....B...l......_.;.r..
WH........o....I '....L...* .T@...L.<.YQQa..$.|>_2.-..f&.....`.
.......q.W..OP.Q........n1..t./,,l.....fRU.r.%..L......'......%%._...f
]q..y...N.......m.>...........9...# .....$...yF:....<....n~....(
..g.v&......_.b....J.t..(2#.|&GQ@6X..|.s...M..]..YX3...<.P..j..@/*F
...............w...9...4.....KJHp.KX...>q.5.9F............3...'9qZ.
i.U:.....j.......>[...3V.....P!.....<.fZYY....Mxo.k.8.L.|.P..9.V
.h.A_........o~..z.T....K9.opp....!......".c.c;....x-...x....s&....j..
1B..-[6.....[o.u3.Z)V....X...'.\R...{<.G..;...G..ztu.`...D,.q.M.`.?
....).L..7^.......... V^YQSSs....!:Z[[7....H.........._.9....!......3.
=`D...K........{..-...-x.....%.L@.q.x.P.mn..Gu;)...,I.Y.lOC.x..F ....n
....P..L.^*[..c..H. P....O3}. e.........TXf..x8...^..I.&....2.....O.}.
M7.X.*..].9!ttt.......O.."7.........Ek.....aS.fBd8....A2......c...<<< skipped >>>
GET /clear.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 02:55:18 GMT
ETag: "56fc9196-2b"
Accept-Ranges: bytesGIF89a.............!.......,...........D..;....
GET /jpg/gdtmvRl.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 127641
Connection: keep-alive
Last-Modified: Sat, 27 Aug 2016 06:06:42 GMT
ETag: "57c12df2-1f299"
Accept-Ranges: bytesGIF89a..x.....^........$j..d....%/...ccc6..d...........U[ity..........
\\\.......0.....gkg...........RRR................|.MMM...|||......2Ji.
.@..7...222...qqq....$..............PT ...<<<Vd.AAAo...N.kk
k.5.[cu..8...... .t... ..................P......e......Q...-7Q......
...e..........H.._..M...v.....;DX............&p.,L.....>X...fhpm...
......J_&........Y..BT....Lm.$,3.b....(......s..yk.............(RGLZ.*
E>4.'=m..&..).d.679.......$V..Z.............=..............t....H..
..6cu..)o.3c.2u-./..............:!M.BUf. G...=..........$>`..|.vvw.
$....PT_~....... ...S..5".....0]....?m......WWW...&&&..b......D..Xy.EE
E....W..<>.....=.v.......ho..... \... .......O.........fX.......
TH......................xf...............2.........III....!.xlr.......
...{....f`v......B{.....&..........!..NETSCAPE2.0.....!.......,......x
........H......*\......#J.H.....3j...... C..I....(S.......0c..I....8s.
......@...J....H.*].....P.J..T ..X.j......`...K..Y.V..].....p...K....v
.............w..... ^...c...K.L.....3........C..M.....S.^.:4...c..M..]
..s.....o.....N..q... _.......K.N..u...k...........O.5....._..<....
.'.~.....#........._...h`z......J.`..F(.n.Nh....Va..v..c.~(..$..b.(...
".....0..@..P.b.8.HY.8.Q....(...1...4.I..L^f..G2.d.TV.X..@...D9.@j7Z).
.c..O.5@YB.f....751..s....C..X.d..'VM$.H.Z..F.>-p..71@g.C....Cd.g..
f..X..9..,....?9BO.99.i.z..@......`|nj..A%P..54.D..B.A.>.P..9..k...
.,.........H.ZV!g.Z&.... ....B e..B..a.V...,.S...p...5-..0w.T........C
.i......8..K... 1...d*.<%Pn.U(.k.UX.0.$.<.3...."CL,..6..F-{.<<< skipped >>>
GET /images/bluefox/buttons/collapse_thead.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 830
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-33e"
Accept-Ranges: bytesGIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3..........................................
......................................................................
...........!.......,........@......H......*\8..C..#J.H."...;...
.
GET /images/bluefox/misc/bg_tile.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 427
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-1ab"
Accept-Ranges: bytesGIF89a.........!........ .............................................
......................................................................
......................................................................
......................................................................
..... ............................................!..!................
....!..... ....................... ........"...,...............~.~....
......;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Wed, 08 Feb 2017 0
9:10:54 GMT..Content-Type: image/gif..Content-Length: 427..Connection:
keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT..ETag: "506e
8108-1ab"..Accept-Ranges: bytes..GIF89a.........!........ ............
......................................................................
......................................................................
......................................................................
...................................... ...............................
.............!..!....................!..... ....................... ..
......"...,...............~.~..........;....
GET /danger1/head4.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 404 Not Found
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzipbb..............1..0..w..pv.i...........9.@.....{.ZA.........6u^.g...R
$.<....H.vt.Z..(..d.!.CcZ............F)l.....'{........W...*?.>.
.....c....v.@".....p8........!....}..#.|a...G.:..J..\;.....0...
...
GET /jpg/larme.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/jpeg
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Mon, 29 Sep 2014 09:09:18 GMT
ETag: W/"542921be-2aee"
Content-Encoding: gzip2901..............wT.Q..'.....M.UB...... (.H..EA..Di.@.t...H.....W.&.R
E.*...}[...{....w..33........f....%...... ...u.....u..|&T.....4.(.BC..
...B.aL..0..&..lL.....6v6..$..bb...@r.G...:........@.!.............@b`
.?@......v.<........U@T.. i......42.T..........rf..YhX..T!l.v...p..
.<:...v...wA..{....g..B...".Y..W......x-m.........K.G'g.W7w._?... b
D.....1.I.).iO..e...........7465............7>195.~........k...[.{.
..G?~.........&.K..3.*jj05.?..U...,.4|R.VUCZ;o6~.0:.Zb^m;....w...1.yA.
e...h.A......D......,......f.T.....X.._M.Z...-54......i.....RTr..n.. F
...D......n..B......f4.M...,1b..k......L..{....Bq."0........z...0....W
#.K.....NJ...\|...Z.b...c4]p..(.7?.s...Y......wkY................-g^..
.d.@.....*5.b4... \eE.jf..3i.E..7.9Z.tc%...efS.*.P[.V^.!>..xv.M..}0
.z*.m.CBYDR`6D....,;..L.....pC|..[g^E.. ...[.......F.e%....C....P. ...
.U./:.D>.K"..!.Xv.[..b6D....3.B#......8.......~..?.2E..qx.Y...hcr#.
.Q..Q.].s|.!Sk. ...D.......q..FN.D;@.3M..2....0..D...Gq"F/W}..].J..x.8
o}.<9.H4.2....%..R.cP...C.c.~.$...n!...N.......`...!.Jki ........A.
....k...Lc..7."...Pb.h.Vh2.....M...dK6..........'.......j.F.~X=.el.tY.
..6.H*6..o..D.t.=N.6...$j=..|4.. hv2.g....*.?...Q...w......f...ng0....
..%....e..N<(E...>RE...........p.t..F M.)`......[....W..B.tC...U
..^q...Tj.T.x..l.@...*8...).d}....Km..1x.-o\I(...D~*4Y.f^.,...........
..........}...'........G..F...<5u.@Iz._..;a..R.w....w......,JS.. ..
"k.*...N.)Q..a..)...........FI.....T...b{c...r..e a.S........p3B_.....
..S*...{.AK...P.W.I....0....*.......W.......%..Z9w..d.l.e<~2.L%<<< skipped >>>
GET /bannerov/leaksbannerov.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: leakswith.pro
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:37 GMT
Content-Type: image/gif
Content-Length: 2629427
Connection: keep-alive
Set-Cookie: __cfduid=da06534c6ce8fa0076443faaab65937fc1486544797; expires=Thu, 08-Feb-18 09:06:37 GMT; path=/; domain=.leakswith.pro; HttpOnly
Last-Modified: Mon, 06 Feb 2017 17:20:17 GMT
CF-Cache-Status: HIT
Expires: Wed, 08 Feb 2017 11:06:37 GMT
Cache-Control: public, max-age=7200
Accept-Ranges: bytes
Server: cloudflare-nginx
CF-RAY: 32dded39914659fc-VIEGIF89a..x....................................."..'..8..-... ..!.#!.*#.
3"...'..!..$..4!.!,.!:.!."$.% .% .$9.*4.-;.(6.-9###*%%&(& )&$&)*')%*
4#%2,,9%'#,3,.1#.92.2$2< 38333;;;76:01.H..X..Q..g..x..q..H."W.#h.
#w.#|. G#'V#(N36k(-L!..)G..D.4H.6X.;V..Q'9G9=D%>S0;M.:f.:k..JB>C
X=Bn<C.C\.B\(DY3GX4BK.Gh.Ku.Sz.Gs&Jf'Ux5Yw.Pk8a}CCDKJLHEINLQQNRSRTY
VZ\Z\WTXQLO]\aHWka^bz\bdbelkmhfjnmqqnrznutru|z}yvzqmrdW^@A>........
............".")..........59.=B.[`.JO.<D.X..\..R.%[./]..d..c.7d.&f.
6k..g..Y..j..u..m.$l.(s.7v.%w.3v."^.~|.mx.Fy.Fm..{..t.${.,z..{..V..~..
|..|..{.7.....`........'..%..7.................'..'..&..2........%..F.
.G....................................................................
......................................................................
..........................|..!..NETSCAPE2.0.....!.......!..Resized wit
h ezgif.com.,......x.....#....#(*((%.%.#...#%.....#....%*.7*..(....17.
..*44.//*../11.....7..#.'.......*..(...)4564..../41,....6.465..*/6.1..
.'1............:W#]...Z.......7jH..oX......!.#.P..$x..Z.?.;..hpb>..
..D).&.....C....?<.UT.!..w...<..F.L.R.3.meIa7;..q.'....I.W.E..b.
....-Z..............B. A..Vm....c..w..%.8.......C..^...3U.....'.......
...4.hR%..5I 0 .....G.......%r..v...}.b..p..q...".xm..l,.W..........f#
..P........... ..u...9..z..T...@..0..B.V...B .... %l0.H....H.P. .....#
......L.H# ...!....*.`....t....D".n.t.H.-v.....C.1...H..(..!H'.......P
..*.M9*...<.<.....iH)..$T.1,....Yw.... .q..DC.Ba..h.L5UE&.d.P.."
.Q.h..,TJ.bi ...d).5.67.6BK.NV.:..&.r.m.XyO.h.bn...H%.......JZ.ueC<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrJdiQ/icg9B19asFe73bPYs+reAQUdXGnGUgZvJ2d6kFH35TESHeZ03kCEFslzmkHxCZVZtM5DJmpVK0= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca4.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:50 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: CD4E411028F5966AE35940E7A80D2D957332E76F
Cache-Control: max-age=530032,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 312
Connection: close
Content-Type: application/ocsp-response0..4......-0..).. .....0......0...0......uq..H.....AG...Hw..y..2017020
7123043Z0s0q0I0... .........%...' ..}j.^.v.b..x..uq..H.....AG...Hw..y.
.[%.i..&Uf.9...T.....20170207123043Z....20170214123043Z0...*.H.=....g.
