Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.car1997.cn/

Overview

General Information

Sample URL:http://www.car1997.cn/
Analysis ID:1616519
Infos:

Detection

Score:68
Range:0 - 100
Confidence:100%

Signatures

AI detected phishing page
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
AI detected suspicious Javascript
Connects to several IPs in different countries
HTML body contains low number of good links
HTML body contains password input but no form action
HTML body with high number of embedded images detected
HTML page contains hidden javascript code
HTML title does not match URL
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 1976 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5644 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2296,i,1317288127873804294,14328008075382093681,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 4416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.car1997.cn/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-02-17T00:12:13.890595+010020126503Misc activity192.168.2.54971545.202.81.1980TCP
2025-02-17T00:12:14.180177+010020126503Misc activity192.168.2.54971545.202.81.1980TCP
2025-02-17T00:12:14.229485+010020126503Misc activity192.168.2.54971645.202.81.1980TCP
2025-02-17T00:12:16.294389+010020126503Misc activity192.168.2.54972645.202.81.1980TCP
2025-02-17T00:12:16.360981+010020126503Misc activity192.168.2.54972745.202.81.1980TCP
2025-02-17T00:12:28.088985+010020126503Misc activity192.168.2.54971645.202.81.1980TCP
2025-02-17T00:12:28.354592+010020126503Misc activity192.168.2.54972745.202.81.1980TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://www.car1997.cn/Avira URL Cloud: detection malicious, Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/leijingji.pngAvira URL Cloud: Label: phishing
Source: http://www.car1997.cn/@public/jquery.cdn.jsAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/betway.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/bet365.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/sansanqiqi.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/bwin.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/188jinbaobo.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/kaiyunbg.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/kaiyun.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/weide.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/tychongse.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/wlxe.pngAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/xinpujing.pngAvira URL Cloud: Label: phishing
Source: http://www.car1997.cn/vue.min.jsAvira URL Cloud: Label: phishing
Source: http://www.car1997.cn/favicon.icoAvira URL Cloud: Label: phishing
Source: https://1k4ej4j1lxvjwz.com/imgs/yongli.pngAvira URL Cloud: Label: phishing

Phishing

barindex
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203Joe Sandbox AI: Score: 7 Reasons: The brand 'Kaiyun' is not widely recognized, making it difficult to classify as 'known' or 'wellknown'., The URL 'www.zl5de9.vip' does not match the expected domain for any known brand, including 'Kaiyun'., The domain uses a '.vip' extension, which is unusual for legitimate business websites and can be a red flag., The URL contains a random string 'zl5de9', which is often a tactic used in phishing to create confusion., The presence of input fields for '' (username) and '' (password) suggests an attempt to collect sensitive information, which is common in phishing sites. DOM: 2.4.pages.csv
Source: 0.41.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://www.tvwxbvay.com/chat/chatClient/chatbox.j... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and the use of obfuscated URLs. The script writes an audio element to the page that loads from an untrusted domain, and it also writes an image tag that sends data to a suspicious tracking domain. Additionally, the script appears to load additional functionality and configuration from external sources, which could potentially introduce further risks. Overall, the combination of these behaviors indicates a high likelihood of malicious intent, warranting a high-risk score.
Source: 1.3..script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: http://www.car1997.cn/vue.min.js... This script demonstrates high-risk indicators, including dynamic code execution through the use of `eval()` and data exfiltration by sending user data to an external server. The script is also heavily obfuscated, making it difficult to analyze and understand its true purpose. Based on these factors, this script poses a high risk and should be treated with caution.
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: Number of links: 0
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: Total embedded image size: 15294
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: Base64 decoded: <svg width="205" height="80" xmlns="http://www.w3.org/2000/svg" version="1.1"/>
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: Title: does not match URL
Source: https://www.zl5de9.vip:8443/_next/static/chunks/pages/_app-ea96b16be7b82345.jsHTTP Parser: (self.webpackchunk_n_e=self.webpackchunk_n_e||[]).push([[2888],{3930:function(e,t,n){"use strict";var r=n(67294);t.z=function(e){const t=(0,r.useref)(e);return t.current=e,t}},45210:function(e,t,n){"use strict";var r=n(67294),i=n(3930),o=n(92770),a=n(31663);t.z=e=>{a.z&&((0,o.mf)(e)||console.error("useunmount expected parameter is a function, got "+typeof e));const t=(0,i.z)(e);(0,r.useeffect)((()=>()=>{t.current()}),[])}},8224:function(e,t,n){"use strict";function r(e,t){if(e===t)return!0;for(let n=0;n<e.length;n++)if(!object.is(e[n],t[n]))return!1;return!0}n.d(t,{z:function(){return r}})},48002:function(e,t,n){"use strict";n.d(t,{n:function(){return o}});var r=n(92770),i=n(52982);function o(e,t){if(!i.z)return;if(!e)return t;let n;return n=(0,r.mf)(e)?e():"current"in e?e.current:e,n}},92770:function(e,t,n){"use strict";n.d(t,{mf:function(){return r},hj:function(){return i},g7:function(){return o}});const r=e=>"function"===typeof e,i=e=>"number"===typeof e,o=e=>"undefined"===typeof e},52982:function(e,t){"us...
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: <input type="password" .../> found
Source: http://www.car1997.cn/HTTP Parser: No favicon
Source: http://www.car1997.cn/HTTP Parser: No favicon
Source: http://www.car1997.cn/HTTP Parser: No favicon
Source: http://www.car1997.cn/HTTP Parser: No favicon
Source: https://www.zl5de9.vip:8443/customer/mainHTTP Parser: No favicon
Source: https://www.zl5de9.vip:8443/customer/mainHTTP Parser: No favicon
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: No <meta name="author".. found
Source: https://www.zl5de9.vip:8443/register94366?i_code=45162203HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49751 version: TLS 1.0
Source: unknownNetwork traffic detected: IP country count 10
Source: Network trafficSuricata IDS: 2012650 - Severity 3 - ET MALWARE HTTP Request to a Malware Related Numerical .cn Domain : 192.168.2.5:49715 -> 45.202.81.19:80
Source: Network trafficSuricata IDS: 2012650 - Severity 3 - ET MALWARE HTTP Request to a Malware Related Numerical .cn Domain : 192.168.2.5:49726 -> 45.202.81.19:80
Source: Network trafficSuricata IDS: 2012650 - Severity 3 - ET MALWARE HTTP Request to a Malware Related Numerical .cn Domain : 192.168.2.5:49716 -> 45.202.81.19:80
Source: Network trafficSuricata IDS: 2012650 - Severity 3 - ET MALWARE HTTP Request to a Malware Related Numerical .cn Domain : 192.168.2.5:49727 -> 45.202.81.19:80
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49751 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKContent-Encoding: gzipContent-Length: 232Content-Type: text/javascriptServer: bfeDate: Sun, 16 Feb 2025 23:12:14 GMTData Raw: 1f 8b 08 00 00 00 00 00 00 ff 64 8f 41 6b bc 30 10 47 bf ca ae 07 49 50 27 ff eb 7f 25 48 e9 69 af 85 5e ba 59 4a 1a 47 0d ac 33 32 c6 0a 6d f7 bb 17 2b 3d f5 32 87 07 f3 1e bf 63 b7 50 48 91 49 e9 cf 77 2f 07 b4 46 5d 86 94 a6 af ed cc d7 93 33 ce 5c 7c f5 f1 50 bd fc ab fe bb 57 07 d7 c2 c1 9b 8f ed e2 20 f0 a8 4d 1f 4b b1 6b a4 96 57 b8 71 f0 9b 0d 06 c1 ae 64 db 72 58 46 a4 04 82 1d 8a a0 d4 b1 53 47 84 84 73 52 a2 f7 26 d9 cc 18 3f 45 98 07 2f b8 bb 37 b5 99 a1 8f 5d 56 73 a3 a8 b0 59 23 36 2b 90 02 b7 f8 fc 74 7e e4 71 62 42 4a ea 4f 43 97 92 e7 3f 2f f9 cd 66 85 68 7d fa 05 cd 0e ea 2d 9b 2c e1 7a 38 8f be c7 3a c1 2c c1 d2 fd ae f6 21 ba fe 0e 00 00 ff ff 97 51 90 77 19 01 00 00 Data Ascii: dAk0GIP'%Hi^YJG32m+=2cPHIw/F]3\|PW MKkWqdrXFSGsR&?E/7]VsY#6+t~qbBJOC?/fh}-,z8:,!Qw
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKContent-Encoding: gzipContent-Length: 232Content-Type: text/javascriptServer: bfeDate: Sun, 16 Feb 2025 23:12:16 GMTData Raw: 1f 8b 08 00 00 00 00 00 00 ff 64 8f 41 6b bc 30 10 47 bf ca ae 07 49 50 27 ff eb 7f 25 48 e9 69 af 85 5e ba 59 4a 1a 47 0d ac 33 32 c6 0a 6d f7 bb 17 2b 3d f5 32 87 07 f3 1e bf 63 b7 50 48 91 49 e9 cf 77 2f 07 b4 46 5d 86 94 a6 af ed cc d7 93 33 ce 5c 7c f5 f1 50 bd fc ab fe bb 57 07 d7 c2 c1 9b 8f ed e2 20 f0 a8 4d 1f 4b b1 6b a4 96 57 b8 71 f0 9b 0d 06 c1 ae 64 db 72 58 46 a4 04 82 1d 8a a0 d4 b1 53 47 84 84 73 52 a2 f7 26 d9 cc 18 3f 45 98 07 2f b8 bb 37 b5 99 a1 8f 5d 56 73 a3 a8 b0 59 23 36 2b 90 02 b7 f8 fc 74 7e e4 71 62 42 4a ea 4f 43 97 92 e7 3f 2f f9 cd 66 85 68 7d fa 05 cd 0e ea 2d 9b 2c e1 7a 38 8f be c7 3a c1 2c c1 d2 fd ae f6 21 ba fe 0e 00 00 ff ff 97 51 90 77 19 01 00 00 Data Ascii: dAk0GIP'%Hi^YJG32m+=2cPHIw/F]3\|PW MKkWqdrXFSGsR&?E/7]VsY#6+t~qbBJOC?/fh}-,z8:,!Qw
Source: global trafficHTTP traffic detected: GET /t010e288a56a0b005e9.png HTTP/1.1Host: p.ssl.qhimg.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.car1997.cn/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/baidu_jgylogo3.gif HTTP/1.1Host: www.baidu.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.car1997.cn/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /web/index/images/logo_440x140.v.4.png HTTP/1.1Host: www.sogou.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: http://www.car1997.cn/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/baidu_jgylogo3.gif HTTP/1.1Host: www.baidu.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: BAIDUID_BFESS=857A662155DBACB1908FD8017A6410E0:FG=1
Source: global trafficHTTP traffic detected: GET /web/index/images/logo_440x140.v.4.png HTTP/1.1Host: www.sogou.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: iframeReferer: http://www.car1997.cn/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /hylfff.php HTTP/1.1Host: vkg.hpdbfezgrqwn.vipConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /t010e288a56a0b005e9.png HTTP/1.1Host: p.ssl.qhimg.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/style.css HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/modalStyles.css HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /css/bootstrap.min.css HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /jquery.min.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /popper.min.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bootstrap.min.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /banner.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /quicklink.umd.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/bet365.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /popper.min.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /jquery.min.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bootstrap.min.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/bg.lanse.jpg HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/xinpujing.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/kaiyun.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /banner.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/wlxe.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /quicklink.umd.js HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/bwin.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/sansanqiqi.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/bet365.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/tychongse.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/kaiyun.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/weide.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/xinpujing.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/188jinbaobo.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/wlxe.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/betway.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/bg.lanse.jpg HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/gf.fc8d6758.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/bwin.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/sansanqiqi.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/banner/banner.365.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/weide.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/2025fajia.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/188jinbaobo.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/2025shiyunhui.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/2026shijiebei.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/tychongse.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/betway.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/banner/banner.365.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/yongli.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/leijingji.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/gf.fc8d6758.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/2025shiyunhui.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/2026shijiebei.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/2025fajia.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/yongli.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/leijingji.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/kaiyunbg.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://1k4ej4j1lxvjwz.com/css/modalStyles.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /imgs/kaiyunbg.png HTTP/1.1Host: 1k4ej4j1lxvjwz.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/new_public/web/bg/fd/cs/csm5shjo0aqpjis5iieg_434169.png HTTP/1.1Host: pos3img.uoenuvy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.zl5de9.vip:8443/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /resource/new_public/cc85pti1pc0ccap7dn7g_177735.png HTTP/1.1Host: pos3img.uoenuvy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.zl5de9.vip:8443/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /resource/new_public/cc85pti1pc0ccap7dn7g_177735.png HTTP/1.1Host: pos3img.uoenuvy.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/new_public/web/bg/fd/cs/csm5shjo0aqpjis5iieg_434169.png HTTP/1.1Host: pos3img.uoenuvy.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/chatbox.jsp?companyID=80002385&configID=508 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.zl5de9.vip:8443/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.css HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/css/robot-8b4e8abbaf.css HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/jquery_183-365c82f9bc.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/utility-ed58c4d655.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/changFunc-02d34b162b.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/scripts/robot.js?cv=6.7 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/sendImg.jsp?tm=1739747606074&scene=inner&lang=en HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/sendFile.jsp?tm=1739747606074&scene=inner&lang=en HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/closeClient.html HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/images/6_icon_common@2x-675956b127.png HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/fileSaver-54943d4103.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/scripts/robot.js?cv=6.7 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/changFunc-02d34b162b.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/utility-ed58c4d655.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/images/laba-c3ffd117f3.gif HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/jquery_183-365c82f9bc.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/style/traack.gif?pk=qXe8p716OpbBo8MWtTWz&_t=1739747608260 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/robot_new.js?v=1737320474350 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/media/sound.wav HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Accept-Encoding: identity;q=1, *;q=0sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: audioReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Language: en-US,en;q=0.9Range: bytes=0-
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/images/6_icon_common@2x-675956b127.png HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/fileSaver-54943d4103.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/images/laba-c3ffd117f3.gif HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/style/traack.gif?pk=qXe8p716OpbBo8MWtTWz&_t=1739747608260 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/robotmain-e7f470c07e.js HTTP/1.1Host: www.tvwxbvay.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /chat/chatClient/refactor/v6.0.1/dist/js/robot_new.js?v=1737320474350 HTTP/1.1Host: www.tvwxbvay.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /vue.min.js HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.car1997.cn/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=fa46o8tgrnl5aducvob8ld9jo3
Source: global trafficHTTP traffic detected: GET /@public/jquery.cdn.js HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.car1997.cn/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=fa46o8tgrnl5aducvob8ld9jo3
Source: global trafficHTTP traffic detected: GET /push.js HTTP/1.1Host: push.zhanzhang.baidu.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.car1997.cn/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /push.js HTTP/1.1Host: push.zhanzhang.baidu.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js-sdk-pro.min.js HTTP/1.1Host: sdk.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.car1997.cn/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /vue.min.js HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=fa46o8tgrnl5aducvob8ld9jo3
Source: global trafficHTTP traffic detected: GET /@public/jquery.cdn.js HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=fa46o8tgrnl5aducvob8ld9jo3
Source: global trafficHTTP traffic detected: GET /s.gif?l=http://www.car1997.cn/ HTTP/1.1Host: api.share.baidu.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.car1997.cn/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /s.gif?l=http://www.car1997.cn/ HTTP/1.1Host: api.share.baidu.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /js-sdk-pro.min.js HTTP/1.1Host: sdk.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v6/collect?dt=4 HTTP/1.1Host: collect-v6.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v6/collect?dt=4 HTTP/1.1Host: collect-v6.51.laConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.car1997.cn/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=fa46o8tgrnl5aducvob8ld9jo3; __vtins__KBYUa6ibFuUdP5LO=%7B%22sid%22%3A%20%22a5e3dee8-b16e-5d6c-a3bb-bb0289791781%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201739749336132%2C%20%22ct%22%3A%201739747536132%7D; __51uvsct__KBYUa6ibFuUdP5LO=1; __51vcke__KBYUa6ibFuUdP5LO=efbcd534-bac7-5f02-8184-486d35947751; __51vuft__KBYUa6ibFuUdP5LO=1739747536144; __vtins__KWVO4mchReU4dX3Z=%7B%22sid%22%3A%20%220b436359-7341-5d72-a8b0-e46e7b718d3c%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201739749336156%2C%20%22ct%22%3A%201739747536156%7D; __51uvsct__KWVO4mchReU4dX3Z=1; __51vcke__KWVO4mchReU4dX3Z=a4269168-83a1-58ec-9f63-da7e10a858f3; __51vuft__KWVO4mchReU4dX3Z=1739747536159; __vtins__KbndiYZgiSgoOHfs=%7B%22sid%22%3A%20%223265ac7a-0521-5c67-8c0e-5f9cf6af0a09%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201739749336174%2C%20%22ct%22%3A%201739747536174%7D; __51uvsct__KbndiYZgiSgoOHfs=1; __51vcke__KbndiYZgiSgoOHfs=a7e502ed-36ff-550a-8107-9584ee848047; __51vuft__KbndiYZgiSgoOHfs=1739747536180
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.car1997.cnConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=fa46o8tgrnl5aducvob8ld9jo3; __vtins__KBYUa6ibFuUdP5LO=%7B%22sid%22%3A%20%22a5e3dee8-b16e-5d6c-a3bb-bb0289791781%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201739749336132%2C%20%22ct%22%3A%201739747536132%7D; __51uvsct__KBYUa6ibFuUdP5LO=1; __51vcke__KBYUa6ibFuUdP5LO=efbcd534-bac7-5f02-8184-486d35947751; __51vuft__KBYUa6ibFuUdP5LO=1739747536144; __vtins__KWVO4mchReU4dX3Z=%7B%22sid%22%3A%20%220b436359-7341-5d72-a8b0-e46e7b718d3c%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201739749336156%2C%20%22ct%22%3A%201739747536156%7D; __51uvsct__KWVO4mchReU4dX3Z=1; __51vcke__KWVO4mchReU4dX3Z=a4269168-83a1-58ec-9f63-da7e10a858f3; __51vuft__KWVO4mchReU4dX3Z=1739747536159; __vtins__KbndiYZgiSgoOHfs=%7B%22sid%22%3A%20%223265ac7a-0521-5c67-8c0e-5f9cf6af0a09%22%2C%20%22vd%22%3A%201%2C%20%22stt%22%3A%200%2C%20%22dr%22%3A%200%2C%20%22expires%22%3A%201739749336174%2C%20%22ct%22%3A%201739747536174%7D; __51uvsct__KbndiYZgiSgoOHfs=1; __51vcke__KbndiYZgiSgoOHfs=a7e502ed-36ff-550a-8107-9584ee848047; __51vuft__KbndiYZgiSgoOHfs=1739747536180
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: kai196.vipConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: www.car1997.cn
Source: global trafficDNS traffic detected: DNS query: www.baidu.com
Source: global trafficDNS traffic detected: DNS query: vkg.hpdbfezgrqwn.vip
Source: global trafficDNS traffic detected: DNS query: www.sogou.com
Source: global trafficDNS traffic detected: DNS query: p.ssl.qhimg.com
Source: global trafficDNS traffic detected: DNS query: push.zhanzhang.baidu.com
Source: global trafficDNS traffic detected: DNS query: sdk.51.la
Source: global trafficDNS traffic detected: DNS query: api.share.baidu.com
Source: global trafficDNS traffic detected: DNS query: 1k4ej4j1lxvjwz.com
Source: global trafficDNS traffic detected: DNS query: collect-v6.51.la
Source: global trafficDNS traffic detected: DNS query: kai196.vip
Source: global trafficDNS traffic detected: DNS query: www.zl5de9.vip
Source: global trafficDNS traffic detected: DNS query: _8443._https.www.zl5de9.vip
Source: global trafficDNS traffic detected: DNS query: pos3img.uoenuvy.com
Source: global trafficDNS traffic detected: DNS query: www.tvwxbvay.com
Source: unknownHTTP traffic detected: POST /hylfff.php HTTP/1.1Host: vkg.hpdbfezgrqwn.vipConnection: keep-aliveContent-Length: 105sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/x-www-form-urlencoded;charset=UTF-8;Accept: */*Origin: http://www.car1997.cnSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: http://www.car1997.cn/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_392.2.drString found in binary or memory: http://12aff.best5689.com/92043302/signup/cs/index.html
Source: chromecache_392.2.drString found in binary or memory: http://kai196.vip
Source: chromecache_352.2.dr, chromecache_348.2.drString found in binary or memory: http://opensource.org/licenses/MIT).
Source: chromecache_392.2.drString found in binary or memory: https://0326018.cc
Source: chromecache_392.2.drString found in binary or memory: https://13413377.app
Source: chromecache_316.2.drString found in binary or memory: https://1k4ej4j1lxvjwz.com/
Source: chromecache_392.2.drString found in binary or memory: https://551007p.cc
Source: chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://665339c.com
Source: chromecache_392.2.drString found in binary or memory: https://665339c.com/wap/downloadApp?promoCode=e9VJBL
Source: chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://789400.cc/
Source: chromecache_392.2.drString found in binary or memory: https://99505n.cc
Source: chromecache_392.2.drString found in binary or memory: https://a43389.cc/
Source: chromecache_392.2.drString found in binary or memory: https://aff.kkcg8.com/sign-up/593325
Source: chromecache_392.2.drString found in binary or memory: https://app.geqianf261.top/s/bet365
Source: chromecache_392.2.drString found in binary or memory: https://app.geqianf261.top/s/bwyz
Source: chromecache_392.2.drString found in binary or memory: https://app.geqianf261.top/s/tyc
Source: chromecache_392.2.drString found in binary or memory: https://appiso-ali.ghgdfdf.com/?cGkxMl90NDA3MQ==&c=101105706293#/
Source: chromecache_392.2.drString found in binary or memory: https://cdn.livechatinc.com/tracking.js
Source: chromecache_387.2.drString found in binary or memory: https://chat.ybtest4.com/chat/
Source: chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://e977110.com
Source: chromecache_392.2.drString found in binary or memory: https://e977110.com/wap/downloadApp?promoCode=pK8XQc
Source: chromecache_401.2.dr, chromecache_380.2.dr, chromecache_399.2.drString found in binary or memory: https://getbootstrap.com/)
Source: chromecache_401.2.dr, chromecache_380.2.dr, chromecache_399.2.drString found in binary or memory: https://github.com/twbs/bootstrap/blob/main/LICENSE)
Source: chromecache_380.2.dr, chromecache_399.2.drString found in binary or memory: https://github.com/twbs/bootstrap/graphs/contributors)
Source: chromecache_392.2.drString found in binary or memory: https://guwu.fun/download
Source: chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://l21714.com
Source: chromecache_392.2.drString found in binary or memory: https://l21714.com/wap/downloadApp?promoCode=XPMJTR
Source: chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://l933004.com
Source: chromecache_392.2.drString found in binary or memory: https://lucky298.com/vsgl
Source: chromecache_354.2.dr, chromecache_463.2.drString found in binary or memory: https://lucky298.com/vsglat
Source: chromecache_392.2.drString found in binary or memory: https://lucky298.com/vsglib
Source: chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://p399224.com
Source: chromecache_392.2.drString found in binary or memory: https://parimatchasia.onelink.me/nec7/949ac8d5?
Source: chromecache_392.2.drString found in binary or memory: https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_1722c_&affid=2017190&siteid=18017&adid=1722&c=
Source: chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_2464c_&affid=2017190&siteid=18017&adid=2464&c=
Source: chromecache_392.2.drString found in binary or memory: https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_2484c_&affid=2017190&siteid=18017&adid=2484&c=
Source: chromecache_392.2.drString found in binary or memory: https://wros8.top/vjS2
Source: chromecache_392.2.drString found in binary or memory: https://www.4a0kzf.com/Yvj3
Source: chromecache_392.2.drString found in binary or memory: https://www.bvty894.com:30122/entry/register?i_code=2270535
Source: chromecache_458.2.drString found in binary or memory: https://www.live800.com
Source: chromecache_392.2.drString found in binary or memory: https://www.livechat.com/?welcome
Source: chromecache_392.2.drString found in binary or memory: https://www.livechat.com/chat-with/15900159/
Source: chromecache_392.2.drString found in binary or memory: https://www.ljjapp3.com/?601158
Source: chromecache_452.2.drString found in binary or memory: https://www.nextjs.cn/docs/basic-features/static-file-serving
Source: chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drString found in binary or memory: https://www.ray061.com/?601158
Source: chromecache_392.2.drString found in binary or memory: https://www.ss52611.com/vip.html?c=88003698540
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/images/operator.png
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/images/robot.png
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/images/visitor.png
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/scripts/robot.js?cv=6.7
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/robot-8b4e8abbaf.css
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.css
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/images/favicon.ico
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/catchScreen-3b7802a171.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/changFunc-02d34b162b.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/client_style1-915f2cd77f.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/fileSaver-54943d4103.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/jquery_183-365c82f9bc.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/media-f312af5fef.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/utility-ed58c4d655.js
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/media/sound.wav
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/style/ad_style1.png
Source: chromecache_458.2.drString found in binary or memory: https://www.tvwxbvay.com/chat/chatClient/style/logo-style1.png
Source: chromecache_392.2.drString found in binary or memory: https://www.xivev6.com:9056/entry/register37012/?i_code=30114312
Source: chromecache_392.2.drString found in binary or memory: https://wy-ali.meriksenrusso.com/wx/app/proxy-qrcode.html?url=aHR0cHM6Ly9hcHBpc28tdHkuc291emhhbnp4Lm
Source: chromecache_392.2.drString found in binary or memory: https://wy-ali.meriksenrusso.com/wx/app/proxy-qrcode.html?url=aHR0cHM6Ly9hcHBpc28tdHkuenZiempzYi5jb2
Source: chromecache_392.2.drString found in binary or memory: https://xj206.cc/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50058
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50057
Source: unknownNetwork traffic detected: HTTP traffic on port 50102 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 50085 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50091 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50113 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50057 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50082
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50085
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50084
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50087
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50086
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50089
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50088
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50090
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50092
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50091
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50094
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50093
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50096
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50095
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 50090 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50095 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50103 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50084 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50110 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50089 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50043
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50044
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50109 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50044 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 50094 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50105
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50108
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50109
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50100
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50102
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50101
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50104
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50103
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50088 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50111
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50110
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50113
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50112
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50099 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50100 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 50093 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50111 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50082 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50105 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50098
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50097
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50099
Source: unknownNetwork traffic detected: HTTP traffic on port 50112 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 50087 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50098 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 50086 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50092 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50058 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50097 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
Source: unknownNetwork traffic detected: HTTP traffic on port 50101 -> 443
Source: classification engineClassification label: mal68.phis.win@19/381@69/22
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2296,i,1317288127873804294,14328008075382093681,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.car1997.cn/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2388 --field-trial-handle=2296,i,1317288127873804294,14328008075382093681,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Scripting
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
Logon Script (Windows)1
Deobfuscate/Decode Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.car1997.cn/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://chat.ybtest4.com/chat/0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/images/robot.png0%Avira URL Cloudsafe
https://www.nextjs.cn/docs/basic-features/static-file-serving0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/catchScreen-3b7802a171.js0%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/leijingji.png100%Avira URL Cloudphishing
http://www.car1997.cn/@public/jquery.cdn.js100%Avira URL Cloudphishing
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/sendImg.jsp?tm=1739747606074&scene=inner&lang=en0%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/betway.png100%Avira URL Cloudphishing
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/robot_new.js?v=17373204743500%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/bet365.png100%Avira URL Cloudphishing
https://1k4ej4j1lxvjwz.com/imgs/sansanqiqi.png100%Avira URL Cloudphishing
https://app.geqianf261.top/s/bwyz0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.css0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/style/traack.gif?pk=qXe8p716OpbBo8MWtTWz&_t=17397476082600%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/utility-ed58c4d655.js0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/robot-8b4e8abbaf.css0%Avira URL Cloudsafe
https://p399224.com0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/images/operator.png0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/scripts/robot.js?cv=6.70%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/bwin.png100%Avira URL Cloudphishing
https://1k4ej4j1lxvjwz.com/imgs/188jinbaobo.png100%Avira URL Cloudphishing
https://1k4ej4j1lxvjwz.com/imgs/kaiyunbg.png100%Avira URL Cloudphishing
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/images/6_icon_common@2x-675956b127.png0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=5080%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/robotmain-e7f470c07e.js0%Avira URL Cloudsafe
https://app.geqianf261.top/s/bet3650%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/closeClient.html0%Avira URL Cloudsafe
https://13413377.app0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/style/logo-style1.png0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/changFunc-02d34b162b.js0%Avira URL Cloudsafe
https://www.ray061.com/?6011580%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/client_style1-915f2cd77f.js0%Avira URL Cloudsafe
https://pos3img.uoenuvy.com/images/new_public/web/bg/fd/cs/csm5shjo0aqpjis5iieg_434169.png0%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/kaiyun.png100%Avira URL Cloudphishing
https://l933004.com0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/jquery_183-365c82f9bc.js0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/images/visitor.png0%Avira URL Cloudsafe
https://l21714.com0%Avira URL Cloudsafe
https://vkg.hpdbfezgrqwn.vip/hylfff.php0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/media/sound.wav0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/media-f312af5fef.js0%Avira URL Cloudsafe
https://www.live800.com0%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/weide.png100%Avira URL Cloudphishing
http://kai196.vip0%Avira URL Cloudsafe
https://1k4ej4j1lxvjwz.com/imgs/tychongse.png100%Avira URL Cloudphishing
https://1k4ej4j1lxvjwz.com/imgs/wlxe.png100%Avira URL Cloudphishing
https://1k4ej4j1lxvjwz.com/imgs/xinpujing.png100%Avira URL Cloudphishing
https://pos3img.uoenuvy.com/resource/new_public/cc85pti1pc0ccap7dn7g_177735.png0%Avira URL Cloudsafe
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/images/laba-c3ffd117f3.gif0%Avira URL Cloudsafe
https://551007p.cc0%Avira URL Cloudsafe
http://www.car1997.cn/vue.min.js100%Avira URL Cloudphishing
https://www.ljjapp3.com/?6011580%Avira URL Cloudsafe
http://www.car1997.cn/favicon.ico100%Avira URL Cloudphishing
https://1k4ej4j1lxvjwz.com/imgs/yongli.png100%Avira URL Cloudphishing
https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/fileSaver-54943d4103.js0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
share.n.shifen.com
182.61.201.94
truefalse
    high
    1k4ej4j1lxvjwz.com
    122.10.50.210
    truefalse
      high
      p.ssl.qhimg.com.cdn20.com
      163.171.146.42
      truefalse
        unknown
        hcdnwsa120.v5.cdnhwczoy106.cn
        90.84.161.15
        truefalse
          high
          api.share.n.shifen.com
          180.101.212.103
          truefalse
            high
            cdn-260-cdn-260-e34-ws.fastliii.com
            175.29.222.233
            truefalse
              unknown
              vkg.hpdbfezgrqwn.vip
              122.10.26.202
              truefalse
                high
                kai196.vip
                202.181.1.204
                truefalse
                  unknown
                  www.car1997.cn
                  45.202.81.19
                  truetrue
                    unknown
                    cdn-260-cdn-260-a19-ss.fastliii.com
                    154.89.50.147
                    truefalse
                      unknown
                      www.wshifen.com
                      103.235.46.96
                      truefalse
                        high
                        d3h3opd4qa0dfk.cloudfront.net
                        13.32.121.43
                        truefalse
                          unknown
                          www.google.com
                          172.217.18.4
                          truefalse
                            high
                            ucloud-internal.v.ucnaming.com
                            36.27.222.246
                            truefalse
                              unknown
                              www.sogou.com
                              43.153.236.147
                              truefalse
                                high
                                a1143.dscb.akamai.net
                                2.16.164.91
                                truefalse
                                  unknown
                                  push.zhanzhang.baidu.com
                                  unknown
                                  unknownfalse
                                    high
                                    _8443._https.www.zl5de9.vip
                                    unknown
                                    unknownfalse
                                      unknown
                                      collect-v6.51.la
                                      unknown
                                      unknownfalse
                                        high
                                        www.baidu.com
                                        unknown
                                        unknownfalse
                                          high
                                          p.ssl.qhimg.com
                                          unknown
                                          unknownfalse
                                            high
                                            api.share.baidu.com
                                            unknown
                                            unknownfalse
                                              high
                                              www.tvwxbvay.com
                                              unknown
                                              unknowntrue
                                                unknown
                                                pos3img.uoenuvy.com
                                                unknown
                                                unknownfalse
                                                  unknown
                                                  www.zl5de9.vip
                                                  unknown
                                                  unknowntrue
                                                    unknown
                                                    sdk.51.la
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      NameMaliciousAntivirus DetectionReputation
                                                      https://www.zl5de9.vip:8443/other/restrictionIp?name=access-caveatfalse
                                                        unknown
                                                        https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/sendImg.jsp?tm=1739747606074&scene=inner&lang=enfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/robot_new.js?v=1737320474350false
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://www.car1997.cn/@public/jquery.cdn.jstrue
                                                        • Avira URL Cloud: phishing
                                                        unknown
                                                        https://www.zl5de9.vip:8443/customer/mainfalse
                                                          unknown
                                                          https://1k4ej4j1lxvjwz.com/imgs/leijingji.pngfalse
                                                          • Avira URL Cloud: phishing
                                                          unknown
                                                          https://www.sogou.com/web/index/images/logo_440x140.v.4.pngfalse