0d.0...`..,3l.s.zT.M...h..&.F........C^..jdu..e..\.G.0H.dD$nk..Z.E.!.b
.!.O.2.Y.<......]8M.c.{r.d..-.....
GET /images/banner.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: vipcvv.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:37 GMT
Content-Type: image/gif
Content-Length: 93803
Connection: keep-alive
Set-Cookie: __cfduid=dd0d29eb98962bff311de9abc93ad0db31486544797; expires=Thu, 08-Feb-18 09:06:37 GMT; path=/; domain=.vipcvv.net; HttpOnly
Last-Modified: Mon, 01 Aug 2016 11:24:43 GMT
ETag: "58602b-16e6b-53900d8c314c0"
CF-Cache-Status: HIT
Expires: Wed, 08 Feb 2017 13:06:37 GMT
Cache-Control: public, max-age=14400
Accept-Ranges: bytes
Server: cloudflare-nginx
CF-RAY: 32dded39b73659d2-VIEGIF89a..<.....q,&......iGi....b.....%.r.roJ..'MKL.m.GD......o.".Uu.
.W .........,)0.Mrq.M...55.qq)%.%.c.....F.lK).......... N$&.kK......M.
.D.....Hb.2.4j..:..3-...3Ej..L3......{xxx......FQi..u8C....nVEKlw..%..
.nc.OF-..k.$3"p...*..6\...I..U..ZX...*rr.O..k....9Ig'../..j.R...H3J4ES
.i.L.#...Qk%.V.Tj......Lm5..0...(..2%S .....$.z.....r&...ege f .R.....
.q1c..DR..2..5.RH.....4..m.c..m....1.!..-.wf..M....I.`Xc....J.......e6
&........K..5......5........,....m.~.vwiZbN........P..fN.5...#.".by..#
...wix.....-(1.4&...4.8.7".$.4...iis.....u...S!#.....yN..x....Y...%.
.v.....F...........:7r.{g[1.).....5m....9.@ 5.5.ze4.....57]...$_\E....
k..........6.........!hue.........bxu..X(.?.IIC.6......4....9........Z
..,..X......................[..|..Y"............z............<=....
...J.../.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:D6CCB982FD56E61191CBCD718AD0B15D" xmpMM:Documen
tID="xmp.did:AC60A445579011E6B960DA0BB64187CC" xmpMM:InstanceID="xmp.i
id:AC60A444579011E6B960DA0BB64187CC" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid<<< skipped >>>
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 86408
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Fri, 16 Sep 2016 21:16:59 GMT
If-None-Match: "8017f9a85f10d21:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: VVV.download.windowsupdate.com
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Length: 50939
Content-Type: application/vnd.ms-cab-compressed
Last-Modified: Sat, 12 Nov 2016 01:34:12 GMT
Accept-Ranges: bytes
ETag: "02e4de843cd21:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
X-CID: 7
X-CCC: RU
X-MSEdge-Ref: Ref A: 58684CBFB1164FB194D1E4E574FC1F5D Ref B: MSAEDGE0108 Ref C: Wed Feb 8 01:06:55 2017 PST
Date: Wed, 08 Feb 2017 09:06:55 GMTMSCF............,...................I.................kI;. .authroot.s
tl.6....7..CK...<.[.........].y.Q..YKv..%k.....!..H!.Q.-..$tU$.)7k.
.R.=...n3......}?...3gf......h<.2...4.(q..f......&{.`....02.s...2@`
.J.<#..q..0Xy%.4..egd.:M.B....in.([....W....(.|.....|....s!..Mo..
@......|"(n;Z..'~DE.}(........Mz:T....x..{..n.`z..-.\.............q...
.ld2z..N/.b.J...........X.S.:UN.S.v."..'l........:yz.<."!.]O..6.:d.
....C.P ....P($.Y.Q y..y..B....u.`...u.00.....|(..A.J.Cp.c...X..g.....
....}..'........D.QVFf0...D...a6.f.0.....k.*8...<.;..o...(.....f...
L.0..C.......I.A!.H.....'._)....Qc.V.....5D..,..d../(..j.F.d.....`..f.
..$>:_%.W..(....@.r.9..Ob.e.$..m.~.]....g.......%`e_..&Qhp .......e
y.c.....H`.%<9.......#.\S...R.5....v.......dWE.....:...../"3.._..l.
XiH.J!..............{.5C_...i.U....7....;p....Q.`....L.j........u....b
.`:Mk.L.......*..@M^m..Jv...g........<d:l..Kq.X...*y...x1.u.......
.....z.....c.(<.b...l.#....,z~..M.Y.]..Z....F..N./..[.#....Ol...f.k
........U.rF)D....3..sK...`..W.....5.=.@#a....!./....>...g.(. ..9..
>!.K..e..j..{x.0.^,...U9..ru.C......,..q^1.G..A.e.F[...".1..*...^..
.L..#:,7...:.z.n...fI1.....l..E.q>......E...x n....H....t....5.....
\...<.l....7}.`\..~_..#..Bz....i..[{.w.....a...c....E w?..6..l.....
.x8..H....7.e.;.%.:.!.*Q....#..bT.......(....ka.......B..|.........1..
..t.r...fk....C.t`....@3.P..*t..nmD.....8$.bd..`D...5X.....H..L../1:..
Ap...w.\...,..U..../"X......}X...a...G....N.X..<....MG....r..H.....
_@..Q2..T...Q.....].e.G./.v,.Z5ib..5........9 ............z..!...g<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR64T7ooMQqLLQoy+emBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEEr1tl+/qet2RM6TJ0qOsO0= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:56 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 15:06:41 GMT
Expires: Tue, 14 Feb 2017 15:06:41 GMT
ETag: 721607A819B905492875ED20B900AD9D6D575C35
Cache-Control: max-age=539384,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0........j:.Z.....Vs.C.:(....2017020
7150641Z0s0q0I0... ........z.>...*,.(....F.@.......j:.Z.....Vs.C.:(
....J.._...vD..'J.......20170207150641Z....20170214150641Z0...*.H.....
..........<..h;(...:Nu...Y..*6..6..a.....L.M!I.\x..%..?...kcC.?....
$...72...5W7d|...XG...B......_..&q.=.o..5....}..3.y..!ZL.U.q..T..l...b
..9....{M`T.#<1V..0......T...M@5f. $=...i%$IQ..}......C.;.Xw.f...W.
z....Li.FF..=.I.<j.....:.p}...'......\>7j..<...wi..2.......l.
.
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRBc6bT2N9qzRkeiWvn5WI5MHBpNQQUTgvvGqRAW6UXaYcwyjRoQ9BBrvICEGpdw+U7Tk/Qe2kepfzsZGs= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.startssl.com
HTTP/1.1 200 OK
Server: nginx/1.7.2
Content-Type: application/ocsp-response
Content-Length: 1769
Content-Transfer-Encoding: Binary
Last-Modified: Tue, 07 Feb 2017 10:12:34 GMT
ETag: "658B432C180941E40F87FC9AA7A10F0CB27A092F"
Expires: Wed, 08 Feb 2017 09:07:01 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 08 Feb 2017 09:07:01 GMT
Connection: keep-alive0..........0..... .....0......0...0...I0G1.0...U....IL1.0...U....Start
Com Ltd.1 0...U....StartCom OCSP Responder..20170207101234Z0s0q0I0...
........As....j....k..b90pi5..N....@[..i.0.4hC.A....j]..;NO.{i....dk..
..20170207101234Z....20170211102234Z0...*.H....................I7._f..
....#..R*....b5..'..uZ........X%...."?A%.'.=.6..du."`m...<.B.'p....
...&!xW.|..j.........S.3.........HF..lVBwv.b..Cv..e.P..4.......{.<.
..g.......^b.HU.N. .EL........~.........-H..B.N.......>W.#.....JKo.
:&..RE.M...j..no../|.(.?.R..a.../..f|...D....0...0...0..........t.P..M
7O.">F.v..0...*.H........0}1.0...U....IL1.0...U....StartCom Ltd.1 0
)..U..."Secure Digital Certificate Signing1)0'..U... StartCom Certific
ation Authority0...160920000101Z..170920000101Z0G1.0...U....IL1.0...U.
...StartCom Ltd.1 0...U....StartCom OCSP Responder0.."0...*.H.........
....0..........W.-..Z.\.....u..6.F~....~>IXqW..h)..{ .C..k.wL..e..{
.k.o........%...l\..=......b...,a....9..4.....6..'.h..ca[....[.>...
e.vdpm..)...e..-....6/.e...ay...T.c.}..a25...'A...x.S..<.#... ..xl.
...D....p..5........L.o. G!....Ld\.!..)o..GK..i.w...b.....p.S.r.......
......0..0...U........0...U.%..0... .......0...U.......0.0... .....0..
....0...U......_tY."....!\.n..&..*.0...U.#..0...N....@[..i.0.4hC.A..0.
..*.H.............-..x5i...H...$Y.....y....2r.!..W]T....z.5..w^...[.1.
...H`..N...|.3...(d<.8..4..l.*.@...:.GV...........=.n.... ...y.WK.x
..~1.%...j....d..../R..p<.mR...Ii.%....d.5.P.Z.s.... ..p.7.W_.9.*.T
......... ..l>M.=...w8.K~.).uU...n.Q.@^.cR.a...5X...]'.P.Yf...0<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRRaBWasZmbOlXoYMAiydUZ4DA9KQQU15FOAcSwv/jIZ5NEnOcz+q2TDK8CECCIbc7NSRKoi/mPAmncjMg= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.startssl.com
HTTP/1.1 200 OK
Server: nginx/1.7.2
Content-Type: application/ocsp-response
Content-Length: 1816
Content-Transfer-Encoding: Binary
Last-Modified: Tue, 07 Feb 2017 10:44:35 GMT
ETag: "3D1C5E12C715FC028EB11588AED61DB9C3424F92"
Expires: Wed, 08 Feb 2017 09:07:06 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Wed, 08 Feb 2017 09:07:06 GMT
Connection: keep-alive0..........0..... .....0......0...0......0..1.0...U....IL1.0...U....St
artCom Ltd.1)0'..U... StartCom Certification Authority1503..U...,Start
Com Class 1 DV Server CA OCSP Responder..20170207104435Z0s0q0I0... ...
.....Qh.....:U.`."....0=)....N......g.D..3....... .m..I......i.......2
0170207104435Z....20170211105435Z0...*.H...............g..^%-.q.......
2....).b*.....#..=.. .}'.@t..X.]....%....^.....|k.:/i.0......".ru.....
o..............I...r<.O.]...H..f.....I...%........y.`k.X...A ...I..
e.ZL....L.^2.F...!.c.I1o.Y.L...V.....#..o;.{GOQ<.o"...Y..f.y..S..k.
$c.."..E..U..^T....C........I]6.8d.....0...0...0..........T...._fA....
.v..0...*.H........0x1.0...U....IL1.0...U....StartCom Ltd.1)0'..U... S
tartCom Certification Authority1&0$..U....StartCom Class 1 DV Server C
A0...161210034431Z..170330034431Z0..1.0...U....IL1.0...U....StartCom L
td.1)0'..U... StartCom Certification Authority1503..U...,StartCom Clas
s 1 DV Server CA OCSP Responder0.."0...*.H.............0.........Y..J.