                                                            high
                                                            https://1k4ej4j1lxvjwz.com/css/style.cssfalse
                                                              high
                                                              https://1k4ej4j1lxvjwz.com/imgs/betway.pngfalse
                                                              • Avira URL Cloud: phishing
                                                              unknown
                                                              https://p.ssl.qhimg.com/t010e288a56a0b005e9.pngfalse
                                                                high
                                                                https://1k4ej4j1lxvjwz.com/imgs/bet365.pngfalse
                                                                • Avira URL Cloud: phishing
                                                                unknown
                                                                https://1k4ej4j1lxvjwz.com/bootstrap.min.jsfalse
                                                                  high
                                                                  https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/robot-8b4e8abbaf.cssfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/utility-ed58c4d655.jsfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://www.tvwxbvay.com/chat/chatClient/style/traack.gif?pk=qXe8p716OpbBo8MWtTWz&_t=1739747608260false
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://1k4ej4j1lxvjwz.com/imgs/sansanqiqi.pngfalse
                                                                  • Avira URL Cloud: phishing
                                                                  unknown
                                                                  https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.cssfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  https://1k4ej4j1lxvjwz.com/popper.min.jsfalse
                                                                    high
                                                                    https://www.tvwxbvay.com/chat/chatClient/refactor/scripts/robot.js?cv=6.7false
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://1k4ej4j1lxvjwz.com/imgs/bwin.pngfalse
                                                                    • Avira URL Cloud: phishing
                                                                    unknown
                                                                    https://1k4ej4j1lxvjwz.com/imgs/188jinbaobo.pngfalse
                                                                    • Avira URL Cloud: phishing
                                                                    unknown
                                                                    https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/robotmain-e7f470c07e.jsfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://1k4ej4j1lxvjwz.com/imgs/kaiyunbg.pngfalse
                                                                    • Avira URL Cloud: phishing
                                                                    unknown
                                                                    https://1k4ej4j1lxvjwz.com/quicklink.umd.jsfalse
                                                                      high
                                                                      https://www.tvwxbvay.com/chat/chatClient/chatbox.jsp?companyID=80002385&configID=508false
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/images/6_icon_common@2x-675956b127.pngfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/closeClient.htmlfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://1k4ej4j1lxvjwz.com/imgs/bg.lanse.jpgfalse
                                                                        high
                                                                        https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/changFunc-02d34b162b.jsfalse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://1k4ej4j1lxvjwz.com/css/modalStyles.cssfalse
                                                                          high
                                                                          https://pos3img.uoenuvy.com/images/new_public/web/bg/fd/cs/csm5shjo0aqpjis5iieg_434169.pngfalse
                                                                          • Avira URL Cloud: safe
                                                                          unknown
                                                                          https://www.zl5de9.vip:8443/register94366?i_code=45162203true
                                                                            unknown
                                                                            https://1k4ej4j1lxvjwz.com/imgs/kaiyun.pngfalse
                                                                            • Avira URL Cloud: phishing
                                                                            unknown
                                                                            https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/jquery_183-365c82f9bc.jsfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://vkg.hpdbfezgrqwn.vip/hylfff.phpfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/media/sound.wavfalse
                                                                            • Avira URL Cloud: safe
                                                                            unknown
                                                                            https://1k4ej4j1lxvjwz.com/imgs/weide.pngfalse
                                                                            • Avira URL Cloud: phishing
                                                                            unknown
                                                                            http://api.share.baidu.com/s.gif?l=http://www.car1997.cn/false
                                                                              high
                                                                              https://1k4ej4j1lxvjwz.com/imgs/2025shiyunhui.pngfalse
                                                                                high
                                                                                http://push.zhanzhang.baidu.com/push.jsfalse
                                                                                  high
                                                                                  https://1k4ej4j1lxvjwz.com/imgs/tychongse.pngfalse
                                                                                  • Avira URL Cloud: phishing
                                                                                  unknown
                                                                                  https://1k4ej4j1lxvjwz.com/imgs/2025fajia.pngfalse
                                                                                    high
                                                                                    https://pos3img.uoenuvy.com/resource/new_public/cc85pti1pc0ccap7dn7g_177735.pngfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://sdk.51.la/js-sdk-pro.min.jsfalse
                                                                                      high
                                                                                      https://1k4ej4j1lxvjwz.com/imgs/wlxe.pngfalse
                                                                                      • Avira URL Cloud: phishing
                                                                                      unknown
                                                                                      https://1k4ej4j1lxvjwz.com/false
                                                                                        high
                                                                                        https://1k4ej4j1lxvjwz.com/imgs/xinpujing.pngfalse
                                                                                        • Avira URL Cloud: phishing
                                                                                        unknown
                                                                                        https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/images/laba-c3ffd117f3.giffalse
                                                                                        • Avira URL Cloud: safe
                                                                                        unknown
                                                                                        http://www.car1997.cn/vue.min.jstrue
                                                                                        • Avira URL Cloud: phishing
                                                                                        unknown
                                                                                        http://www.car1997.cn/favicon.icotrue
                                                                                        • Avira URL Cloud: phishing
                                                                                        unknown
                                                                                        https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/fileSaver-54943d4103.jsfalse
                                                                                        • Avira URL Cloud: safe
                                                                                        unknown
                                                                                        https://1k4ej4j1lxvjwz.com/imgs/yongli.pngfalse
                                                                                        • Avira URL Cloud: phishing
                                                                                        unknown
                                                                                        NameSourceMaliciousAntivirus DetectionReputation
                                                                                        https://www.nextjs.cn/docs/basic-features/static-file-servingchromecache_452.2.drfalse
                                                                                        • Avira URL Cloud: safe
                                                                                        unknown
                                                                                        https://www.4a0kzf.com/Yvj3chromecache_392.2.drfalse
                                                                                          high
                                                                                          https://e977110.comchromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                            high
                                                                                            https://www.tvwxbvay.com/chat/chatClient/images/robot.pngchromecache_458.2.drfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://chat.ybtest4.com/chat/chromecache_387.2.drfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/catchScreen-3b7802a171.jschromecache_458.2.drfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://appiso-ali.ghgdfdf.com/?cGkxMl90NDA3MQ==&c=101105706293#/chromecache_392.2.drfalse
                                                                                              high
                                                                                              https://www.livechat.com/chat-with/15900159/chromecache_392.2.drfalse
                                                                                                high
                                                                                                https://xj206.cc/chromecache_392.2.drfalse
                                                                                                  high
                                                                                                  https://www.tvwxbvay.com/chat/chatClient/images/operator.pngchromecache_458.2.drfalse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  https://app.geqianf261.top/s/bwyzchromecache_392.2.drfalse
                                                                                                  • Avira URL Cloud: safe
                                                                                                  unknown
                                                                                                  https://789400.cc/chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                    high
                                                                                                    https://github.com/twbs/bootstrap/graphs/contributors)chromecache_380.2.dr, chromecache_399.2.drfalse
                                                                                                      high
                                                                                                      https://p399224.comchromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                      • Avira URL Cloud: safe
                                                                                                      unknown
                                                                                                      https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_1722c_&affid=2017190&siteid=18017&adid=1722&c=chromecache_392.2.drfalse
                                                                                                        high
                                                                                                        http://opensource.org/licenses/MIT).chromecache_352.2.dr, chromecache_348.2.drfalse
                                                                                                          high
                                                                                                          https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/chromecache_458.2.drfalse
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          https://parimatchasia.onelink.me/nec7/949ac8d5?chromecache_392.2.drfalse
                                                                                                            high
                                                                                                            https://cdn.livechatinc.com/tracking.jschromecache_392.2.drfalse
                                                                                                              high
                                                                                                              https://www.tvwxbvay.com/chat/chatClient/style/logo-style1.pngchromecache_458.2.drfalse
                                                                                                              • Avira URL Cloud: safe
                                                                                                              unknown
                                                                                                              http://12aff.best5689.com/92043302/signup/cs/index.htmlchromecache_392.2.drfalse
                                                                                                                high
                                                                                                                https://13413377.appchromecache_392.2.drfalse
                                                                                                                • Avira URL Cloud: safe
                                                                                                                unknown
                                                                                                                https://0326018.ccchromecache_392.2.drfalse
                                                                                                                  high
                                                                                                                  https://app.geqianf261.top/s/bet365chromecache_392.2.drfalse
                                                                                                                  • Avira URL Cloud: safe
                                                                                                                  unknown
                                                                                                                  https://www.ray061.com/?601158chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                                  • Avira URL Cloud: safe
                                                                                                                  unknown
                                                                                                                  https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/client_style1-915f2cd77f.jschromecache_458.2.drfalse
                                                                                                                  • Avira URL Cloud: safe
                                                                                                                  unknown
                                                                                                                  https://www.tvwxbvay.com/chat/chatClient/images/visitor.pngchromecache_458.2.drfalse
                                                                                                                  • Avira URL Cloud: safe
                                                                                                                  unknown
                                                                                                                  https://www.ss52611.com/vip.html?c=88003698540chromecache_392.2.drfalse
                                                                                                                    high
                                                                                                                    https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_2484c_&affid=2017190&siteid=18017&adid=2484&c=chromecache_392.2.drfalse
                                                                                                                      high
                                                                                                                      https://aff.kkcg8.com/sign-up/593325chromecache_392.2.drfalse
                                                                                                                        high
                                                                                                                        https://l933004.comchromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                                        • Avira URL Cloud: safe
                                                                                                                        unknown
                                                                                                                        https://665339c.com/wap/downloadApp?promoCode=e9VJBLchromecache_392.2.drfalse
                                                                                                                          high
                                                                                                                          https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_2464c_&affid=2017190&siteid=18017&adid=2464&c=chromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                                            high
                                                                                                                            https://www.bvty894.com:30122/entry/register?i_code=2270535chromecache_392.2.drfalse
                                                                                                                              high
                                                                                                                              https://665339c.comchromecache_354.2.dr, chromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                                                high
                                                                                                                                https://l21714.comchromecache_463.2.dr, chromecache_392.2.drfalse
                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                unknown
                                                                                                                                https://www.live800.comchromecache_458.2.drfalse
                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                unknown
                                                                                                                                https://wy-ali.meriksenrusso.com/wx/app/proxy-qrcode.html?url=aHR0cHM6Ly9hcHBpc28tdHkuenZiempzYi5jb2chromecache_392.2.drfalse
                                                                                                                                  high
                                                                                                                                  https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/media-f312af5fef.jschromecache_458.2.drfalse
                                                                                                                                  • Avira URL Cloud: safe
                                                                                                                                  unknown
                                                                                                                                  https://lucky298.com/vsglatchromecache_354.2.dr, chromecache_463.2.drfalse
                                                                                                                                    high
                                                                                                                                    http://kai196.vipchromecache_392.2.drfalse
                                                                                                                                    • Avira URL Cloud: safe
                                                                                                                                    unknown
                                                                                                                                    https://e977110.com/wap/downloadApp?promoCode=pK8XQcchromecache_392.2.drfalse
                                                                                                                                      high
                                                                                                                                      https://www.ljjapp3.com/?601158chromecache_392.2.drfalse
                                                                                                                                      • Avira URL Cloud: safe
                                                                                                                                      unknown
                                                                                                                                      https://551007p.ccchromecache_392.2.drfalse
                                                                                                                                      • Avira URL Cloud: safe
                                                                                                                                      unknown
                                                                                                                                      https://guwu.fun/downloadchromecache_392.2.drfalse
                                                                                                                                        high
                                                                                                                                        https://a43389.cc/chromecache_392.2.drfalse
                                                                                                                                          high
                                                                                                                                          https://wros8.top/vjS2chromecache_392.2.drfalse
                                                                                                                                            high
                                                                                                                                            https://wy-ali.meriksenrusso.com/wx/app/proxy-qrcode.html?url=aHR0cHM6Ly9hcHBpc28tdHkuc291emhhbnp4Lmchromecache_392.2.drfalse
                                                                                                                                              high
                                                                                                                                              • No. of IPs < 25%
                                                                                                                                              • 25% < No. of IPs < 50%
                                                                                                                                              • 50% < No. of IPs < 75%
                                                                                                                                              • 75% < No. of IPs
                                                                                                                                              IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                              2.16.202.83
                                                                                                                                              unknownEuropean Union
                                                                                                                                              16625AKAMAI-ASUSfalse
                                                                                                                                              182.61.201.94
                                                                                                                                              share.n.shifen.comChina
                                                                                                                                              38365BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtdfalse
                                                                                                                                              14.215.182.161
                                                                                                                                              unknownChina
                                                                                                                                              58466CT-GUANGZHOU-IDCCHINANETGuangdongprovincenetworkCNfalse
                                                                                                                                              122.10.26.202
                                                                                                                                              vkg.hpdbfezgrqwn.vipHong Kong
                                                                                                                                              139817GIGALINK-AS-APHONGKONGGIGALINKNETWORKLIMITEDHKfalse
                                                                                                                                              175.29.222.233
                                                                                                                                              cdn-260-cdn-260-e34-ws.fastliii.comBangladesh
                                                                                                                                              134548DXTL-HKDXTLTseungKwanOServiceHKfalse
                                                                                                                                              103.235.46.96
                                                                                                                                              www.wshifen.comHong Kong
                                                                                                                                              55967BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtdfalse
                                                                                                                                              202.181.1.204
                                                                                                                                              kai196.vipHong Kong
                                                                                                                                              7587ACCESSNETWORKSTRANSMEDIA-IDfalse
                                                                                                                                              45.202.81.19
                                                                                                                                              www.car1997.cnSeychelles
                                                                                                                                              139086ONL-HKOCEANNETWORKLIMITEDHKtrue
                                                                                                                                              122.10.50.210
                                                                                                                                              1k4ej4j1lxvjwz.comHong Kong
                                                                                                                                              134548DXTL-HKDXTLTseungKwanOServiceHKfalse
                                                                                                                                              13.32.121.43
                                                                                                                                              d3h3opd4qa0dfk.cloudfront.netUnited States
                                                                                                                                              16509AMAZON-02USfalse
                                                                                                                                              180.101.212.103
                                                                                                                                              api.share.n.shifen.comChina
                                                                                                                                              134770CHINANET-JIANGSU-SUZHOU-NETWORKCHINANETJiangsuprovinceSufalse
                                                                                                                                              90.84.161.15
                                                                                                                                              hcdnwsa120.v5.cdnhwczoy106.cnFrance
                                                                                                                                              5511OPENTRANSITFRfalse
                                                                                                                                              148.153.240.66
                                                                                                                                              unknownUnited States
                                                                                                                                              63199CDSC-AS1USfalse
                                                                                                                                              90.84.161.18
                                                                                                                                              unknownFrance
                                                                                                                                              5511OPENTRANSITFRfalse
                                                                                                                                              2.16.164.91
                                                                                                                                              a1143.dscb.akamai.netEuropean Union
                                                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                                                              172.217.18.4
                                                                                                                                              www.google.comUnited States
                                                                                                                                              15169GOOGLEUSfalse
                                                                                                                                              239.255.255.250
                                                                                                                                              unknownReserved
                                                                                                                                              unknownunknownfalse
                                                                                                                                              154.89.50.147
                                                                                                                                              cdn-260-cdn-260-a19-ss.fastliii.comSeychelles
                                                                                                                                              132839POWERLINE-AS-APPOWERLINEDATACENTERHKfalse
                                                                                                                                              163.171.146.42
                                                                                                                                              p.ssl.qhimg.com.cdn20.comEuropean Union
                                                                                                                                              54994QUANTILNETWORKSUSfalse
                                                                                                                                              43.153.236.147
                                                                                                                                              www.sogou.comJapan4249LILLY-ASUSfalse
                                                                                                                                              IP
                                                                                                                                              192.168.2.6
                                                                                                                                              192.168.2.5
                                                                                                                                              Joe Sandbox version:42.0.0 Malachite
                                                                                                                                              Analysis ID:1616519
                                                                                                                                              Start date and time:2025-02-17 00:11:12 +01:00
                                                                                                                                              Joe Sandbox product:CloudBasic
                                                                                                                                              Overall analysis duration:0h 3m 28s
                                                                                                                                              Hypervisor based Inspection enabled:false
                                                                                                                                              Report type:full
                                                                                                                                              Cookbook file name:browseurl.jbs
                                                                                                                                              Sample URL:http://www.car1997.cn/
                                                                                                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                              Number of analysed new started processes analysed:7
                                                                                                                                              Number of new started drivers analysed:0
                                                                                                                                              Number of existing processes analysed:0
                                                                                                                                              Number of existing drivers analysed:0
                                                                                                                                              Number of injected processes analysed:0
                                                                                                                                              Technologies:
                                                                                                                                              • HCA enabled
                                                                                                                                              • EGA enabled
                                                                                                                                              • AMSI enabled
                                                                                                                                              Analysis Mode:default
                                                                                                                                              Analysis stop reason:Timeout
                                                                                                                                              Detection:MAL
                                                                                                                                              Classification:mal68.phis.win@19/381@69/22
                                                                                                                                              EGA Information:Failed
                                                                                                                                              HCA Information:
                                                                                                                                              • Successful, ratio: 100%
                                                                                                                                              • Number of executed functions: 0
                                                                                                                                              • Number of non-executed functions: 0
                                                                                                                                              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                                                                                                                                              • Excluded IPs from analysis (whitelisted): 142.250.185.99, 142.250.186.78, 64.233.167.84, 142.250.185.174, 142.250.186.174, 172.217.18.110, 142.250.184.202, 172.217.18.106, 172.217.16.138, 142.250.185.170, 142.250.184.234, 142.250.185.74, 142.250.186.106, 172.217.16.202, 142.250.186.42, 142.250.186.170, 172.217.18.10, 172.217.23.106, 142.250.185.138, 142.250.186.138, 142.250.185.106, 142.250.186.74, 199.232.210.172, 184.30.131.245, 142.250.186.142, 142.250.186.46, 216.58.206.78, 142.250.186.110, 142.250.74.202, 216.58.206.42, 142.250.185.202, 142.250.185.234, 142.250.181.234, 216.58.206.74, 142.250.184.195, 142.250.185.78, 142.250.184.238, 199.232.214.172, 2.18.97.153, 172.202.163.200, 13.107.246.45
                                                                                                                                              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                                                                                                                                              • Not all processes where analyzed, report is missing behavior information
                                                                                                                                              • Report size exceeded maximum capacity and may have missing network information.