?V..F.r..,.:..{{o@.O....$bC...s7!..J.h..T...jY....V..c.\$.(q.{O..L..u.
X89U....{.K.?}..,(.S.>F<`].`...yJ.......2.v...&."><.f.....
..CK.....}.k.8...[....Rg.t..x...z....(..?..9xT..Z.\|}{........>....
.....a.2.G.'..h....!I.....:..<..h...5.H$.\.>PI.....JY..........3
0../0...U...........0...U.%..0... .......0... .....0......0...U.......
0.0...U......o...iOM...:...S....T0...U.#..0.....N......g.D..3.....0o..
........c0a0$.. .....0...hXXp://ocsp.startssl.com09.. .....0..-http:/
/aia.startssl.com/certs/sca.server1.crt08..U...10/0-. .).'hXXp://c<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.usertrust.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 6F025C3022E0D67186FDB650BF8A81E7E712AAA2
Cache-Control: max-age=530037,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0.........z4.&...&T....$.T...2017020
7123043Z0s0q0I0... ........|.fT...D.b&...e{.z.......z4.&...&T....$.T..
.'f.V.I....p...."....20170207123043Z....20170214123043Z0...*.H........
.....2.]-..W.....0.?.zW....j...)hM ..q.......z..6.....1..|.z(..#Q..`..
"#<.V...A;W..D.\..Ud:OJr^.....juw.m..0T.."..v.(...6....(..S.p|....l
......^.Nw..<[..@...r...V...5. .7.....Lz{'..0.B.Z...r.j...\'y.z-.'q
... ..r.f)l.'dH.5..1S...k).}d).....\.. ...F9...@.."$......
GET /MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEQDKocXPk7YxqrHoH1imS68J HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca4.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:56 GMT
Server: Apache
Last-Modified: Sun, 05 Feb 2017 18:38:06 GMT
Expires: Sun, 12 Feb 2017 18:38:06 GMT
ETag: 965ED2546197F1814A730E26C5CE4B7CB24AFB5B
Cache-Control: max-age=379269,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 279
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0.....0..0......@.ag...qO...,o.. v=...201702051
83806Z0t0r0J0... ..........3.....>v..1.9S......@.ag...qO...,o.. v=.
.........1....X.K......20170205183806Z....20170212183806Z0...*.H.=....
G.0D. H.fK.g~.X.q....d..L .G...J.....o. .3B..........d8c......5.[TH8..
....
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj/6qJAfE5/j9OXBRE4= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.trust-provider.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: 5907E30F032C051F75CAAEB6ABD5F2B380B5ACAC
Cache-Control: max-age=530038,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0.........z4.&...&T....$.T...2017020
7123043Z0s0q0I0... ........|.fT...D.b&...e{.z.......z4.&...&T....$.T..
.CR.?..........DN....20170207123043Z....20170214123043Z0...*.H........
.......,.....y...{.J....<ox.*{.`rU....=.1.v]'..Tq.V.....O.2..!....s
..!#^..DGC..6.Xo..h...}...>..q...*Z..[[....^r%.1......p~.K...}..<
;.....H..X"Z..A..&.....x....&..O..uN....4"..l...i.W..? ~.....A?..]..ZX
.h.........7..$......tv.N&."_].b".....Qr...........'I.{..m@U..
GET /certs/ca.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: aia.startssl.com
HTTP/1.1 200 OK
Server: nginx/1.7.2
Content-Type: application/x-x509-ca-cert
Content-Length: 1997
Last-Modified: Fri, 18 Dec 2015 11:03:49 GMT
ETag: "5673e815-7cd"
Accept-Ranges: bytes
Date: Wed, 08 Feb 2017 09:06:50 GMT
Connection: keep-alive0...0...........0...*.H........0}1.0...U....IL1.0...U....StartCom Ltd.
1 0)..U..."Secure Digital Certificate Signing1)0'..U... StartCom Certi
fication Authority0...060917194636Z..360917194636Z0}1.0...U....IL1.0..
.U....StartCom Ltd.1 0)..U..."Secure Digital Certificate Signing1)0'..
U... StartCom Certification Authority0.."0...*.H.............0........
.....lF|x..{.3..rb..6 "$^..w.C...d...6.8.#.nm.<.r.....=.3 ./....AYg
...}..t..yL.7z.9.RY...FC......q.ub4.,......4.....R=.3..M..;JK..&/....r
5w.<]...&..6v\..t.%.......x.-...0.-ry.F..*.....I...........cS..b...
:..f..kt.. .v>.m..D.sb.;...SV%lQ......v.m.....=f..V...H.:K..XP.8u.[
.C......lMp[)e...]...1........{.n.'f..H.nB.?.!>{..p.c..l.T.\%z.....
..,~.^.MXn........2.......n..6I..Hi...M...i......y"H..{i.p..z7....vOW.
........`.g:........r".................\R<...*s......`.z/...n.&0...
..W..=.. ..v.... ...*r..3.].K....t.RK........R0..N0...U....0....0...U.
.......0...U......N....@[..i.0.4hC.A..0d..U...]0[0,.*.(.&hXXp://cert.s
tartcom.org/sfsca-crl.crl0 .).'.%hXXp://crl.startcom.org/sfsca-crl.crl
0..]..U. ...T0..P0..L.. ......7...0..;0/.. ........#hXXp://cert.startc
om.org/policy.pdf05.. ........)hXXp://cert.startcom.org/intermediate.p
df0.... .......0..0'. Start Commercial (StartCom) Ltd.0.......Limited
Liability, read the section *Legal Limitations* of the StartCom Certif
ication Authority Policy available at hXXp://cert.startcom.org/policy.
pdf0...`.H...B........08..`.H...B... .)StartCom Free SSL Certification
Authority0...*.H..............l..f.4...^}....N8.^..%.K.2..;.=.D.[<<< skipped >>>
GET /COMODOECCDomainValidationSecureServerCA2.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.comodoca4.com
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 08 Feb 2017 09:06:59 GMT
Content-Type: application/x-pkcs7-crl
Content-Length: 483
Last-Modified: Tue, 07 Feb 2017 05:47:36 GMT
Connection: close
ETag: "58995f78-1e3"
X-CCACDN-Mirror-ID: rmdccacrl1
Cache-Control: max-age=3600
Accept-Ranges: bytes0...0......0...*.H.=...0..1.0...U....GB1.0...U....Greater Manchester1.
0...U....Salford1.0...U....COMODO CA Limited1806..U.../COMODO ECC Doma
in Validation Secure Server CA 2..170207054736Z..170211054736Z0..0"...
...c.....{..x.n...160809152657Z0!..@Z.v<\.....[ e....160809152707Z0
"....|.........$?Y....161026165848Z0".....h.2...l..wY_2...170113180023
Z.00.0...U.#..0...@.ag...qO...,o.. v=.0...U........0...*.H.=....G.0D.
...'@{[[.3.. ..|o.k.f!....;@g..>. ...4#.w...&.D.X..V._...RQ...?....
.
GET /rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCDkbwjNvPLFRm7zMB3V80 HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Content-Type: application/ocsp-response
Content-Length: 1521
Connection: keep-alive
Set-Cookie: __cfduid=db6b3b513e41b40dc41edf66d20817ad41486544804; expires=Thu, 08-Feb-18 09:06:44 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 05:58:20 GMT
Expires: Sun, 12 Feb 2017 05:58:20 GMT
ETag: "41c7eb8fdc046ab687ca238404c2a1525516dbf1"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded65a64a59f6-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208055820Z0q0o0G0... .........W......#....*..2..1..`{f.E....P/}..4...
.K..F....,Tf.3.._4....20170208055820Z....20170212055820Z0...*.H.......
..........C..=.<.#s...6L...>.jf}..?.,..l...D....H..A..).v...~98.
....|..........y.....= ......by/*..J#.p6.08x...c..`.}l......[.......v
.(./.i...6?.W.bo....K's...O..w-D..........cgf%i.._.A..)..qS.J.99..9..e
.<y..%X.}y...x.....u/......s.J.....#.?...Ev..M..;].U....i.....0...0
...0..........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....G
lobalSign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612
08000000Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/
..U...(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H............
.0..........N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;..
.-..g..8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I
..g.J{}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.
o.B.x.....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..
0...U...........0...U.%..0... .......0...U.......0.0...U........>'.
..;6..9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U
. .E0C0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/reposito
ry/0...*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...
u..4.\m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<
;....e\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.
Filstf.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A....<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=d5d00ef27afb0ee6651b8b6d124fb54de1486544805; expires=Thu, 08-Feb-18 09:06:45 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded6847de59f6-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /certs/ca.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: aia.startssl.com
HTTP/1.1 200 OK
Server: nginx/1.7.2
Content-Type: application/x-x509-ca-cert
Content-Length: 1997
Last-Modified: Fri, 18 Dec 2015 11:03:49 GMT
ETag: "5673e815-7cd"
Accept-Ranges: bytes
Date: Wed, 08 Feb 2017 09:06:50 GMT
Connection: keep-alive0...0...........0...*.H........0}1.0...U....IL1.0...U....StartCom Ltd.
1 0)..U..."Secure Digital Certificate Signing1)0'..U... StartCom Certi
fication Authority0...060917194636Z..360917194636Z0}1.0...U....IL1.0..
.U....StartCom Ltd.1 0)..U..."Secure Digital Certificate Signing1)0'..
U... StartCom Certification Authority0.."0...*.H.............0........
.....lF|x..{.3..rb..6 "$^..w.C...d...6.8.#.nm.<.r.....=.3 ./....AYg
...}..t..yL.7z.9.RY...FC......q.ub4.,......4.....R=.3..M..;JK..&/....r
5w.<]...&..6v\..t.%.......x.-...0.-ry.F..*.....I...........cS..b...
:..f..kt.. .v>.m..D.sb.;...SV%lQ......v.m.....=f..V...H.:K..XP.8u.[
.C......lMp[)e...]...1........{.n.'f..H.nB.?.!>{..p.c..l.T.\%z.....
..,~.^.MXn........2.......n..6I..Hi...M...i......y"H..{i.p..z7....vOW.
........`.g:........r".................\R<...*s......`.z/...n.&0...
..W..=.. ..v.... ...*r..3.].K....t.RK........R0..N0...U....0....0...U.
.......0...U......N....@[..i.0.4hC.A..0d..U...]0[0,.*.(.&hXXp://cert.s
tartcom.org/sfsca-crl.crl0 .).'.%hXXp://crl.startcom.org/sfsca-crl.crl
0..]..U. ...T0..P0..L.. ......7...0..;0/.. ........#hXXp://cert.startc
om.org/policy.pdf05.. ........)hXXp://cert.startcom.org/intermediate.p
df0.... .......0..0'. Start Commercial (StartCom) Ltd.0.......Limited
Liability, read the section *Legal Limitations* of the StartCom Certif
ication Authority Policy available at hXXp://cert.startcom.org/policy.
pdf0...`.H...B........08..`.H...B... .)StartCom Free SSL Certification
Authority0...*.H..............l..f.4...^}....N8.^..%.K.2..;.=.D.[<<< skipped >>>
GET /site_stats/gif/t/a/YWx0ZW5lbi5jb20=/s.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: xsltcache.alexa.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Age: 8
Cache-Control: public
Content-Type: image/gif
Date: Wed, 08 Feb 2017 09:06:32 GMT
ETag: "07-Feb-17"
Expires: Thu, 09 Feb 2017 09:03:20 GMT
Last-Modified: Tue, 07 Feb 2017 00:00:00 GMT
Server: Apache-Coyote/1.1
Via: 1.0 ip-172-30-50-145 (squid/3.1.23)
X-Cache: HIT from ip-172-30-50-145
X-Cache-Lookup: HIT from ip-172-30-50-145:80
Content-Length: 2860
Connection: keep-aliveGIF89ax.A.............................................................