                                                                                                                                              • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                              • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                              • VT rate limit hit for: http://www.car1997.cn/
                                                                                                                                              No simulations
                                                                                                                                              No context
                                                                                                                                              No context
                                                                                                                                              No context
                                                                                                                                              No context
                                                                                                                                              No context
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Feb 16 22:12:08 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2677
                                                                                                                                              Entropy (8bit):3.980755149780353
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:8pdTTbrqHVidAKZdA19ehwiZUklqehTy+3:8PjwIy
                                                                                                                                              MD5:5EF67B15B41A4123DE450FA1EA6018A0
                                                                                                                                              SHA1:A6FBF32A2FD16505878EE5FDAC4B9E3644A5EBE9
                                                                                                                                              SHA-256:AF5119928EE5DAC292CB893771E85D3B1F8C2C821CF54EAF4CD3FD95E5A0C2DE
                                                                                                                                              SHA-512:000F0AA4BE6DF629E051D9D8DE8A29B6F581DA6C7AF06BFF2AA55691EABC0E582DC5963E209C7FDDC4BD6B7079EA696E4E0B91305F1F324453BEAFA4284A092D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:L..................F.@.. ...$+.,......[3...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPZ......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPZ......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPZ......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPZ............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPZ.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........>........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Feb 16 22:12:07 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2679
                                                                                                                                              Entropy (8bit):3.995513844695449
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:8hdTTbrqHVidAKZdA1weh/iZUkAQkqeh4y+2:83jK9Q1y
                                                                                                                                              MD5:606E38AB77B5C617452EDC424E30BCDA
                                                                                                                                              SHA1:6F52FAE02B44B07BF0A6BC3F0DE675E2A1E09E66
                                                                                                                                              SHA-256:612AA6130C349DE67E2554755E907A0BFB00518DC19C8879D46567FF1EEB769B
                                                                                                                                              SHA-512:A8E73D6702B7F2D9CE67113CEF903E60890BB9C0E540FD30F96A6805FD8E49F7145AC90B8F690E23A6001F033EB60275C46F46C8839D9A4BF13758ED208E94DA
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:L..................F.@.. ...$+.,......K3...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPZ......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPZ......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPZ......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPZ............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPZ.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........>........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2693
                                                                                                                                              Entropy (8bit):4.006668410181268
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:8x8dTTbrsHVidAKZdA14tseh7sFiZUkmgqeh7s6y+BX:8x8j8nUy
                                                                                                                                              MD5:0261C7231470F6AEDE9E78A7482FEBCB
                                                                                                                                              SHA1:792D4ECB4400F988047577FEA44EA2701608E88D
                                                                                                                                              SHA-256:9E481C155A1324B0D07F28BCBA442DC360FEC2F2DEB1A0E54E0D08C0ACB65103
                                                                                                                                              SHA-512:D3DDF411FD51076C4AF9DC5D82C6CCE373F3273F417CEB7296FA5D364539D021809F55987B26F801520AEA1FC0287366195162B30D9B2E4A5E960A48B2EE0A6C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPZ......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPZ......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPZ......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPZ............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........>........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Feb 16 22:12:07 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2681
                                                                                                                                              Entropy (8bit):3.9938181728677105
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:84dTTbrqHVidAKZdA1vehDiZUkwqeh8y+R:8ojRCy
                                                                                                                                              MD5:6550324A9861962335F824651E4256B0
                                                                                                                                              SHA1:0D89175157630C4CA752E93C2D14DD2B830EFD61
                                                                                                                                              SHA-256:52287E0A8D41C7B5AED556B5A8384DD5168F9A1795C9F3B6D338A64BAD25B674
                                                                                                                                              SHA-512:2E926355D0B8CAF8FD0D66330A737F2EA9274E5D33315634E15686744535EEE35000A0DB06D1620872DBCF9EA172B2A3E2C064FBB58FB327A6A558A9CF7CB481
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:L..................F.@.. ...$+.,....W[F3...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPZ......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPZ......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPZ......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPZ............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPZ.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........>........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Feb 16 22:12:08 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2681
                                                                                                                                              Entropy (8bit):3.984368060361888
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:8GdTTbrqHVidAKZdA1hehBiZUk1W1qehGy+C:8ajx9my
                                                                                                                                              MD5:331B91090BA7CAA88B2FEB332086E9D9
                                                                                                                                              SHA1:EDE64773775884F3435004A18FB9A335E4170462
                                                                                                                                              SHA-256:847B95D0E91CE258A18A4BD1EEE777DD6845E8C58EBD8130F1F26774DD2A9F0E
                                                                                                                                              SHA-512:F392164DFDF6B62DA5862B67E08A42F6202DABA02553E66D305B46B304F6693FC9A294B7170FC8C63CB81B87BF8204FC5BF5DB33D792CD0DD7325008F5972E89
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:L..................F.@.. ...$+.,......T3...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPZ......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPZ......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPZ......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPZ............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPZ.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........>........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Feb 16 22:12:07 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2683
                                                                                                                                              Entropy (8bit):3.997028415829834
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:8UdTTbrqHVidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbUy+yT+:8EjtT/TbxWOvTbUy7T
                                                                                                                                              MD5:E15EF31A83E1ABC26BD9D8AD323A6A0B
                                                                                                                                              SHA1:8D47E60CBED47AE50FA01036D7C1B9FC89D77335
                                                                                                                                              SHA-256:FAFF7C05B26A444D2F4931ED9A34116ADB886C1ECEE19293A69FEAA003F86396
                                                                                                                                              SHA-512:C72049303CC3588A2537CE275ECD460241FFA143D85899C6FBCE10A685ADD79941B505892540580CD98179BBA55249EA7D7B2BA0CB6A5889ABA4EEFDF248D2C8
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:L..................F.@.. ...$+.,......<3...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.IPZ......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VPZ......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VPZ......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VPZ............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VPZ.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........>........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):18
                                                                                                                                              Entropy (8bit):3.5724312513221195
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:uZuUeB:u5eB
                                                                                                                                              MD5:53AF239EE5D3E261545DEDEDCB6FFD57
                                                                                                                                              SHA1:04CA7E137E1E9FEEAD96A7DF45BB67D5AB3DE190
                                                                                                                                              SHA-256:99EB12F2AB3C4866A353E098FFA3CB7A967E617C49B98480394EC5D8EA92B094
                                                                                                                                              SHA-512:C734E4A5FF5D335A91518DBF47861BDAF8012AF49371DCD2E3350E269C9A5A1CC094114D17C4F5B053F3757B4B07487EBD0D309C91EF97ACF4665CC5D5C9A2D3
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:404 page not found
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 4994
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):1766
                                                                                                                                              Entropy (8bit):7.885410223434479
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XUrmPWJFtpWm7cF2MqRdk7Asg3V83L2oLx9v46:kr+AJtg3Cm4V8qn6
                                                                                                                                              MD5:AF102D97A6FD03461420FA5C13CE0860
                                                                                                                                              SHA1:0233E05978FCF7C71F2F2D814D91CAFC5D890D15
                                                                                                                                              SHA-256:ED374569DDD50CD06E9C13F809837FAFCED1B4175868115B239C21BF087426C4
                                                                                                                                              SHA-512:C0737FE9FCCCA223AFE618DE52F931A93E8C8E61630CEE6BEA431E6879CB63C4F77D9E66D6E8627F5FBB9F4F15A6A326517D66F6336EB96E78B50E2C471F1DE2
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/1609-c64b7dcdd3c9f311.js
                                                                                                                                              Preview:...........Wms.6..+6.z.#`..V...}.....~.}.L..*D.7..w%.....~..JZI.....`m>.U.z..o.z.....G.i:[ 3J.[}6.{.pa....i......R... ...e...n[...t.;N.3D.....?}.17.s.2.c.5...O....H......>......X...+.U.}...O...q.f.u..B......,..w...0..F.!.[-m.......&y ....c.n.5..S..v..Y.<..t{......H`8.$......1...}Hc....l.8.0\.!;..X.C......P`..k..+g>.1b...n<}.`..0.1V....z.t.v.6=7.....D....b6..?3.Ot4./^........VXU......f.O.|>.Q.X.L<E1.H.:.a...3.u.7...T.....t17Y.|dr.s=.l.~g...O.v...,.}ex...v..v....../.s7.m..S.....j.v.f..!..5.....}..u....L.e.&..\.tL..K.k.*3..0 ..ps.:d....*3w...b....<..n.b..T^_a..U92p*..g..m.U..$^....7...f3..%...V=R8.vO..7.%RT...5..........1...c.J]....LWb.......=.hMLZ-.r.A.L(....R.@/..f.b;.........Q..~.-.^...x...\/....2E.kX u.....q.2..Ap(.....?!...nXp.^..x}...].%.B..h...l)p..2.!...`E...e..P.1.D....;.q......#.j.8.)2..."..~.2n. ..~>2......<.&......j...u.&.z....=H.q.<.]...4.W%@....i..;....).uah.|.....7......;L"..H......O>.na..1i.......sz....}..+E_...v..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 5279
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):2092
                                                                                                                                              Entropy (8bit):7.915615707755917
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XvQutbmk/cGPBPSh/d+5kkZAbINNZYrZ07BLrpCLaZokN0TD0:rlZlPGI5tZA8NHY+FfKJTD0
                                                                                                                                              MD5:9D687CAC4902441860B630F2F22C69B1
                                                                                                                                              SHA1:39A8A18E18F59BA93DDF825846C2BA1FA95FB089
                                                                                                                                              SHA-256:E0AF0CC233B09AC12F26EB66AED9FB15486929C99458E8107A6D0C30409084C5
                                                                                                                                              SHA-512:69CF276E973AD06BCCA9F8A150E19D5E6EEF244E540929F508390B6413FB78EAFA9A2FF506ACED2278C79C5455E78D60CA7B2D93CF6669818969607EB688CE50
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2274.451b98d67be6c3c3.js
                                                                                                                                              Preview:...........W.N.H........x...$!dw ..@...x.^.....!...c...f4......:U.'..+k`,usQw.p...f......{.......e..zO>1.lg..zQ..2!C.....-Ic.L.....q...o^-.4OI....J.{.......F..d..</..A.P..$.J.pHs"G.&...@........T..K.A:pN.D.%....l=...[h...!!=..*^../$-8^..h.N....:0S`.uc./........,.1i..{..Z`C.K.J..Ym.y.7.V.-On..%...2.....~.:..e...g......9.....1.....Zyi.B.CU. W_9....C..y.kxv.;.....I..i.G.......h[..\~B.99.}....u.OjV..z^.<.E.7...Tl/.p.\...Y....%U....."..W..$...$.B.e..n.+b...86.0.|PY..+..o.T..k.u...o..!.'8E:.y.!pl..O...V.B...8...2.....l...8.z..6.c...v`3..B..I...r8.C.(B..'@...a.c.5.*......l8#.....g.e,E1......_i....??...x.Z.$.*...9CD3.M.".X`..V.=u..'1..r<.....b.9O.{.ua..JlT.8IO`4.$!}.C.............`..(,.._...Y6.,...C)q/p.R..2d(.. E.~*c0Dd#.....GG%..N...\... .D...Z<v_..Sp...m...F.E..T^..v..g.*.v^x...A......k...fN.,...i).2B..B1.z...$G8<$..A...q.J....;j.{P..'.w.......F..E....+.<.Lb.:.Rf..r..m.M%.v1/A..E...,..[..0p.k...gQ.N.....h..x_+.....^1Is..Ok.J]...H.......q...H.$.7.xy)c.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 4994