......................................................................
..{{.{{.zz{............||..........{{{............||.{{|......||......
................|||......}}......................||}...}}.............
...}}............................~~.}}}...............................
..}}~........................~~...............................~~~.....
.............~~.......................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........,....x.A........H......*\.......H.H.....3j.......?..I..I..O
.\.........8@&M.....h.....aJ<p......HD.4.N.......d..@/...@...=k..;.
)..3.X..UkJ.].|..s.Q.D...9`*A.Du2.H`...f%.U.W.....,h.@.....68.u...s...
.....lQc..`.Q..(&......g#...@...U..................q>.(..D.=.2..u..
..(.O.>.-W..k.....s..._LLYm..9#oG.9;z...'.T...^j.E..x.%.._I...w.eGT
...g........$p V.Bx.k.!..D=...f.< .~rUX.....V....bR#...k...Sa.e..z.
........T)vf^.Xf...Zv.%q^.. ..A ..*.Y..h.9.......tny..s..'...........s
.*..|.ZgEp..g.......V.i..f.(E......R.i..Z....r.%.........yj..j.f....'.
...'....*...k...&[^..6....F ...Vk...^ ...v..... ....k.... ......... ..
..k.... .........,....l.....o..7......p..Wl....T...w... .,..$.l..&.d..
,....0.,..4.l..6C...<....@.-..D.m4.:...v.4.t.N?.t...L..Q/..@.t.<<< skipped >>>
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 86408
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Fri, 16 Sep 2016 21:16:59 GMT
If-None-Match: "8017f9a85f10d21:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: VVV.download.windowsupdate.com
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Length: 50939
Content-Type: application/vnd.ms-cab-compressed
Last-Modified: Sat, 12 Nov 2016 01:34:12 GMT
Accept-Ranges: bytes
ETag: "02e4de843cd21:0"
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
X-CID: 7
X-CCC: RU
X-MSEdge-Ref: Ref A: 42B19F4D095E4BC4B915EE48F35B24F4 Ref B: MSAEDGE0123 Ref C: Wed Feb 8 01:06:55 2017 PST
Date: Wed, 08 Feb 2017 09:06:54 GMTMSCF............,...................I.................kI;. .authroot.s
tl.6....7..CK...<.[.........].y.Q..YKv..%k.....!..H!.Q.-..$tU$.)7k.
.R.=...n3......}?...3gf......h<.2...4.(q..f......&{.`....02.s...2@`
.J.<#..q..0Xy%.4..egd.:M.B....in.([....W....(.|.....|....s!..Mo..
@......|"(n;Z..'~DE.}(........Mz:T....x..{..n.`z..-.\.............q...
.ld2z..N/.b.J...........X.S.:UN.S.v."..'l........:yz.<."!.]O..6.:d.
....C.P ....P($.Y.Q y..y..B....u.`...u.00.....|(..A.J.Cp.c...X..g.....
....}..'........D.QVFf0...D...a6.f.0.....k.*8...<.;..o...(.....f...
L.0..C.......I.A!.H.....'._)....Qc.V.....5D..,..d../(..j.F.d.....`..f.
..$>:_%.W..(....@.r.9..Ob.e.$..m.~.]....g.......%`e_..&Qhp .......e
y.c.....H`.%<9.......#.\S...R.5....v.......dWE.....:...../"3.._..l.
XiH.J!..............{.5C_...i.U....7....;p....Q.`....L.j........u....b
.`:Mk.L.......*..@M^m..Jv...g........<d:l..Kq.X...*y...x1.u.......
.....z.....c.(<.b...l.#....,z~..M.Y.]..Z....F..N./..[.#....Ol...f.k
........U.rF)D....3..sK...`..W.....5.=.@#a....!./....>...g.(. ..9..
>!.K..e..j..{x.0.^,...U9..ru.C......,..q^1.G..A.e.F[...".1..*...^..
.L..#:,7...:.z.n...fI1.....l..E.q>......E...x n....H....t....5.....
\...<.l....7}.`\..~_..#..Bz....i..[{.w.....a...c....E w?..6..l.....
.x8..H....7.e.;.%.:.!.*Q....#..bT.......(....ka.......B..|.........1..
..t.r...fk....C.t`....@3.P..*t..nmD.....8$.bd..`D...5X.....H..L../1:..
Ap...w.\...,..U..../"X......}X...a...G....N.X..<....MG....r..H.....
_@..Q2..T...Q.....].e.G./.v,.Z5ib..5........9 ............z..!...g<<< skipped >>>
GET /CRL/Omniroot2025.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Sat, 16 Nov 2013 06:15:02 GMT
If-None-Match: "200da-5b6-4eb453c33260e"
User-Agent: Microsoft-CryptoAPI/6.1
Host: cdp1.public-trust.com
HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Type: application/x-pkcs7-crl
Date: Wed, 08 Feb 2017 09:07:20 GMT
Etag: "200c0-cba-546dfb468d5d3"
Last-Modified: Tue, 24 Jan 2017 23:45:01 GMT
Server: ECS (arn/45A4)
X-Cache: HIT
Content-Length: 32580...0......0...*.H........0Z1.0...U....IE1.0...U....Baltimore1.0...U..
..CyberTrust1"0 ..U....Baltimore CyberTrust Root..170124185021Z..17042
1185021Z0...0....'k...120111220757Z0....'k...120111220847Z0....'.C..13
0130174530Z0....'....130807173059Z0....'....140122185220Z0....'....140
212185542Z0....'yr..150701184507Z0....'#...100303201301Z0....''q..1004
14175202Z0....'L...110224181251Z0....'Pn..110309142119Z0....'....10021
6203312Z0....'#...100303201213Z0....'3#..100908172555Z0....''n..101208
175627Z0....''m..101208175749Z0....''p..101208175916Z0....'H...1101141
62156Z0#...'X>..110815145134Z0.0...U.......0#...'Z2..110818184101Z0
.0...U.......0....'g...120111164333Z0....'g...120111164409Z0....'g...1
20111164519Z0....'....100216213519Z0....''s..100414175225Z0....''k..10
0414181839Z0....'3"..100908172705Z0....'3$..100908172728Z0....''o..101
208175645Z0....''l..101208175727Z0....'H...110119195142Z0....'Nz..1103
02154045Z0....'c...111207220933Z0....'g...120111164445Z0....''r..10041
4175143Z0....'8...101012182723Z0....'e...120111163041Z0....'VJ..110714
160903Z0....'s...130123162633Z0....'....130904190524Z0....'....1310242
14319Z0....'....140129172435Z0....'....140129172453Z0....'....13102421
4310Z0....'....131101204601Z0....'....140219171632Z0....'.^..140409155
638Z0....'i...140709171930Z0....'/:..141119193302Z0....'J...1506031846
05Z0....'k...150603185020Z0....'k...150603185058Z0....'k...15060318513
1Z0....'k...120111220827Z0....'8...140716191203Z0....'....131219195909
Z0....'....140219171545Z0....'k...151105070000Z0....'q...160126173<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=d3fe201fff8aef30ed8eea49e93f0abf21486544804; expires=Thu, 08-Feb-18 09:06:44 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded65909159a8-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:44 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=d3fe201fff8aef30ed8eea49e93f0abf21486544804; expires=Thu, 08-Feb-18 09:06:44 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded67015f59a8-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6+MgGqMQQUYHtmGkUNl8qJUC99BM00qP/8/UsCCwQAAAAAAURO8DYx HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.globalsign.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:45 GMT
Content-Type: application/ocsp-response
Content-Length: 1518
Connection: keep-alive
Set-Cookie: __cfduid=d69eb61ac61daba69edcb95c70bcb2e9d1486544805; expires=Thu, 08-Feb-18 09:06:45 GMT; path=/; domain=.globalsign.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:06:33 GMT
Expires: Sun, 12 Feb 2017 06:06:33 GMT
ETag: "29a3474243d07310ea1bf093a53dbe76ca70ff2f"
Cache-Control: max-age=10800,public,no-transform,must-revalidate
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 32dded69428d59a8-VIE0..........0..... .....0......0...0........>'...;6..9.wS..._...2017
0208060633Z0n0l0D0... .........W......#....*..2..1..`{f.E....P/}..4...
.K........DN.61....20170208060633Z....20170212060633Z0...*.H..........
.........w'..n..u..*h.j8j..H.I:...A.kD.m....&...>....~`)..1..^....$
.....A.E./....xpF..C.......... .....;.n.1...Jx...X..Q....eSx..z.....0E
..Gy..e....U5..p.].^c.{(....?........nk.W....?r?p&.D..a..e..."s....S.Q
..K..A....~..;.>iQ.y....w......NWq.N%.3..r.m............0...0...0..
........H...!U,43.....0...*.H........0W1.0...U....BE1.0...U....GlobalS
ign nv-sa1.0...U....Root CA1.0...U....GlobalSign Root CA0...1612080000
00Z..170515000000Z0[1.0...U....BE1.0...U....GlobalSign nv-sa110/..U...
(GlobalSign OCSP for Root R1 - Signer 1.20.."0...*.H.............0....
......N....K.N..z.........p...CL....@....\....f.JsR.{_awn....;...-..g.
.8..6.|l.(....h....;G.@..T..%.....7.R..O;u.g@g.C........2.Y....I..g.J{
}...u.@...ih..$.<...{.h.h... ....}M}.:.........rS=.$....lE)3.o.B.x.
....^.V.#N..=S^.F..U.}C2...-S...... .2....I.......].c........0..0...U.
..........0...U.%..0... .......0...U.......0.0...U........>'...;6..
9.wS..._.0...U.#..0...`{f.E....P/}..4....K0... .....0......0L..U. .E0C
0A.. .....2._0402.. ........&hXXps://VVV.globalsign.com/repository/0..
.*.H.............>S.......F@.).fox..V\.........x.[...I&.=[...u..4.\
m....V..n......3YC..Rl-.....a..@G...@..o.......@..~....9/}.i.<....e
\.\a.'.}......}.....Cn.y.u....xZ9..x..x|h .}I-:..RD.S..Ql..2cnX.Filstf
.......e.V.G......\..]hh ....W.../..x:.2I.*.....S?.Dr..A.....=..._<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrJdiQ/icg9B19asFe73bPYs+reAQUdXGnGUgZvJ2d6kFH35TESHeZ03kCEFslzmkHxCZVZtM5DJmpVK0= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca4.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:50 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 12:30:43 GMT
Expires: Tue, 14 Feb 2017 12:30:43 GMT
ETag: CD4E411028F5966AE35940E7A80D2D957332E76F
Cache-Control: max-age=530032,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 312
Connection: close
Content-Type: application/ocsp-response0..4......-0..).. .....0......0...0......uq..H.....AG...Hw..y..2017020
7123043Z0s0q0I0... .........%...' ..}j.^.v.b..x..uq..H.....AG...Hw..y.