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):1766
                                                                                                                                              Entropy (8bit):7.885410223434479
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XUrmPWJFtpWm7cF2MqRdk7Asg3V83L2oLx9v46:kr+AJtg3Cm4V8qn6
                                                                                                                                              MD5:AF102D97A6FD03461420FA5C13CE0860
                                                                                                                                              SHA1:0233E05978FCF7C71F2F2D814D91CAFC5D890D15
                                                                                                                                              SHA-256:ED374569DDD50CD06E9C13F809837FAFCED1B4175868115B239C21BF087426C4
                                                                                                                                              SHA-512:C0737FE9FCCCA223AFE618DE52F931A93E8C8E61630CEE6BEA431E6879CB63C4F77D9E66D6E8627F5FBB9F4F15A6A326517D66F6336EB96E78B50E2C471F1DE2
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........Wms.6..+6.z.#`..V...}.....~.}.L..*D.7..w%.....~..JZI.....`m>.U.z..o.z.....G.i:[ 3J.[}6.{.pa....i......R... ...e...n[...t.;N.3D.....?}.17.s.2.c.5...O....H......>......X...+.U.}...O...q.f.u..B......,..w...0..F.!.[-m.......&y ....c.n.5..S..v..Y.<..t{......H`8.$......1...}Hc....l.8.0\.!;..X.C......P`..k..+g>.1b...n<}.`..0.1V....z.t.v.6=7.....D....b6..?3.Ot4./^........VXU......f.O.|>.Q.X.L<E1.H.:.a...3.u.7...T.....t17Y.|dr.s=.l.~g...O.v...,.}ex...v..v....../.s7.m..S.....j.v.f..!..5.....}..u....L.e.&..\.tL..K.k.*3..0 ..ps.:d....*3w...b....<..n.b..T^_a..U92p*..g..m.U..$^....7...f3..%...V=R8.vO..7.%RT...5..........1...c.J]....LWb.......=.hMLZ-.r.A.L(....R.@/..f.b;.........Q..~.-.^...x...\/....2E.kX u.....q.2..Ap(.....?!...nXp.^..x}...].%.B..h...l)p..2.!...`E...e..P.1.D....;.q......#.j.8.)2..."..~.2n. ..~>2......<.&......j...u.&.z....=H.q.<.]...4.W%@....i..;....).uah.|.....7......;L"..H......O>.na..1i.......sz....}..+E_...v..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):7076
                                                                                                                                              Entropy (8bit):7.950564894223784
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:8u2vJzscWVb7BpUg+OPXr8aeSUDAcBWalDIytYuvpLEmLAgKUR2Af:32vhdWbpHLP78bNoalbaIEmLAgKhAf
                                                                                                                                              MD5:F54529F769913035E9BC66A8B12628A4
                                                                                                                                              SHA1:307730FFE890FB6CCB68E0B4B3A1035CF06B5B2D
                                                                                                                                              SHA-256:EEE83710DE65BDE638DB3085F8A1418FE482523F500AC67AB4029D7D34E2F480
                                                                                                                                              SHA-512:BD386A341E7EA0E1992F51AE25445DA862C12AACCD6712C8289CEC99E81924D2194B6C3BD85E1ECF973094A9178713E15580613A0983E8472149955FFF45CA85
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/yongli.png
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE.....x.rc..t.pa.`O_=.yR?.n`.[KI$.e;$..u...]/.tJ3.td.gX..q...D..g9.uTG['._3.N).]2..fU.iU.U@zRBY6.oF.lF3.qa.[K`5.yP:.k[yWFZ0.g@1]1.zTCY4.^).pA.b6#|XE.}mh@.f<$kB,.`Q....mZ|]O<..\*.zU@_9$.Q;:...gWrF2.}lfA1c4.c7.Q#.c6 .]G.hY<...lUgPFk9.W,.a2.c3.wN5k5.rI5oJ=Q%.Z..j@&P).h;)iA0c;"~W@o?$rC*hB0^2"\3"a...zigC4.whZ".Q..W+.A..Z+.Y$.M..P..T..z^R.[F.\H.]Cb5$P..I..N..R$._2.Z-.|`RN&.mD,mI0o>%.`HJ..a..wZHhC0nO;qB/eD3=....v...`7"8..b,.W%.h= uG-Q..n:.^*.nOB...=..pD..kUB..7....G..-..{P=.wa..Y$.=...vaL).|R=..y.}i0..Y(.[&.V'.^(.U..R..O..M..Y&.V!.[+.U).N..S#.N..I..K..T..W+.Y&.K..G..C..X#.I..G..[,.Q..Z#.l;$Y*.G..Y..C..:..?..W).S#.W"._..]".d..\%.Q".....bS......%.r....tRNS.......o 3..%...WP....D...F.ba.~<<..~+#......RD:.]:,)"....wgSN.....tt]X......K...........xjf`5..........xgU......yp.........o^]KF4......wN...iU...r&......|..pp....'IDATx.....A.E.!A..$$..X...(...N.x,.`>3l..3.u.-i.y.t...5..................=...4m....$=.>7GS4....L.tS...y{(..)..+v.)..=..&..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 200 x 200, 8-bit/color RGBA, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):9166
                                                                                                                                              Entropy (8bit):7.943044395390699
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:6SR6qSQiN4jFrNuFYJzUYUbI04bYPaJBxKqZcGVlX:1R7GKT8YzUYON4b6sOqZcQX
                                                                                                                                              MD5:2DC231BC7104153AD42E898E7D4E6779
                                                                                                                                              SHA1:9ABD8A5A5CF86DC95EEB72F882B40E69E2A7D23E
                                                                                                                                              SHA-256:1A622555817668F36C77A472DACE4390AA8C2160A1AF60330E9DC04DE9F91E4F
                                                                                                                                              SHA-512:0EF4E68315EE37E5AC0A947085101E55930F6956DB6B01D324012FA709108C375AD2388E699920D6B29CCBD8026399F035C8F657A7D27673C96CB8079783B489
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............X......pHYs...............#.IDATx..{.]Gy.._.;#..X..F...m..........`B...]*...`IQ.qv.X.J.lR..d.J.j!DKBB.3.......v...%.H.=...H..5sO..G.;s.....s..H..X#.>..._?...kQU".Hg.r....d..D".D..D2....d..$.. *H$.AT.H$.. .H.QA"....D".D..D2....d..$.. *H$.AT.H$.z^...7..(V...~...l. .V.V.}.M...... ..`......Q......(..O$5....q..F.AH.R..:.*....j."...&..T.!A.K..+.....Ke?.....c ...h!...4......xYQj.U.....;c..I..4.[...N._./..~..]..*HW.PV.o.6....K.6.g.2.S...\N..I....P.R`........r..d........i.}.E..r._.l. .>Q9....N...r.'"......MH..(......Y.J.j.q.QR.."TA.5......^..].........s..P._...~.').J........d?......a../.~_...>........YJ.h.....-.<...p /Q....0j...-.Y..,..T.#.~..f.o.1.p@^g |.&.....@...~XE?..].k...t.33.....IU%....c.*G1............eA......o%......<|:.QQ.3A.Z...H.uE.k.....H.r6......z#N.}.YV...._T..,../..g....H:.Z....V._.L...=.d_j].xS.....8...\h.....Z.....W..y*..s...,.r.2l...}...dv....$WA...Q....%...*z..^H.C..(........\....s....b..=.H.Hr?.......}.R.T....GY..z.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):18
                                                                                                                                              Entropy (8bit):3.5724312513221195
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:uZuUeB:u5eB
                                                                                                                                              MD5:53AF239EE5D3E261545DEDEDCB6FFD57
                                                                                                                                              SHA1:04CA7E137E1E9FEEAD96A7DF45BB67D5AB3DE190
                                                                                                                                              SHA-256:99EB12F2AB3C4866A353E098FFA3CB7A967E617C49B98480394EC5D8EA92B094
                                                                                                                                              SHA-512:C734E4A5FF5D335A91518DBF47861BDAF8012AF49371DCD2E3350E269C9A5A1CC094114D17C4F5B053F3757B4B07487EBD0D309C91EF97ACF4665CC5D5C9A2D3
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:404 page not found
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 1139
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):340
                                                                                                                                              Entropy (8bit):7.326832691821609
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6:Xt3Pv8k5jnYpJizMv/1xGXWDLbXZD0qUEjQpYUhdtZuPI/t9eV0j:XF8kqGMvDGX4LbpguTqsPIreV0j
                                                                                                                                              MD5:91AD258EFE69F53C4CACBC153D21F521
                                                                                                                                              SHA1:7335A307C448D6DA52FCA7D63639ECC35A41F83C
                                                                                                                                              SHA-256:33080FC9707795B6E1175ABF03827D030DB8490A3D4C160CB60D8119254E964F
                                                                                                                                              SHA-512:E0335B9244F4C97C43DB29AAB8BB878BCC72F7FBBEE9D95AD87103903E85C2E910693F68DB78B79668F7D16668FF1B53C0DE63FED5CADF4E6577778FEDA74E71
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/4f5a15ecad11756c182f29db661fdb35/_ssgManifest.js
                                                                                                                                              Preview:.............k.0.....(.!{.{..,..b}s"......\,._....VI.|...%9.P.w.].&....|......7).h3....L[Pd...y.lm~..(..'.....cF[..c&+..L.H..".Yo....r...e.V0..B..........IU.\mY].3.Qs......J..ImHm....+..&.Vh@K37b..U.W.uB.D..J.b.b..H....(...y..:..........*.......Q.Qaz..C...+..Go`T.........%3..`.U.L...r$......g[!\..v....!...p...?g..,s...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 100 x 22, 8-bit/color RGBA, interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3294
                                                                                                                                              Entropy (8bit):7.925369044227741
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:Hej86oIAG5+8aOMrzoqrLKsQ49EgTZPeWm:HPNGbaOUcqrfS+eZ
                                                                                                                                              MD5:E7C1F199EF4AD1CD5E2381777F3AF90F
                                                                                                                                              SHA1:8B06F308405EEC3219587E4DC9E67BC6280FA841
                                                                                                                                              SHA-256:A01D73B630804F843C99D70F8F64A30303A8BC1273FED46BDF9F3D190BEA8A68
                                                                                                                                              SHA-512:4A790EE2F5FDAB27981B429A89694055AA5BC8EC873959117E73F71A6DBDE745E143B2738AE04C7960FC2B1B382D52CC1E7792EFDE67072619BD58E6439D5363
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://p.ssl.qhimg.com/t010e288a56a0b005e9.png
                                                                                                                                              Preview:.PNG........IHDR...d.........A.......gAMA......a.....IDATh..yt.......$... D.....R.M..F...b..X.l...ZA..,j(j+n.X.,.{.F.%.`.#i.D....P..IB...d~.|_...q.........w.....{.7.CI/...`..U(XX.oI)77wSNN.'~AAA.......<.......;Z<//.$.R..0....X....o.P.Q.z..X.8b.Q4_...B.+VO.d..U...?...^^^....W....>.};.y..wj....'..u.u..\..;..<.KB.~..6.^...gK..O..V..C>.....?....[%D....#...!..*(....7X8.c.#%...`p$....o.c...l....f.$;.W....^.|.;.|@.....N........q.3.~;._.v......p}..^.{N"5..1...j.....g...LJJ....x...Y..eee.%..&..2.b.A;.:]r.$.1uF.me0hb..B.....N{.p.v....F.c5.Z..{.....cS....."..C..9..MD..h.p...#F$.g&I.Q.v;lC3eoV..'.~...?e):H....).)[1.u.....mDDf)@{.l@...Wj..=o.a..~.{ .d.r.s.'...w...:..s..W[..Vi.>._U8kq.p.....g...1n..[.....S......."..Y<.8b.y.......@(.....RP__....+.f.t.....X<#..-.z.o..Z>gT..'!rM..d..zj.vla............D..@.....F.h..|....I....I%%%.222*v...G...&.N..K.~..d...K4...$...O.V<5.v.Dp%..S...9.Xe.f..d..Zd..tPK.}.(m.x..e;.%...X.;.i.........u..:..L.E.i...2.<...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 36084
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):35993
                                                                                                                                              Entropy (8bit):7.991075115355502
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:768:lo43E4XDIyIc0zkTEDXnuruBem5vmckQB74VqORQQjANYAq1:l53tItLDqGRlmckLJRQtY31
                                                                                                                                              MD5:ADF3FE062A46C653FF61E04B7ACA9564
                                                                                                                                              SHA1:2F02508B8A6927D19DB1B5C1841FE40693096398
                                                                                                                                              SHA-256:16B80D0D0CD8DC0FC4349C13C96F11331A1639AD82E8C7DDBECB06BA09DCAA56
                                                                                                                                              SHA-512:E7BF349BC1C5D2C70108F064C4BF8BBD8BC41865ECDCE27003DC75FA5C3B96204748464053B6B6BF1D39959D09900ADB0EBF16BAF229E1108ECB5FA986716103
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/api/ImageOptimizer/w=640&q=80/https%3A%2F%2Fpos3img.uoenuvy.com%2Fimages%2Fnew_public%2Fweb%2Fbg%2Ffd%2Fcs%2Fctj9f7qnghtku82qsdmg_128059.png
                                                                                                                                              Preview:...........UgT...}.......P.`.I^.B.MzP.4.....RB/..P.#..6............)".F........s...){..f...gkm..}....^s3#{.`....<'+s.P...........!7c+#..3-.NSd|5s..1t...6=....sR.)*k+#......*..>++8".j.C0"..7.......q......0.7...../3....B[.v.....$!....?.$(#....nDD<.J...<...K.h4Z.1L.I#.s..z.t...9.*(...1..}..?..d.<<...t2;.....'.|.M....)....P..Z\T...oa.zpx...z.~$/BW.*.......l..4...97...&NL.~...?8.......g.sl..N.nEI.s....+..<Re....O.K'..p_.=.../.A...7...........F.....W.$]w..i.c..z)>.)>%c..............<.Ng0. .Jf.....T..:."@...9..9..1Z.W.....Ir......./l"..p...5.rC.. Q.@.?.......M...Z.%.3.k[s=-5.......F.......n......K.z....\...1).......Z.OY...I.[j...N(*..Y\caq.$uD^..C.....##u..\P...7J.....a.t...b.qaa7L\[...R...@.8..f@..........Q..>.J........."......;3..\.a..u.. PI...%EM..m|n...}.t....]ss +l]\..;;Pni.R..'..W.x90..g.$tY.#OF=..E....|.......o_Az%Y...R..'..,..4..5m......o....k/\.Ki.X..M.fqv..S2..:.Y.TZ)y..=Q....ks.A.......;..i.5......X.../.../gh..M...\..W..=.;..........S..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 5568
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3186
                                                                                                                                              Entropy (8bit):7.9233846338030824
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:X+9DPU0fQUsSyCsKDPjbtnopmc3k2/wrdRopai6RsMbPNqKV9MAbiOc6:iR4UsnKDfZHclKliOrV/btR
                                                                                                                                              MD5:DA57FC8F7593A135208CCBBAE6BD34CD
                                                                                                                                              SHA1:E0C424145F19D6741CCF90D272E6407DF5EBAE47
                                                                                                                                              SHA-256:3CFC98122D88525A5B27553A504E49EF99632A382A5C60AC230C38501AD6D7A3
                                                                                                                                              SHA-512:FF9D6324BB7469DE54851A7B499AB824D90E0371C1459736C5289E96B67A0A592CF1C7307B4AFE545BF0E4998C18459D182AA09BA13EECC13F7F462F156D8344
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/customer/main
                                                                                                                                              Preview:...........Xi...JY..........AQ.J-TI........ AI.s.w......._.>.A....3c....X../.d&..W...[...L.O.??.......y.B.X..eo.m.z..i{Y.De;Jq..J.(}+.v.2+@...o....W...'...".....aGFl/.F.8.....eQ...A..?$.}....g.)c.....([.^..(e.._..>......C.Fe..m.91z.>._.e.....sk....:iP9....5l...].k.F...)#7.z.....=za.1.B.....}.....?.{.c......-.2Y..|....C...jl..%.....C.*?F..bU.A...g.......t..4f....b..]..m{...y).......".Yy...)......F..Y..Ni.x.....K.......!......._...#..K<.'..p..p.Jv.~..W.b...2.-.$....}...h...}"V0.......}.92".............<...l.R..J,/.Q..9..x....P.x...SS../X.%..#.%.mq.j!..Ai.lJm.YY.0)1-.5...e.)........L....LR.{......+.'.?K.QR..:....5....5....G...+.Fg@..bT.V""i..[Y.n........^B.W.T.<.....w.zl'9>..%..U}.h.0........3..g..p...<...@.. .-....>[..z...P*.x\Z"P6r3....*_kj....9.7L'i.lVb.#.O.@.A.=[.Hu...*g..V..../...r....@<X..by.........k..J.IL...+.)..[..6...}m..g.Z]A...uZ.U....3;F@f..2......................Y.3..j...G.gg.Y'...c.|.@o~.O....&.%..........A"T.:c.ev
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 35802
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):13078
                                                                                                                                              Entropy (8bit):7.980686104681234
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:D4OsejGA647T4+T1Ltr5JiN2nLxvpky5yquKIUBPC/aOB2xcRdkDKOXTIxRUkiTB:XsOT4Et1cSVpJBuKI6PoxYx92Uki2W