.[%.i..&Uf.9...T.....20170207123043Z....20170214123043Z0...*.H.=....g.
0d.0...`..,3l.s.zT.M...h..&.F........C^..jdu..e..\.G.0H.dD$nk..Z.E.!.b
.!.O.2.Y.<......]8M.c.{r.d..-.....
GET /COMODORSADomainValidationSecureServerCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:07:00 GMT
Content-Type: application/x-pkcs7-crl
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=d83a406ca9002836e833e935738c62bfc1486544820; expires=Thu, 08-Feb-18 09:07:00 GMT; path=/; domain=.comodoca.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:28:59 GMT
ETag: W/"589abaab-132603"
X-CCACDN-Mirror-ID: rmdccacrl8
Cache-Control: public, max-age=14400
CF-Cache-Status: HIT
Expires: Wed, 08 Feb 2017 13:07:00 GMT
Server: cloudflare-nginx
CF-RAY: 32ddedc693a35990-VIE5c4c..0..@.0..?t...0...*.H........0..1.0...U....GB1.0...U....Greater M
anchester1.0...U....Salford1.0...U....COMODO CA Limited1604..U...-COMO
DO RSA Domain Validation Secure Server CA..170208062859Z..170212062859
Z0..>z0!....w`.h.**..$.R.\..140220191049Z0"....P{.... .]A....m..140
404195800Z0!.......u,y".QU..A...140410154408Z0"........fU.%....}....14
0410172927Z0".....,.jc...Q..FV....140410185945Z0!...0...:.Km.~..V....1
40410214937Z0!..cE...2!D....,It...140410215014Z0"......*{u.....BZ.....
140410223535Z0!.....(..7./.9..n....140410224524Z0!..].F.L.....|.O .,..
140410224851Z0!..\...Y...N.........140410230501Z0"....P.#.~..>.U>
;<.....140411065449Z0!...'.k.WJpt.?.......140411131823Z0!..b.B.F..
.&.D...X..140411131850Z0"....5......0.?.B!....140411131922Z0".....@.wb
0}=..L{.....140411131938Z0!..2..r........G..F..140411131956Z0!..4...Y/
X..f...cb...140411174902Z0!........~4...LV..(..140411185644Z0".....uU_
o....C.m.M]..140412001353Z0".......r.!......-p...140412001402Z0"......
xW {d...rW?.P..140412021032Z0".......#.8...d.."L#..140412114042Z0"....
x.{...!..........140412155740Z0!..L....7.-~.r.J*....140412163423Z0!..M
..\_L.3..5}.).5..140412171532Z0"......b/.m.../.Z.Y...140412175728Z0!..
0............T.3..140412183108Z0".....dIk......b..C...140412200345Z0".
........._$.........140413022007Z0"............C..c.....140413104918Z0
"......n...xS.Y.E..J..140413123759Z0!..p..J.)vO.'...x.]..140413143438Z
0!..4...r..V..g.B.....140413190918Z0!..'..]...<.......t..1404131937
21Z0".....'....}1...z.....140413194717Z0"......R.g.t.......R..1404<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR64T7ooMQqLLQoy+emBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEEr1tl+/qet2RM6TJ0qOsO0= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:56 GMT
Server: Apache
Last-Modified: Tue, 07 Feb 2017 15:06:41 GMT
Expires: Tue, 14 Feb 2017 15:06:41 GMT
ETag: 721607A819B905492875ED20B900AD9D6D575C35
Cache-Control: max-age=539384,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 471
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0......0...0........j:.Z.....Vs.C.:(....2017020
7150641Z0s0q0I0... ........z.>...*,.(....F.@.......j:.Z.....Vs.C.:(
....J.._...vD..'J.......20170207150641Z....20170214150641Z0...*.H.....
..........<..h;(...:Nu...Y..*6..6..a.....L.M!I.\x..%..?...kcC.?....
$...72...5W7d|...XG...B......_..&q.=.o..5....}..3.y..!ZL.U.q..T..l...b
..9....{M`T.#<1V..0......T...M@5f. $=...i%$IQ..}......C.;.Xw.f...W.
z....Li.FF..=.I.<j.....:.p}...'......\>7j..<...wi..2.......l.
.
GET /COMODOECCDomainValidationSecureServerCA2.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.comodoca4.com
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 08 Feb 2017 09:06:59 GMT
Content-Type: application/x-pkcs7-crl
Content-Length: 483
Last-Modified: Tue, 07 Feb 2017 05:47:36 GMT
Connection: close
ETag: "58995f78-1e3"
X-CCACDN-Mirror-ID: rmdccacrl1
Cache-Control: max-age=3600
Accept-Ranges: bytes0...0......0...*.H.=...0..1.0...U....GB1.0...U....Greater Manchester1.
0...U....Salford1.0...U....COMODO CA Limited1806..U.../COMODO ECC Doma
in Validation Secure Server CA 2..170207054736Z..170211054736Z0..0"...
...c.....{..x.n...160809152657Z0!..@Z.v<\.....[ e....160809152707Z0
"....|.........$?Y....161026165848Z0".....h.2...l..wY_2...170113180023
Z.00.0...U.#..0...@.ag...qO...,o.. v=.0...U........0...*.H.=....G.0D.
...'@{[[.3.. ..|o.k.f!....;@g..>. ...4#.w...&.D.X..V._...RQ...?....
.
GET /clientscript/yui/connection/connection-min.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-2d54"
Content-Encoding: gzipeda...............r.F.}.B....0.=.f#..@H....f<.IiU.,Z....._J.....4.9
......O..s.t.........~IZ.\o.w......e..o....r.....V.3.>...E.nE.....Z
y...E...~.Z.|..nI..wx....%k...t[3...9...r.<.w.8..$..............M&f
N...'q........Ut.N..0.M.e8O.,Y........52..W.>...G..3.f.-=....p.....
..U..~.a.6..m..~...u..1.#i..M3._..6..A.O......$]..i..90..Z...f...n...D
.>.........i....Dy.d~...8#....%...*..l.g....B"Y.ca........=......Qd
..U.O|..:."...Wx...M....6......~..@...?.L....H..."..1......P..v.f..@..
.c.T.7.BStj....M}...@...d.S......@F.[_.<.i..w..cr....`..v...p..@...
...}?..n.i4..m.........]NH.#...\.<.q.......3........,...|.2.'.u..8.
..`z....8.@W..v.[)&y...bX[......5.......^..[....$ 6.!..tc.H"L._....(..
s.eo...a....<}....Kr..........y.....o..(.T...<.gV....g..H..`.@T.
.@.o(.WN4.H...Jp...9...r..$..H...)...A0.p(-.P.........v..z..@...o.2...
.7.8[.....[.q.s....{ u...j....P.')..$.m...cm1(hm.].D....{.;].UO.}....*
.oq.].U .E......G...;..v...8$.@.).^.o?O.O0.5...\F.......X$}.86U.j...5.
7sp6=. ....B../5O.....s.Z.I..!z......p.......w~.mw...5...2.... ...a.G
..F8........@b.b.S..._....a...X..`....@.\..oo.V.........'..N../%S....I
9!..:.}J..=.s!.EbF..qq*<[.N...).k..FO...N....6h..&.6.......^......a
.Pa|l).z.y=A?UT.Ef.g.t...."....K....&:L..v8E....C....k%~..7H...O.v....
..ck.......BC.........Cm.wj.AH..]......c;..e.....v7..v..8_...C..b...#.
4. .S..,.#.............IM..........X..b,}_u."}....Bwqp.kH.h.h.w.......
..1&.rI...~...r^U................L.VQ.......Rk...\..G...Z.q../0......V
..2......."..A.W|{Z..6.v.(...\.)....<eF.x.p....F...Wk....a.m...<<< skipped >>>
GET /clientscript/vbulletin_md5.js?v=389 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Thu, 31 Mar 2016 02:55:20 GMT
ETag: W/"56fc9198-1558"
Content-Encoding: gzip7d9...............s......T.x..rp..DuH...G.m.G..(.l..%W..l..../....#..E
......@<~..^....'.iF..p.^...U.j....j.9......f.\X.wwW2....t..Z.x?_.2
.G....=[oV..B(..o..........F..zN....&H=....U..nv7...."`.........B.....
.9......(~<.3......2..E.(~.Y.=....[........q...l..}...3..5...f..b..
........72.j...r.....T.. ?w.vFU.h...37k...k...k...g...]_Gg.ir....7e.\$
i.Q..T.......'^.J........JH...Z.*..V.A,M.Q.HMM.=....gN._$..(.B2.9..G..
..JP.M.@...2B.&....C.P..r......N..H.y.M[4...p)h.k.{...N!h.`....F..pQZy
.."..d.4...|..W..".=. ..%4.&*.I..3fH.O:>...\rfj...C..DB...Q....R.t.
.....$T..:....l^.D...Ii.;...... {S.o....I...*.....l.L.5.........(ED.9.
.2......Z....dRi!`.....i.hD.F.Y6...N..F...vh.......xr.P.6M.J.t..I.|...
...a.C.iTj....u.5..NS.j...iD...FDk...s.LJ..Cn..64...W..PW..N.-..Z.....
cQ...R...#.V...I.N8:.R...(..:6.....\.g#......%H..[<.....".G....H^.X
..{8HHFMj.p....0C.....6.s%.N.`6?,.`TS.m.=.S....T.......1xWilZ5.|..Mjc`
....Z.Aj......S.PA.4.}......(.iv.....m.."w..E.l.#H^...j!..8...5..3....
...H*...Q.....2....c.v..2.&...ewq...."..*2..>.m:....E.RI.....U!a'II
..V..9.Qlq&...^.ku......9.."\>...........vZs....b......l..I.o..n.ZM
~...;.Z...E4J..H.d.....Q.~.y.Z.F.@....8i.rL......pd.........Qq4..D..E|
..;.C=x.._=#...E..........o.oG........F..0.a.a}X...f.....hX.....?..>
;d........}.!..v....@.P.....v...)..!~......Zu...E.......V.Y;?.\..'.].g
....G.L..'..A=s...?..h.I..{.(?R8.......Uo..}...W..].5...;..e5k...Ry...
.^..0T.#.:O[Goe...~..).....z...}....O....>.o..EZ..&.ry5.7Q..??..AF.
.,.........C.....dir..=.A;.i../n..W...B......aX..e......J.U_=.."h.<<< skipped >>>
GET /images/head3.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:52 GMT
Content-Type: image/gif
Content-Length: 33457
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-82b1"
Accept-Ranges: bytesGIF89a................................................................
..................}..e.....\..........................|..\..L........l
.....T.....;..4..$.............................|.....F..B..t..>..l.
..........t.................d..\..:.....6..2.....T.................*..
L..&..D....#..."..<..C.....w.....4..g.....,..L.....X..$....-..(....
.....7..'.............................................................
....*...........,.....b.....$.....4..<.."..T..L..D..*..&..y.....d..
:..U..6..2..............|..F..B..t..>..l..[........................
..........................n...........................................
....|..\........t..L..l..d..F..B..>..:..T..6..2.....*..&.."........
...............F..B.....t..>..:..6.....2.....F..*.....L..&.."......
.....,.......................!.......,...............`...x...cgoN"v...
c.P.@{.-j....G. ....Q...%1.c..^..."......B.Y".(`.I...@....7o.......4S.
8]r.n....mr...%..]..I...K....J41..n...ry..&....K...>...i.V..6n.. ..
S.Wv.XND.........G/K7z..)d............k.=}..M..c......%..n......6Wve..
s.m.#......L..k..y.....(.....K..m.......(Rm.......%.........y?\...>
D...?d..L..uVd....E]..._..s.5.p..5.l..nb.FQj..."P....y.....Wx&FLmU..q.
...<...I6..6.5...C(.D.M6.hcM.?0..7. ...f.4.{4.T.Kh.q...t..7D...;^..
.</...Q..b..#....;.q.4..e.D*=...`.w..zd..S.<..4..g.R1U4.....cm'.
.Ue... ....#O...3.7.`..5....&.<..2.8.I7lb.M6.`..l".4.7]\r.v..d!DY..
...l..M......X...p...6.H....$..4.pc...e...... ;yD.N6.@s.u.t#.L4......W
.O.U.S.;...e..R....*M.B\..*.(.L4&h..#.\A,...Z..wv...H..c..}..7.L..<<< skipped >>>
GET /images/bluefox/buttons/collapse_tcat.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 834
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-342"
Accept-Ranges: bytesGIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3..........................................
......................................................................
...........!.......,...............H......*\......"F|H.........;HTTP/1
.1 200 OK..Server: nginx/1.11.5..Date: Wed, 08 Feb 2017 09:10:53 GMT..
Content-Type: image/gif..Content-Length: 834..Connection: keep-alive..
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT..ETag: "506e8106-342"..Ac
cept-Ranges: bytes..GIF89a..................f..3..............f..3....
..........f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..
............f..3..............f..3..............f..3....f..f..f..ff.f3
.f..3..3..3..3f.33.3............f..3..............f..3..............f.
.3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............
f..3...f..f..f..f.ff.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.
fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..<<< skipped >>>
GET /images/bluefox/buttons/lastpost.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 239
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-ef"
Accept-Ranges: bytesGIF89a...................... ..&..,..4..:..H..N..T..b..h..v..|........
................%%.GG..................!.......,..........l...di..h.l
.).XWm_.<.......5rL".$&......DC.l&..K4H,...u. .Df.x.)......q..".|..
..&.p.r....p.........p*._..o)!.;HTTP/1.1 200 OK..Server: nginx/1.11.5.
.Date: Wed, 08 Feb 2017 09:10:53 GMT..Content-Type: image/gif..Content
-Length: 239..Connection: keep-alive..Last-Modified: Fri, 05 Oct 2012
06:41:12 GMT..ETag: "506e8108-ef"..Accept-Ranges: bytes..GIF89a.......
............... ..&..,..4..:..H..N..T..b..h..v..|.....................
...%%.GG..................!.......,..........l...di..h.l .).XWm_.<.
......5rL".$&......DC.l&..K4H,...u. .Df.x.)......q..".|....&.p.r....p.
........p*._..o)!.;....
GET /images/bluefox/misc/w3cxhtml.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 175
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-af"
Accept-Ranges: bytesGIF89aG...... ......:::!.......,....G................0.....f.E.X...(
..... ...........<....z)m-e......a.s.n..e.I...E*oH.E..I...p.k.9]G.[
...?!F.f.T..s(.W.x.....H)&y......iP..;HTTP/1.1 200 OK..Server: nginx/1
.11.5..Date: Wed, 08 Feb 2017 09:10:53 GMT..Content-Type: image/gif..C
ontent-Length: 175..Connection: keep-alive..Last-Modified: Fri, 05 Oct
2012 06:41:12 GMT..ETag: "506e8108-af"..Accept-Ranges: bytes..GIF89aG
...... ......:::!.......,....G................0.....f.E.X...(..... .
..........<....z)m-e......a.s.n..e.I...E*oH.E..I...p.k.9]G.[...?!F.
f.T..s(.W.x.....H)&y......iP..;....
GET /images/icons/icon7.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:53 GMT
Content-Type: image/gif
Content-Length: 1058
Connection: keep-alive
Last-Modified: Thu, 31 Mar 2016 12:09:55 GMT
ETag: "56fd1393-422"
Accept-Ranges: bytesGIF89a..........................................s.....2.....p..7..}...
!#...t......cX....IJ1NN6........krgA........T........t}sG..q........i.
.....VY:..wGG0..X..`dd?.|A..Y.z...k........t..u.....f..5..w..M..rpq:..
?|m7.........re.bV&..[..f..^psH...XN......p..HypA.....N..k..A..H.....Q
.....q.....Z_a4../......na'........O....................5........_..\.
.Y.....r.........~x]od:..E.v@..vk^ }n5......pd/..|oqH.....t..`........
b.|\..{........S..t...........g..z..y..Y..]~qE.....V..N.....X..M......
.....z.....`..u..C...{n)......46#..m........Xre%..q.....}.....g..Y23"&
%...@..G.....V...PP2..M...............................................
......................................................................
......................................................................
...........!.......,............}..XAJ.....\.....xZq..*......01I..D=6.
.4P..C.".X.f..Ha....B...........8w|..Ee...`.... ..Q|.."....7[4..E...X.
@h.AA......8..@..nv4..g......H ...".j."%..-.f..H.b..4..e.".O..........
UB>..U%.. ....eiD.,%...a%........@..K....Ak......9....D.L......P..b
...S'.....;....
GET /images/misc/password.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/png
Content-Length: 620
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:10 GMT
ETag: "506e8106-26c"
Accept-Ranges: bytes.PNG........IHDR................a....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx..S=..`.~.VN.......[.A.m.A.N... ..&N..&................<
;P.Z......I.5.V....M.&._h....|..{......Dp]...|.........Q"..s..^....4}.
f ..g2.$....a....e9U.T.9.s.4/}..O..`.>.>..B..l6.f..I..i."....4..
(...l.>|.s.....8.a,'.I.j5....h4..PP..r.X|]....L..L.....P*...[r..3?.
"....`q..:..]..i.... s..N..(.. 0{.{..`ex.....[|....W..~...7......./...
...l.>..U..m.X<..S....!..u..-4,....Gl...]o...n.%.fM.....C...'...
.....m..... .K.....u....V.}.,.[_6.[. ..F{..c..e...../...#..=.[......?%
....D......7....q.F.cf..L......U!......g.pv....G.?...........c.&...m@.
...IEND.B`.....
GET /jpg/sa1.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/jpeg
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Last-Modified: Sat, 04 Oct 2014 10:40:50 GMT
ETag: W/"542fceb2-927b"
Content-Encoding: gzip400a..............gTTM.(..!g..$........$9'.0d...(A.P$ 9...."A.dI.D2
H.......{.s...u..s-V..U.....{v.}..|. V.W..@h @......K.y.Y...*....6..".
.H....@........./..t......^`...\A|(...............=.......KY.-`..[.;..
.........9[.=..>.^.Q^.Q.../....(./.......m/.~......N.~.&..S...~....
.....@..g. .._u....O.g..........u...'3.U...@...V......................
........%.K.(I.Q..........!.1!!1.!!!.."$.Q..?....@..tQ........$..)dWq.
..$.Vb.P...`d..10..qp.@.*D..........h.h.X...`|~....~...CJ......|.d....
.L.Zo-..\..e......nY..RdV._.}.c%...].....l....A...<...........T../.
.Y{.&.V..|..V....K..n.]< .......l....D.p....i.].K.|.c..,x......b.5(
NF...M`......k....Fd]....r...2.....o....|0.M.@....Sbf%-L...A.JQ-...k..
'j.4.i-..mb%[..7.fV.....4k..O....h...a.......>jT".3...&....~..e....
..u#..Wjt....L(NC..,.^.r..........n_u~.>1h.. ....K.o'PV.O.%.....!d.
d..d.eF..7=,f.;.j.A....z4^UL\..`^.a..e...1s...m......{.....-.y...;.G..
..... F.r.os...g.v.Z.........j.$.X.el.|...*.Jr....4._}.......].E9U.6.&
lt;....%nJ.#.............5.wM...2..p...m...i.t....].i...=.B.... ...bF7
.~....;x_7L..0..b..q4.....-.OP.&w%.....<....>K.4...D.........WC.
..{...T.5....B..;.....5.....-9|....p....-..g.C=v./nE..^..b.h..:}..}<
;..........%g....A.....%C.g...........4...W......a. .UG.Ee.K{.......@.
.'.....4.6 .x.$......)m].{D..;z2......\.>....:.-|:{.....f{O...j....
.....1..w..^.5.........y......oy?.....o.c.q.|......{...........Xi....h
Z.,;..zu...b..9.'.......GN..E.#.f.......4.5..p.....N`<K......:....E
.8...i..b..5........hH......s2.I6/..8.?.|~Z3..a..V..~fs.8.........<<< skipped >>>
GET /images/bluefox/misc/nav_bg_small.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 1453
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-5ad"
Accept-Ranges: bytesGIF89aN."..H.^.._..b..c..g..j..k..n..o..s..v..{..~....................
......................................................................
.......................................... .$$. .22.44.66.??.BB.DD.I
I.KK.TT.VV.[[.]].``...................................................
......................................................................
...............................................,....N.".....G......F..
.G....F...E.E........F....ED...C...C.........B.............?.@........
...@?.......A.><.==<..................;9..987.......o`.......
#a>..#..A....22..xq.F.5B...Q$...7..(2...-m.......7].h.S'N.9}....(..
>..=.....F..0..*..)......W.*.n..V...g..M!v.[..iY.`A..\.!@....o...C.
.<./..!...1........L......X....f..?w.p.4.../.V.!....c...A..../[..A.
....C..!.o..../.......?g.\.....g...;o.....O..x...7h`.<.....o.......
...`A....(....h...*.`..6.....P...Vh...Nh...n.!....a...X..'............
".-...........H..?....6..c....@..L29..G....4..#......3r...\....0....6.
.f.7.0..C..'./.Id.v.y..7..g...H......./2Y....j!.K.8h..R......h...h...z
.....:j...*.....@.."......j..F....6._......... ..>.........0....2.^
....-..u....Z{-}.P0......u..;.t.B......[..6g...V..... p...;p...,0..(.p
.....l...V.j...Y..s..l...A.$.L...i...&....-..2n0....1w.r.,.L.....s.-..
X...-4.G..W... ..TW-.a.U...!\-..T_.u.`..u.S.=6.T.`..%.`B.%.M..&.]w.t.m
w.r.m7......'....(.....#~.........-...7N.../.....>..x;..d.7^9.y...a
}. ;...N8...N...3&.. x..`..V<..#O..%{ <.y1.<.......g.v.....&g
t;clk-.....<.j/.}....;....<<< skipped >>>
GET /images/bluefox/misc/nav.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 1831
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-727"
Accept-Ranges: bytes.PNG........IHDR...N..."........<....sRGB.........bKGD.............