                                                                                                                                              MD5:B0B8DBF638D5426C0EDBE25EBAD2924A
                                                                                                                                              SHA1:E844DB17D0BA0557602EFE2A87C7DFB59635DD3A
                                                                                                                                              SHA-256:6003CBEF846E6F74FB73370605EE8A26BF370477BF213106505136F3DAF62FFE
                                                                                                                                              SHA-512:ED4AB727A0B3545539621A719E38CB767C80DBAA031D2D6563C8C3D62C70647706C22F1558BF22978B000077AC183A5AEA3C7D49EAFDCF48992DE6BB93D95E53
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/8067-b564165738404b95.js
                                                                                                                                              Preview:...........}i{.H.._..n....h..L4.cO.;[...'...E....l..........^.}..p'..:..:{U!m..F....k#=........W..7.......a.W.\.L.V.......rf....$.).Ij..t#...^/.....4.p...n.Y.d...-..u.....{;.5S3..m.YziF.........u.j.e}.....6R.ov..l..WiP...B<..k/...0.c._.;."....I.XX..8./X.:}.....0F.W...N[.ql.V.l;eW:=.....;..x.t!......K...r..z..c....bJS(i.d.ZB{.4........X..&u.L..C..Vzl...k......b......6.O.'z......q........':$Z....WF.....^.,])...)...65.X....J.,@O..~..?.n9...{/.}:.V...5.f..L#^......<.Y.G...d... iY.......l!..d.]...JES.hJ.k...z...0...5.].*L#`7.*...c.N./Z$q...~....B..!.....9..S..4..!...^..*.6.I...t:..,|/..h.7.R.:..^........2.?.<...........f=...Y...T....{4..Y..0......"Kpx.ow;...b.....(..LyV.5...$.h..y.....O..N...d...z....y.`7s.&...Q_...i.....p.(\S.j......51_....]%.?.q..a...<3..hT.el.!....#OdRO.3.M...'.5.x..:......h..Ow...X%a........U..aA.2)].........fS../`......O..JN.\..b.!#.Y..)('.b...A^..V..l...Y.$.Y...n...v...cp.=..0.I.0r...7O..hp.y]%....x.k+8...s.X.......%.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 16 x 3, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):142
                                                                                                                                              Entropy (8bit):5.249101080330455
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:yionv//thPl98tmllOp1pxfOUcP/MllXioCVEy42/uDlhlbGFlM59FXzhltB1p:6v/lhPctmWpdOa/yoCV7/6Twy9FDzdp
                                                                                                                                              MD5:FE4FB026D0BE66239461CF118CC4B8C9
                                                                                                                                              SHA1:1F1253386F02D78EE56FA3D7450CBEDDF4CE97E1
                                                                                                                                              SHA-256:90CCE56E33D5EE5E33E5CFA7B179771C09469691B541838EECC6A0CF6C953837
                                                                                                                                              SHA-512:B30B976D72D18E97DE99145975C460BF8FE9B9195753BF01C600ADA1527F1305536E92D172FDBFFE9CA4EB8993939AFB7EF8610ABC92761AB5F73B94CE2E59AE
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/api/ImageOptimizer/w=16&q=80/https%3A%2F%2Fpos3img.uoenuvy.com%2Fimages%2Fnew_public%2Fweb%2Fbg%2Ffd%2Fcs%2Fctj9f8uriolb595l2tug_339027.png
                                                                                                                                              Preview:.PNG........IHDR..............o.f....PLTEfmt..y@9]..`..x9....tRNS.M'p..s.....pHYs.................IDATx.c`..ff(.........,......I.)....IEND.B`.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 21469
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):7791
                                                                                                                                              Entropy (8bit):7.972650550128744
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:91+cG9O4PXrdASWuzNdZuXmJGd7UklGiSNlw7hez:7bGw2Xrd6WN0Abs8
                                                                                                                                              MD5:F56B5D9D66430844218AC5CE45096F0B
                                                                                                                                              SHA1:34A2CEE9E0BB3E2F20B784E9592D982613E3C4E9
                                                                                                                                              SHA-256:596D255CB280218ACBC9A271A19C27576C4D3D06A351E413B2878701644B1CA3
                                                                                                                                              SHA-512:F63B18307EEE331D92DC9CFF63764ACF9B88713664FFDDAB4988C6EEBCE8474D6B8874FA9F850EF8BBB535A7F49E0702183821CCCEB090F1E466E0407CD7F978
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3355.11eba924ce8b2eed.js
                                                                                                                                              Preview:...........<.r.H...x..Z,.q....6.>... .T..!a..v.._fI....ggvc...R......w.q..F7d...Eq.IkR.]l......]y.,..["!.O.k,......[f.p.g....O.k..|5.v.e93.D\.U!....q..j...O+...~]K.';gF.l2.e9......r.\...l..dlL...*.e"......t6....L..8.yp..........XN......+........x<.r;l.2...i....W....DL...n8..[[....r....W.5...E.....[....3.Plb......xbH...DT"l...2.Z[.w.p..=...>...{}.^...nEwEF...f....3.....76.....B,.c.<E...t..4.8N..9}<e.-R#......e..b.(.a.6.f"..[8yVH...8H..C.1..%.B..T...R;.....E.L%C2e..a....C...#.M.....'.d......q.......5S![`..u.;:.......b*=@1.....v....4...nZ&.."IT7W.....H.\..;@......u!h}o..]..7...z8.iZ.dpE..-.Fq...%.r@X+....J.a#........u.+....{|.jUr..2......Q........n...=.]o.........a.K...}.^.[..&*[.,..........'...|.O..r?]..88.D..$.+.y.*'~..i.....p?.).J...H..0..R.....nj....Stn.f....3.../..r........*..l6..L..?~...4.71u...D.7/%Ly..S..l&...aPJI..R.>.<,..UyF\.HjGm6....im".?.....M+..%.m......UN#.2....&I.TU^..S5....J... ....(...n........E>.@.j.K.; ..a`.....x.e.K...F.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):5294
                                                                                                                                              Entropy (8bit):7.937849280289421
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:Q0/zqWkEB5tP/GGhqd+9BWfV2EIWIKJFensiSCLhnLEARybIDf1V7:Q6oEBrPeGhE+bWd7MnsiSuhLpR80fD7
                                                                                                                                              MD5:B5F40F3C38B9464DBFAA82F5FCA1921B
                                                                                                                                              SHA1:1F3CDC4D8CFEBB93899220A15C26943E24973849
                                                                                                                                              SHA-256:0160DE7C57628AFC1694999264E44C99BEB18DFFDB2992BE7D8223ED5F3DDC94
                                                                                                                                              SHA-512:A193D308CEE71CBB01C7675D572134655FBF6778A711422E09EBCEFFB8732ED74D502335655F75D5A783601AB955E640F7978DF7D07A6AD30AD6D06A2713A812
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/weide.png
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE...&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5%,3&-3...&.5#*2%,2)08#(/. ).#+,3:.'/..$"%,\..\..|.....8>E""')7A....B~.W..,>H .!/HTFLRkqupuz...KPV]..;k~=l.agkV..Z..X..2O][..._.._...........c..G.....=p.^bg3SbOTZ.....! %...Z......16=............>t.49@........?EL<BHx|.ty}...fjoCIN(3<....Z^cTY_...@z....8cvimr5Zj^.....Q....W..e..E........<p.6^p4XhK..B..N..I.....i.....x.......tRNS....[..~1.............IDATx...YR.0....-^c;I...`(.YH...../...<.:...l..2..[1e6)O...>.Y...6..K..S.c.G.@..;.B..tW~...M."s....=?..Q)...!.....z...en|.{&..](.O!x.d...%M......@PT.3....FH-....W.......j.M...9]...9]...9]...9]...9]...9]...9]...9]...9...9.......o=Hg................(.z}$.Q..D0....F.>..@.^..`..#... ...B..>.3r...Z....Y+/X.d.C'u>.II.m..bsU1.|.T.=R=&...q.S..a... .Bm Nx....&.N..T..^:.-.......Co$..W.i..Z^.ASi].A)...2.}g.hx......0..( ...z...Zhq...4[E........=.>H.[{^..7.F.....Up.I]K....u...'f..F...H&..1....X....B{(EK.D..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:HTML document, ASCII text, with no line terminators
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):107
                                                                                                                                              Entropy (8bit):4.703914676699388
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:qVZxgROMCXbZ6zzmKXAQZIaK+MyMEMYYdaNqH7064:qzxUpCX96ziBW7KVfSVNqb8
                                                                                                                                              MD5:0B9A1090CD0F1F0056D67BF6FB4A38E7
                                                                                                                                              SHA1:6619F6628C73A9B330676A7E0E754006B119473A
                                                                                                                                              SHA-256:469FD55713C5A9265A0779C5FA6866623CE7E59F589A40F49149F5428EDB5370
                                                                                                                                              SHA-512:D7A74EFC4597BF01BF84B5AC86FE2C056024AB689EF857FA8B936FFA275F8DCAC3F697B6CC0ACC46E424BA94F14C754FD0457BBBB0A5C67848B5DFDA127F7273
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/closeClient.html
                                                                                                                                              Preview:<html><head><title></title></head><body onbeforeunload="try{parent.LIM.WinExit()}catch(t){}"></body></html>
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:data
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):52
                                                                                                                                              Entropy (8bit):5.661978179679557
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:+lJcKux0hVl+OL2Ahun:aJcKqHy1hun
                                                                                                                                              MD5:59ABB299F3898409469978AFC3E2D3E9
                                                                                                                                              SHA1:DBBBF2D45C7B49B49732A99E3E3EA7726C191A27
                                                                                                                                              SHA-256:DC0AA9392243369B83C754BEBF347E741E1E6034DA419629267988EB455404D5
                                                                                                                                              SHA-512:5C5055C657849D1F3CB8167A595D5A9F21D586594B6651FEB4633285845749D8549E06A6552D05A1C3159586F9E632D340ADDAD7DE542CB685D3EA76BE81E7EF
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/4f5a15ecad11756c182f29db661fdb35/_middlewareManifest.js
                                                                                                                                              Preview:.... ..m.X........A..D.v....1.L.....K.<..>..\t.J...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 3593x1400, components 3
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):296412
                                                                                                                                              Entropy (8bit):7.931124631952406
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6144:jsw/ojc+qPxyYKTsbcGPp5iD8PRCb2otJdY0b0raG0idjHlaDfBW:pQjc+qPlxS8PREFtEnDblIo
                                                                                                                                              MD5:ACC29E2A810DBB1885ED42BCCFCC3DDF
                                                                                                                                              SHA1:16175006F7ECBE64FEC2BF622188680E9620E525
                                                                                                                                              SHA-256:40A9EF15524032293E0F19486DD17456585762F1FCE3BA47349CB2E79E2D56E5
                                                                                                                                              SHA-512:32FF9CFCE71411FF45F847F19D4F21111E4DB8A058D9440DE2483D3F228C033C3D5AE14AF05A45DB93E1BF1D017B479D74F989E8A11AAE3F3E72BF5DEE87988A
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:......JFIF.............C...........................".##!. %*5-%'2( .?/279<<<$-BFA:F5;<9...C...........9& &99999999999999999999999999999999999999999999999999......x.........................................................................................@..T......T...T.:..`.X..V.....B..M................. D.X...e...e.............(..............*.....@.................D....P......Y@.@....R.....P...U........!...!.t.".........I .......P.....h..@..@ P......$.QTP...PI11[b.[+A@.I..`...............)M..%Y%@...L.U"Q6.J.aQ..........................@..L.......X........"...@...( .($..... ..X...,.........*...... "t.D N...B.......[.@........YEP........".:....4.............$.............B...(A....."-A.%Ye..%YX...).d-..$..V.....$..*............D.l.*N.T.-lb..PR..DJ........"..........M"......&P.......h........................U.................b..*.P..DM............@.l....*..Y..@......+ .............................:..P.(.@ P...L.H...%I+T...X.A2....ex....DEX..`....*.......jR....M....DI+\.".+J..PE"e
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 192 x 180, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):21808
                                                                                                                                              Entropy (8bit):7.965220787615533
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:RLAQ6vBzj2oCaGhj0jFwYjYPLPiLNUookpzAltXNhJtQTRgpa0LBH3pf:RNAB/BbG4jdsD6LskpzAlvtQtX0Lx3pf
                                                                                                                                              MD5:C83EED0DF1357AA7A2DF0686EEF73598
                                                                                                                                              SHA1:B175DC79CAB26C5616A83CA5954865B2285E9C73
                                                                                                                                              SHA-256:F9335A2D909DA756905E552DFC2AE98A06001CF6EE1548F79BCDFE6446B3EF1A
                                                                                                                                              SHA-512:CE53ACEF2474AD18BF97722952E9275B900B415E37B80F82FE362F89E3D53DEC5F94261B9F6FC4F870CD1EBC5497422B0E2B2C31C4C728672C94BC29A848D49C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR.....................PLTE........$....9@.9@.....$.......7=.."..........<D.-6.)2.07....7?....?F.."....5>.:B..".#(....2<.18.@J...........$....8A.%-.!).......(..!$..&.............AH."(.....6....2;.-4.'.."#.... ).)2..5./9....#,.BK.-1.(.....8A.*6..&....%*..".(+.(2.<C....#,.....#..........$-........)..&..........gW.PG.ZL........IB.3=.,(." .p.0/.. .YO.*%......RF.\S.NB.E>.1'....iX.?<.37....")..........ED.G:.....g.! .....70.......w.z`.cP......q].=7....bM.10..r.XF.N=.:3.<9..&.....x..$.~i.w.dD.......:)...#...z..o.oJ.}[.Y..9.....OL......uZ.Q5.6!.E/...r\.79.%-.+..$...1....m.[....{d.~.e....f.a.......s.[>...p.cP....dA.....x.kW.o.tK..#.}..{.c.B7.D4..h......z.g].....P.....O..,....w.l.se.a..l...v.Y9.O0.....g.pH...d.B(...p...R.#..{.\~WcZ....tRNS..)...X..J.}g..Q.IDATx..mHku..{.Rh;X..F...xfT.2]..-..!....{p.<..k.`./8.v....-.^...iV.3.^\.....z.U0.......9....=|=..L.|?..........>.......v.>.n6..U..(..N.8>;;.V.{@S.T*..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 265120
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):156787
                                                                                                                                              Entropy (8bit):7.993840783113738
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:3072:zsrMglmEpIhxEvxqcxOVP8wueAS9TVho9xGXLgD0o+Un2kDjQvNFLxAnCHa:fymEpIhxEJqccByepBVhoHvXnXWNFLOZ
                                                                                                                                              MD5:1062D55D93FD1BD5A0A059B32AD0893D
                                                                                                                                              SHA1:817D135684E64F827898207B4FF0F66E5D2BB6C6
                                                                                                                                              SHA-256:2741D7EA11496766FF5619E740C79444D9C9BA10EA79875D807337BEA56A5D98
                                                                                                                                              SHA-512:BA348E988B5CF5D51D8B3FB2C0E2B487EFBE925E4612DCFEA7DFED8AC243CBDBD91F5E13CBD9AE318AC21128A4062F004DEA8333D43F021C14320AB3DA99E7FB