.pHYs.................tIME....."5&.......IDATh..Z]..6...b,.q.].EPt.c..
.B.....G...I."I.....Z.8} %...$o.E."..93.|.C...pH.......-k.....l.7o\...
g.|:..s..h.....4..u...|....Ck......u.Y..Xp...1.....N...{..........l...
......:......_..u...;&].p...R.......5tD;'._,b.9..^.b.%....M.PY.....ed.
e.}.. K.xl.3...-.8...^..R...<.H..F.p6j..u.=gqwWw..-.F]........j...V
.c...V...=.e9....2..e.....pn(...U...]...#......FM'T...._....%w...iY..`
..s.Q......{=.I8V^...)...3.i..}=........CX...b.z.Z...8..r....E0.p.;..!
...Y.Q....N....v:y;....>..=t..v.........gl6Z.....l.#.i..M.$.....Y.;
....u.X.)J.^fU....33...5.....-.5...,e...(V......l$p..O*..`...Z).z6.H..
!..DB...m....k.`..D...0..0s..S..[...\....V./_L"..F......:....m6.....
.u-.C.p...^1......e.u.(.1..9..@...3.gq.mz.o..B.......8..Q3d.....d.rT.R
tJY.0..N....7...J.Fv.c9R..3............V....M..'r......."...Pyh,[...Q.
R.e..e.$......g........mu.. {.......js..,)....)....s.....L..X.<Z..q
.9..N..].....Z.........x.p.`..........t.=J.a..B..{..J.8m .=.N.K..HCY..
...{b..bP.S;...H.4J.....`.........2.z.d.).DO...@."!.......]fz.........
.B.9Z....}......*.h).....q.[..}4c.&]F...._E.}......}..6.Z..G..........
....3..._...".,...=.x..tPz8.)...yNt.d/.[....=.|.L.@\.}..J..U. ........
lS....z."..8..K".M.=...C.Ow.W.........-....7../......d2a.%.B./.&..[M..
&....rN.. .W..k~..Z...W5...m;..oGdap.`$.....2[.....]...@1^{....m...>
;......O....}..B......5X.1Y=.....^Q;S........%..;G.q..s..`......@.....
2..FX6..i,..5.9p.q.D.....n..........._s.F.F.0.....Zus...i.(......Y<<< skipped >>>
GET /images/bluefox/gradients/gradient_thead.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.altenen.com/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C)
Host: VVV.altenen.com
Connection: Keep-Alive
Cookie: bbsessionhash=09e27ae7feeb5688b5ded822c65bcb98; bblastvisit=1486544796; bblastactivity=0
HTTP/1.1 200 OK
Server: nginx/1.11.5
Date: Wed, 08 Feb 2017 09:10:54 GMT
Content-Type: image/gif
Content-Length: 846
Connection: keep-alive
Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT
ETag: "506e8108-34e"
Accept-Ranges: bytesGIF89a..'.............................................................
...!!!###&&&))),,,;;;.................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......'... .3`.`......0P..@.....0p.A....0h......$L
.I2 .;HTTP/1.1 200 OK..Server: nginx/1.11.5..Date: Wed, 08 Feb 2017 09
:10:54 GMT..Content-Type: image/gif..Content-Length: 846..Connection:
keep-alive..Last-Modified: Fri, 05 Oct 2012 06:41:12 GMT..ETag: "506e8
108-34e"..Accept-Ranges: bytes..GIF89a..'.............................
...................................!!!###&&&))),,,;;;.................
......................................................................
......................................................................
......................................................................
......................................................................
..................................................................<<< skipped >>>
GET /COMODORSADomainValidationSecureServerCA.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crl.comodoca.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:07:00 GMT
Content-Type: application/x-pkcs7-crl
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=d6439c4d28b31ebe2e2d9c09ce9a1b9521486544820; expires=Thu, 08-Feb-18 09:07:00 GMT; path=/; domain=.comodoca.com; HttpOnly
Last-Modified: Wed, 08 Feb 2017 06:28:59 GMT
ETag: W/"589abaab-132603"
X-CCACDN-Mirror-ID: rmdccacrl8
Cache-Control: public, max-age=14400
CF-Cache-Status: HIT
Expires: Wed, 08 Feb 2017 13:07:00 GMT
Server: cloudflare-nginx
CF-RAY: 32ddedc65617595a-VIE5c4c..0..@.0..?t...0...*.H........0..1.0...U....GB1.0...U....Greater M
anchester1.0...U....Salford1.0...U....COMODO CA Limited1604..U...-COMO
DO RSA Domain Validation Secure Server CA..170208062859Z..170212062859
Z0..>z0!....w`.h.**..$.R.\..140220191049Z0"....P{.... .]A....m..140
404195800Z0!.......u,y".QU..A...140410154408Z0"........fU.%....}....14
0410172927Z0".....,.jc...Q..FV....140410185945Z0!...0...:.Km.~..V....1
40410214937Z0!..cE...2!D....,It...140410215014Z0"......*{u.....BZ.....
140410223535Z0!.....(..7./.9..n....140410224524Z0!..].F.L.....|.O .,..
140410224851Z0!..\...Y...N.........140410230501Z0"....P.#.~..>.U>
;<.....140411065449Z0!...'.k.WJpt.?.......140411131823Z0!..b.B.F..
.&.D...X..140411131850Z0"....5......0.?.B!....140411131922Z0".....@.wb
0}=..L{.....140411131938Z0!..2..r........G..F..140411131956Z0!..4...Y/
X..f...cb...140411174902Z0!........~4...LV..(..140411185644Z0".....uU_
o....C.m.M]..140412001353Z0".......r.!......-p...140412001402Z0"......
xW {d...rW?.P..140412021032Z0".......#.8...d.."L#..140412114042Z0"....
x.{...!..........140412155740Z0!..L....7.-~.r.J*....140412163423Z0!..M
..\_L.3..5}.).5..140412171532Z0"......b/.m.../.Z.Y...140412175728Z0!..
0............T.3..140412183108Z0".....dIk......b..C...140412200345Z0".
........._$.........140413022007Z0"............C..c.....140413104918Z0
"......n...xS.Y.E..J..140413123759Z0!..p..J.)vO.'...x.]..140413143438Z
0!..4...r..V..g.B.....140413190918Z0!..'..]...<.......t..1404131937
21Z0".....'....}1...z.....140413194717Z0"......R.g.t.......R..1404<<< skipped >>>
GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ/C8g3FP3hIILG/U1Ct2PZYCEHQcVg+I29Zftz+dMPk8jMI= HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: ocsp.comodoca4.com
HTTP/1.1 200 OK
Date: Wed, 08 Feb 2017 09:06:55 GMT
Server: Apache
Last-Modified: Mon, 06 Feb 2017 16:47:02 GMT
Expires: Mon, 13 Feb 2017 16:47:02 GMT
ETag: 4B521F64471389944671117613D4F86037624D9D
Cache-Control: max-age=459006,public,no-transform,must-revalidate
X-OCSP-Reponder-ID: rmdccaocsp34
Content-Length: 279
Connection: close
Content-Type: application/ocsp-response0..........0..... .....0.....0..0......@.ag...qO...,o.. v=...201702061
64702Z0s0q0I0... ..........3.....>v..1.9S......@.ag...qO...,o.. v=.
..t.V...._.?.0.<......20170206164702Z....20170213164702Z0...*.H.=..
..H.0E. {..R.2'....a.l..H.^\.E..o..EYY.I.!...@..jT..P....u. ........l.
.......
The Trojan connects to the servers at the folowing location(s):
.text
`.data
.idata
@.rsrc
@.reloc
Invalid parameter passed to C runtime function.
advapi32.dll
setupx.dll
setupapi.dll
advpack.dll
wininit.ini
Software\Microsoft\Windows\CurrentVersion\App Paths
ADMQCMD
USRQCMD
FINISHMSG
IXPd.TMP
msdownld.tmp
TMP4351$.TMP
wextract.pdb
PSSSSSSh
SSSh<
PSSShp
PSShp
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
Command.com /c %s
rundll32.exe %s,InstallHinfSection %s 128 %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
%s /D:%s
PendingFileRenameOperations
SHELL32.DLL
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\
RegCreateKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
RegCloseKey
ADVAPI32.dll
GetWindowsDirectoryA
KERNEL32.dll
GDI32.dll
ExitWindowsEx
MsgWaitForMultipleObjects
USER32.dll
_amsg_exit
_acmdln
msvcrt.dll
COMCTL32.dll
Cabinet.dll
VERSION.dll
7 *%<=:
430[54.1&$
00.exe
CARDGE~1.EXE
-AO}O
5.jqW
m^-p}
%fxPA
Y1%9ssL
.vn{qU.Du?H
C%x4[
H%dzm}
z[ .gr
[.xP<
u0.SE
t~.Pz
x^.Yk
%XbFS
.Eq[y/
.KGb9!O8KS
mY[.pHA
&e.jM#
f'm%F"
7-E} |T-
34%u;
<4%u4
X.OJNJ
=)%sM4w
.mK.S
.sy.;en
Q4<.FY
%xST2
sM.san
,/%U6
%u|_Z
58c.BxV
L*.Kc8f
-.Fl6
)eR%s
.OeK.
-N&%c
.Hi?sW
4TCp?Q
<%%Sw
f.RsK
#L'.au
z~r%x
w.jGc
sJ%sC
gZ5.yW
8%F|x
#g.MT
zW?%S
Ï*\E
)V%f\
q6Udp
E.Yls
.0.wC$;
<assemblyIdentity version="5.1.0.0"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
<!--The ID below indicates application support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/><!--The ID below indicates application support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>Kernel32.dll
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
Filetable full.Ên not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.OFalha ao obter informa
o em disco de: %s.
Mensagem do sistema: %s..Um recurso necess
o pode ser encontrado.#Tem certeza de que deseja cancelar?
o do sistema operacional.'Falha do pedido de aloca
O arquivo de gabinete (.cab) n
vel encontrar uma unidade com %s KB de espa
o.NPasta inv
lida. Certifique-se de que a pasta existe e de que permite grava
o.ZEspecifique uma pasta com um nome de caminho totalmente qualificado ou clique em Cancelar.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process <%s>. Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
o da pasta.QN
logo do navegador.RN
vel carregar Shell32.dll, necess
)Erro ao criar o processo <%s>. Causa: %s7N
suporte para o tamanho do cluster deste sistema..Um recurso necess
rio parece estar corrompido.IA instala
o requer o Windows 95 ou o Windows NT 4.0 beta 2 ou posterior.
Erro ao carregar %smFalha de GetProcAddress() na fun
o '%s'. Poss
o incorreta de advpack.dll est
sendo usada.>O Windows 95 ou o Windows NT
vel criar a pasta '%s'
precisa de %s KB de espa
o livre na unidade %s.
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
$Erro ao recuperar a pasta do Windows
*Desligamento do NT: erro OpenProcessToken./Desligamento do NT: erro AdjustTokenPrivileges.'Desligamento do NT: erro ExitWindowsEx.
o em disco insuficiente para arquivo de permuta) ou arquivo de gabinete (.cab) corrompido._As informa
es de volume da unidade (%s) n
Mensagem do sistema: %s.
o e tente novamente.pO programa de instala
/C:<Cmd> -- Override Install Command defined by author.
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
pia do pacote '%s' j
sendo executada no sistema. Deseja executar outra c
vel encontrar o arquivo: %s.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
xito quando executadas por um administrador.
(A pasta '%s' n
sendo executada no sistema. Apenas uma c
pia pode ser executada de cada vez.PO pacote '%s' n
o do Windows que est
sendo executada.FO pacote '%s' n
o do arquivo: %s do sistema.
11.00.9600.16428 (winblue_gdr.131013-1700)
WEXTRACT.EXE .MUI
11.00.9600.16428
iexplore.exe_1376:
.text
`.data
.rsrc
@.reloc
>.uzf
.us;}
IEFRAME.dll
MLANG.dll
iertutil.dll
urlmon.dll
ole32.dll
SHELL32.dll
SHLWAPI.dll
msvcrt.dll
USER32.dll
KERNEL32.dll
ADVAPI32.dll
RegOpenKeyExW
RegCloseKey
GetWindowsDirectoryW
_amsg_exit
_wcmdln
UrlApplySchemeW
PathIsURLW
UrlCanonicalizeW
UrlCreateFromPathW
iexplore.pdb
KEYW
KEYWh
KEYWD
.ENNNG.
a.ry.v
l.igM4
?1%SGf
xh.JW^
.97777"7" " " !
3.... ))
8888888888888
8888888888
.lPV)
úW1
.ApX/
H.ZAf
ð[U
%s!FK
1YYYY1YY9GEAA=77YRNNNW:.VT1
888777777
Y.hilkRROMLK=C,
..(((($$
3...((((%
3....(.''$
3.2...((((%
33.2....(,'
55323222...
(%&'00443445?
00.,,,4(
000.,,9(
0020..9(
003200;(
(#'( (''''!'!Microsoft.InternetExplorer.Default
>user32.dll
Kernel32.DLL
>xfire.exe
wlmail.exe
winamp.exe
waol.exe
sidebar.exe
psocdesigner.exe
np.exe
netscape.exe
netcaptor.exe
neoplanet.exe
msn.exe
mshtmpad.exe
mshta.exe
loader42.exe
infopath.exe
iexplore.exe
iepreview.exe
groove.exe
explorer.exe
dreamweaver.exe
contribute.exe
aol.exe
{28fb17e0-d393-439d-9a21-9474a070473a}Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
DShell32.dll
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}"%s" %s
Kernel32.dll
\AppPatch\sysmain.sdb
-extoff go.microsoft.com/fwlink/?LinkId=106323
-extoff go.microsoft.com/fwlink/?LinkId=106322
-extoff go.microsoft.com/fwlink/?LinkId=106320
kernel32.dll
{00000000-0000-0000-0000-000000000000}\\?\Volume
shell:%s
Imaging_CreateWebPagePreview_Perftrack
Browseui_Tabs_Tearoff_BetweenWindows
Frame_URLEntered
Imaging_CreateWebPagePreview
WS_ExecuteQuery
Shdocvw_BaseBrowser_FireEvent_WindowStateChanged
IdleTask_Execution_Time
9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
IEXPLORE.EXE
Windows
9.00.8112.16421
iexplore.exe_1376_rwx_10000000_0004D000:
`.rsrc
ServerKeyloggerU
789:;<&'()* ,-./12345
%SERVER%
URLMON.DLL
shell32.dll
hXXp://
advapi32.dll
kernel32.dll
mpr.dll
version.dll
comctl32.dll
gdi32.dll
opengl32.dll
user32.dll
wintrust.dll
msimg32.dll
KWindows
TServerKeylogger
GetWindowsDirectoryW
RegOpenKeyExW
RegCreateKeyW
RegCloseKey
RegOpenKeyExA
FindExecutableW
ShellExecuteW
SHDeleteKeyW
URLDownloadToCacheFileW
UnhookWindowsHookEx
SetWindowsHookExW
MapVirtualKeyW
GetKeyboardLayout
GetKeyState
GetKeyboardType
GetKeyboardState
FtpPutFileW
FtpSetCurrentDirectoryW
.idata
.rdata
P.reloc
P.rsrc
URLF
KERNEL32.DLL
ntdll.dll
oleaut32.dll
shlwapi.dll
wininet.dll
x.html
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
[Execute]
KeyDelBackspace
<meta http-equiv="Content-Type" content="text/html;charset=UTF-8">
.html
XtremeKeylogger
Software\Microsoft\Windows\CurrentVersion\Run
.functions
icon=shell32.dll,4
shellexecute=
autorun.inf
\Microsoft\Windows\
ÞFAULTBROWSER%
svchost.exe
ah-antihacker.ddns.net
ftpuser
{GC38A0CR-DN53-H852-7HLM-OT3OQ1BPW5BR}HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ogspot.comHKCU
PTF.ftpserver.com
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe
%Program Files%\Internet Explorer\iexplore.exe
svchost.exe_2736:
.text
`.data
.rsrc
@.reloc
msvcrt.dll
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
KERNEL32.dll
NTDLL.DLL
API-MS-Win-Security-Base-L1-1-0.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
RPCRT4.dll
ole32.dll
ntdll.dll
_amsg_exit
RegCloseKey
RegOpenKeyExW
GetProcessHeap
svchost.pdb
version="5.1.0.0"
name="Microsoft.Windows.Services.SvcHost"
<description>Host Process for Windows Services</description>
<requestedExecutionLevel
Software\Microsoft\Windows NT\CurrentVersion\Svchost
Software\Microsoft\Windows NT\CurrentVersion\MgdSvchost
\PIPE\
Host Process for Windows Services
6.1.7600.16385 (win7_rtm.090713-1255)
svchost.exe
Windows
Operating System
6.1.7600.16385
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:452
00.exe:3400
.exe:3656 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\00.exe (2939 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\CARDGE~1.EXE (11970 bytes)
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.new (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\a33333.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\LoMkjwQ.exe (673 bytes)
C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.new (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\.exe (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\w3ccss[1].gif (177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\c_Y6_Ex_Vd[1].png (2572 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\468x60[1].gif (3532 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 (100 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\h_Yjw_ZId[1].gif (182282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\close[1].gif (428 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9E4BE0042965AB3D0DE015F847D8AB90_03E448FF6BD55C02A6D9C1DD496E4276 (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\MTW9W09E.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\pid[1] (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\stats[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\password[1].png (620 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\bg_tile[1].gif (427 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\collapse_thead[1].gif (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\vbulletin_md5[1].js (213 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\vbulletin_important[1].css (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\final_banner[1].gif (11008 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\6QLB5TNV.txt (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\GX1OvJc[1].gif (23453 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4C7C.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 (2720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\whos_online[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\sa1[1].jpg (6204 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\w3cxhtml[1].gif (175 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 (1413 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar362D.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\collapse_tcat[1].gif (834 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\banner[1].gif (6031 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\head2[1].gif (1160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\forum_new[1].gif (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\facebook[1].png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\clear[1].gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\NVJHO8PL.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\crckbanner[1].gif (183280 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_C7E630361CE489407CC0114009311154 (716 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\nav_bg_small[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\username[1].png (728 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\nav[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\head4[1].gif (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\icon1[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\small[1].gif (81464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab6196.tmp (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4C8F.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LISK6Z0Y.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\nav_final[1].gif (652 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BC3EBA4E46329F29E449DFA191208FBF_BD64D75B80DFC94E25718464FE4C47FB (3318 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1BB09BEEC155258835C193A7AA85AA5B_F9E222772213E8AB26AD25ACDA31AFAB (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\LMR7UUH6.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\gdtmvRl[1].gif (8442 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7B59DAYM.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\icon7[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\icon2[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\yahoo-dom-event[1].js (21224 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F0060A9F9287878B15AB61E0E47645E5 (644 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\QWRKLHO6.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9E4BE0042965AB3D0DE015F847D8AB90_03E448FF6BD55C02A6D9C1DD496E4276 (3346 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_727F58DC786B1E896AAB69F069684AB9 (279 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\OD4_KEVB[1].gif (92577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\vbulletin_global[1].js (11653 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\CFERAQO9.txt (120 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\ACF244F1A10D4DBED0D88EBA0C43A9B5_BA1AB6C2BDFDF57799E8116E4002D001 (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\mff_NTNk[1].gif (5740 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\74F831100DEB0B8799203064F3E38B68 (966 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\L3Zd0Sx[1].gif (10308 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\forum_old[1].gif (584 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\tcat_left[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BC3EBA4E46329F29E449DFA191208FBF_BD64D75B80DFC94E25718464FE4C47FB (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab362C.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F (3948 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_D004E5083B392DC7F7C7D16A878C03CA (279 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\gradient_thead[1].gif (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\twitter[1].png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5457A8CE4B2A7499F8299A013B6E1C7C_CE50F893881D43DC0C815E4D80FAF2B4 (2674 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\icon4[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\subforum_old[1].gif (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\gradient_tcat[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5457A8CE4B2A7499F8299A013B6E1C7C_CE50F893881D43DC0C815E4D80FAF2B4 (942 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\vbulletin_menu[1].js (6412 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\a[1].js (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AF4EE75E3A4ABA658C0087EB9A0BB5B_C7E630361CE489407CC0114009311154 (279 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\s[1].gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\head3[1].gif (1928 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F0060A9F9287878B15AB61E0E47645E5 (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\source[1].gif (289438 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220 (1454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab61A7.tmp (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 (4048 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\X4DZBFM2.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4C7D.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\altenen_com[1].htm (758 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_7DC3E633EDFAEFC3AA3C99552548EC2F (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\max_banner_big_900_120[1].gif (29968 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\US26EDXK.txt (86 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_D004E5083B392DC7F7C7D16A878C03CA (692 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\ACF244F1A10D4DBED0D88EBA0C43A9B5_BA1AB6C2BDFDF57799E8116E4002D001 (13664 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\leaksbannerov[1].gif (163316 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\connection-min[1].js (6176 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_7DC3E633EDFAEFC3AA3C99552548EC2F (1888 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\74F831100DEB0B8799203064F3E38B68 (746 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8D93UTC3\larme[1].jpg (1887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\L8Z4GR9W.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZU3OSJ64.txt (246 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\lastpost[1].gif (239 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar6197.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017020820170209\index.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\navbits_start[1].gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JCZ65HM1.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\head1[1].gif (1160 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\64DCC9872C5635B1B7891B30665E0558_5552C20A2631357820903FD38A8C0F9F (936 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4ZZNMJGQ\altenen_com[1].htm (15684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\900[1].gif (47928 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C1F94CD5CA263ECFB1A4BAB1B832C909 (548 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\JN31I3JO.txt (117 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220 (2688 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4C8E.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar61A8.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AF4EE75E3A4ABA658C0087EB9A0BB5B_727F58DC786B1E896AAB69F069684AB9 (708 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C1F94CD5CA263ECFB1A4BAB1B832C909 (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1BB09BEEC155258835C193A7AA85AA5B_F9E222772213E8AB26AD25ACDA31AFAB (1112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\ZMECC7Y2.txt (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Cookies\7Z4LLQJ1.txt (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\25FDO7QC\Big_banner[1].gif (75764 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYNOWECL\51[1].gif (3 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.