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2650-97aeeabf3579e756.js
                                                                                                                                              Preview:...........}.w.H.._.....=0.}...<] ...>.{..]H..t....7......cf..nL*32#2"2.L.y.:.{[:..i..e.....S..X..o.~........'..._.q.".;7....k.^...Wy...f.oeW?g..uU.<.....8Y.D?...7?.f.Cq.]...7...I..z..,E0..".p8(:.Hp....}XK`,~S7A..0.....J.`....7u..S.K..|....P....f..k'.....l...O?..o...x.........w....=...S..X......\].U..y./.. ..Q.|d.5Z.o...\_!..!..G..1..I2?.#.Y....@....O....El..Z..~.y.y....l;.o9wW.U.......p.=....._.'.|...c....<......I3.M]..#...H..n.k....:...X.....r.Q;.{@Xzk.7...v....^O.........In.o..l./$!.....f....)..0N.zxo..oS'...\..6.AffyZ.....-c..E....N.#H`...#97.?b7.....Q...._./A>?...=.b./.....,.zp. ;..@..D.5...<.$k.k..S7.u.+;g..j|......H"X.u..k.}......K...+.P..7......c..0NL...L.....0/xuuk.ef.>`."1#..T#...9$.P.?..#.....'.w_(..ps.^.G._.J4.l.n.7.V...r3..........f..Ey....g....G..|..~....y...X..M[...H`......A...:...0S..9..x..........`I....p..U`r;...^.Ez...w.~.].<8!0......I.'/........\.. .o.<...8..q...h.~x.jp.UP.....0.x....k....-m....C;q..........X...:..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 31475
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):15433
                                                                                                                                              Entropy (8bit):7.982098122673745
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:gZZP02bH6cISJoj1C9+iWFtw0FtA9Ihq1eEs3QozctjEyX:gZd6cISJS1ZV/7AmhGslyX
                                                                                                                                              MD5:972084AB97E45615B75037E6448CA103
                                                                                                                                              SHA1:18767B400ABEEC964647B573F3EA0BD12EEEB917
                                                                                                                                              SHA-256:A843B715654317671C9AE9FD336C1DCA809DDECFADE220D0FD9FC4A1A9D425AA
                                                                                                                                              SHA-512:4E89A9B89A9FB61F4BF6DBFB8EAAFEB28E8FF632C0815BB251C9FFB220E9D7D8F5BAB7E8D039DD0781BCFEA5EE25AA1DA0419E1DFFC8354DD550E93FC29370D9
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3473.2bec367cff8fad09.js
                                                                                                                                              Preview:...........i..F...W<..C...6....f.....F.......J...~..*.J*Y...}..f.H..<[..L... .?..[9.....i....f.......P.m...9..r.+. `.!...K..]p..'......k....{......z.B...&.............c.nA....}...x.#.....'.].....ze.v?...2...!.o..................T....8Q..|..................wV...W"...Z.N.~nB.....=../..v.c...~-...._.4..<....7f...r$o......P&.O........{..,.}...... ..3y.....}.(......c..D.sK....Yj.E..+....*....vI......'.0vw..n.\[~........:w..O..7@d@|w..N..a.............T....OH......2...Wb....t..qJ....?.a..9o.../.g.. ......._/ ....H..B......m..5.#..(C.{..1..6.".............2.........`%..D.j....+..........9.`..._.@..?.-..<+....*.6.R.......I.....X...Q..?.?r...;.#.r.k.7....WN^N.?..O........0....tD`..Y....~...$......#..W....w..=.....J..G..........%.~.......Y....4....'.......h.W.....L.E7............k..7...o:....G..W...t..I.....V.s.....O...a?...B.....>..[.}...?.........A...A_....._.o....o.......u............}.m../t..i7.#N..?r.y.......?v....K...u.I.|.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, original size modulo 2^32 281
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):232
                                                                                                                                              Entropy (8bit):7.0676437260056115
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:FttbL1NiZoYX781qpKiRjsUQs3VoFXggY1nxU2ihA3Q8vatHdWHXbcfdg1imeE:XtbLzA81qpPo+lqE1xU21gaIWrSg1imz
                                                                                                                                              MD5:D26C13A934C8B22EE43899454C789B9C
                                                                                                                                              SHA1:416A6678C317A0C76B57D798B5262C58F9DF17FC
                                                                                                                                              SHA-256:F6922D720C4BCBACD3786AFBA731DC0276255C488139BA8E63339805C1AC505A
                                                                                                                                              SHA-512:3C1C844AC9ACDEF768EA49DD01965D019078AD0EC626FD0E2456E1AEEAF49B8772785EB1C075C293898EA893B81ECCCBC5D239900452C00F67C4F3E738CBF410
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:..........d.Ak.0.G...IP'...%H.i..^.YJ.G..32..m...+=.2.....c.PH.I..w/..F].......3.\|..P.....W........ .M.K.k..W.q.....d.rXF.......SG..sR..&...?E../..7....]Vs...Y#6+.....t~.qbBJ.OC...?/..f.h}.....-.,.z8...:.,.....!........Q.w....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:HTML document, Unicode text, UTF-8 text
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):608
                                                                                                                                              Entropy (8bit):5.300507717143507
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:12:skhibx5iFFA2JjtAWJIJXp/tar74xUTfoW2AfI6Qb:skdOMjtfJoY7rg/t
                                                                                                                                              MD5:E86759444E99E5AA3BFBC7243D0C727F
                                                                                                                                              SHA1:AC30C134AC40CA09D5AB8D27A0127F101B1A9379
                                                                                                                                              SHA-256:8C05C2270B8FF8348AC5BD5BCE927731B29B612325BC7C83D328D4221012D667
                                                                                                                                              SHA-512:E6D7831CAEB36D1BE0D0BA5831E1AE424AA817245443E08CD3DCFF839C5B83DD48D65E6F4AC2E2F4184C9FF1FE6E05FD42A6F6D2823E49C2EBCA539FE674CB23
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:<html>.<head>.<script>var V_PATH="/";window.onerror=function(){ return true; };document.onkeydown = document.onkeyup = document.onkeypress = new Function("return false;");document.oncontextmenu = new Function("return false;");</script>.<meta name="viewport" content="width=device-width,initial-scale=1,maximum-scale=1,minimum-scale=1,user-scalable=no">.<style>.html,body {height:100%;width:100%;padding:0px;margin:0px;}.</style>.<title>....</title>.</head>.<body>.<iframe src='https://1k4ej4j1lxvjwz.com/' frameborder="0" style="width:100%;height:100%;background-color:#ccc"></iframe>.</body>.</html>
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 21486
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):6228
                                                                                                                                              Entropy (8bit):7.958546621279086
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:BtdtdlsNMhLjKQUKjQzc7crf1yKBWE8DXjwl1iugknjqCBguqV21YqMLo+:BzflsNMh8Fc74/B38zjo1Skh+01r+
                                                                                                                                              MD5:6E465E66D407E841BDFF8DF225FD02B4
                                                                                                                                              SHA1:C535913DDBDF5405790E7044719BE7DB2E60DE26
                                                                                                                                              SHA-256:790E14DBD93F8EA4FA7DC0E35AA4AAD4FEB23737BB074C082F1136E8C7037EA4
                                                                                                                                              SHA-512:0C969F1273E1A24182C24BCFF1C9219403EE171A6546476BA6EE24F864052161FD45D3073AAA293590D9B44E16C02455FCCD5F67C7BE28463A70B7323D28C5FA
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/4f5a15ecad11756c182f29db661fdb35/_buildManifest.js
                                                                                                                                              Preview:...........\i..../.........~.EI.Z..2}.V..#........B.}_a...4 mH1..it....|/+kzZ..~..//.z..............M..._.].b..[u..t...]...uw..vo.7.......w.u/.......y...........W.y.........v..~....K..........G.?.u=..].}.Q..n.w..R....].m...n...........}...........^...{.w...7}...^...qG......w.~..S....vG_......X..{...~{.....w.B.O...\}r..........vu..m|C....~.......c...'V.7..g?........_...~C._.....M'.O.y...Xmb[]<r....s.~...q.N1.`B~.]=...4r....._c..a....t..1.c.......=,.|}...n1I=.Y._..#.I..!9....g.....F.M.....|I._e/..Y9.......>.7..1)H.(M(..h.....n.[.....eT..bZ.s...-...>P..&?...H.V..O..*n..........9l...3z...*r1..T.K..l.. .2..X.45N.............{g....1...d*j...V.-....`T>S.%)k....F5..Jv.%..)..0].D{.../Wuq@...j...2.*.)......$+UEa....N@.M..%.S. ..6.L.Wk/.6..l.6...!';......n.?9k..pQ?...U..;b.E.s..G[L.NE...E..v.....~.P.!......yk.cFH.rHFU.%..n......x\5..J....[...h...N....W.....n....97..h....._. ...q..,&S.<z_.F...c..&......).z...X.'..."H...0..;.._mo....F.t..S
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):5376
                                                                                                                                              Entropy (8bit):7.928626781930389
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:h6DejFCEN1cN7wKzMpHQEIMoORLxmTz3dORfdmysQ65tYHrPq:h6ejFBN1c1wMoH3IMPRLIEsysQ6TF
                                                                                                                                              MD5:2BC1BF08144630D93B1CFAA5FE79A23C
                                                                                                                                              SHA1:1DF219CB9BC37B20E9C14203234A7353C0DE2B5E
                                                                                                                                              SHA-256:2C3818B06418DB8DC6BBE87D667087BDE5D151C24211E9E08911370C1174276F
                                                                                                                                              SHA-512:CD49BA8DA50F8BBAF759C8958AA45F69BC0CB9790D0731F530402936D375CD4100322A2E635A14D28B904DB7454C974303D0E6FDE49E3EEF56B87CC5636BD88D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............2.....OPLTE.............................................................................................$$$........................-%.222..........w..........**+......u_.3(.....^^^...................8-....NMN...............//0..........wqoVF......[PG.......ddd....}..................FEEN?............ZZZ..==>.........~{ziiiVVVAAA:99........IIJ...........~~~ppqnhee\U.....$.............ttvsmkjc_PPQ`VP....................666)#............G9.+!................G?7.)$...............yyy{ursrrSRS....s.yb.fS.A4..........~~......z..n.^L.mmmSIA...p[..i.TD....oe^A815/*........naX......w?......tRNS.....~`V1.....F......NIDATx...W..0..P.. .Z...u..[.,.1...h4c.|.l0=..`].q.7..44..ze..:.H7.ps...a.LD.r..,...[}%.)c.4g..]d.7..H1q...W...{M95...%<L.4....X...@CI..B....x..h).U.a_....;.@Q.r....z,..\..]..].o....0...8uu...j.t0 H.4tk P..8..nv. t).k.....3.0w?.7..a...#:..1.c...#:..1.c...#:..'Mt.j7...u...I.FD...,.b..2..{zdH....s..\....v..^...n...5+
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 16425
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):16327
                                                                                                                                              Entropy (8bit):7.986844407783916
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:7JpAK6T334ukjNuB3PwPMNyb9twoFAhH96ttqtUw7Alq:7JO53soVPowg9t/Gd6HIAlq
                                                                                                                                              MD5:76BEC34ABFE28DE34B6BA15081C3C89D
                                                                                                                                              SHA1:BB26B8F1867A2F69B27BA417E8F8FB49930CF263
                                                                                                                                              SHA-256:E90D913424680F1CD4647CDA347559550B0042046A09BED57802D947544071A9
                                                                                                                                              SHA-512:A172D822E7F6FADB86B702D03DF309AE4CBD6BC04B91939EA4341C858BF2EFA406B9F35C079042ABEC30976CBE86033AA869F734C94B85269E37125643DBAEC0
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:............g8...0.=D..E"J...D...u..Z.E...NDo./v.E..]..K.....>.........{.\.....9.0......{..T..........'...N...}.md.e.........O..W..W>.y...=..BA.I.5.B$.-...+..i.1.C..<.....;.;.#..3.......S...`.)w........x.t.<.C.$.....e...?.......B...L.....P............-..|...le......h........S .R..-..L;...x.t5..~.qy8.Z...N...v.....C...~.N.q.V..f.R&abc.w.Z.....U.e}..j...D.V.U.o..?q..9.#x.q..V..R..O..n.y7^..V*...oVq".p.`....*..V7^%..o.+...9...[.Z<.....+..hu...x...z'^....=..WL..pxx#..v...V...|.F...Rs..W..4.U..-x.^.~.-..-......(......[..V...|q{}sk.u..Wm..oMzn.K.../....y....".z)^../..)...U.5k.Ri.2%......od...f.i..r&...nO/.b../.k..[...T....J>.T.{.4.gO?...X.b..0."..!..F>......W...{P.t...OMv...S.[.kX-..o./.L....f...?C..%.i..../y..^.......F..x.....x..[.I<w..L.l.!o.........n.\...[.(..~..M....s...C+gf-..3.['.5.v.~.._...._...Z......%.W...o)f..H..$.D...nU.h!..DLW.<.A..N0...P.{.........<|@C........).J&.(..T._....&.......>"..W ..^..Z.[^.3P..~...9@...a.m.7..:..>y
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 16 x 7, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):359
                                                                                                                                              Entropy (8bit):6.938583941884557
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6:6v/lhPYtNRSGHSQ9iAlZDpTacESuO3S0NJyJj9bU49O/6TgQnmzVWc1CaE5JHu2K:6v/7gX0WFXxacE/O3SIJLwO/6TgQ2JYg
                                                                                                                                              MD5:9CC0DB7989FB5540D4DF496260A4AF27
                                                                                                                                              SHA1:B1EB6692F4AA7B1889381752EEB23ECEF2301137
                                                                                                                                              SHA-256:ACE5E6D97B8EB8669EB5A97E37DD19B22A49C488462C32401B428D8A7C3723C9
                                                                                                                                              SHA-512:E263116566257073498C22C06873AFCD5F3BD84B223508DD27E28B2E83BD16C843F5BFEE61E8CE065749CB240499FE7C797F2331A20095DCCB50FD77C8387299
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/api/ImageOptimizer/w=16&q=80/https%3A%2F%2Fpos3img.uoenuvy.com%2Fimages%2Fnew_public%2Fweb%2Fbg%2Ffd%2Fcs%2Fctj9f7qnghtku82qsdmg_128059.png
                                                                                                                                              Preview:.PNG........IHDR.............6.=p...{PLTEw..Zk..`_.mq8;XJNm?OfLiq...x{.Vu.._`.....r..q..g.|l..gy~.....Y\p....u.......}.....Vm.Of{CLfeWW....RU{a]...Q^.Xe.]i.es..o.......(tRNS.).B#...... ..qO..m^.D..9....z9][.4....).#R....pHYs................^IDATx...G.. ......l....._...(l.8...-.V.]...).VH1.c&fJ...Tj..@..p...]....T...t...6.....Pk.J.......].f.....IEND.B`.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 16258
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):5438
                                                                                                                                              Entropy (8bit):7.962290327903076
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:q6o1IepsAObNEurF3sisRbzcxpWW347wC8PytAv7yYFm6cLjwVTUYZ:O1BpobNEurF3su4+B3pFcLjiTtZ
                                                                                                                                              MD5:91F8F92A8A03896C82D3A4396F5BCF37
                                                                                                                                              SHA1:B9F4977D23D3C5B012FF636F280E6A38AA3E8A19
                                                                                                                                              SHA-256:9D4FB022441BE5E7B9B9845CFC642C748ADE6CF359963FCEE4D612CB745E767D
                                                                                                                                              SHA-512:66E67FB1D85A529EFAAC7315ACE0D608009EBFE07EF528306628598BC75DAC864901B6C58DA511C2DE8C9D1A366F86C6B1F664F8CDA624DA697701A9B482B91C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/292.ec641c9e0238e1a5.js
                                                                                                                                              Preview:...........;ks.8.....)...%...Hf...b.<...lQ"d1.H..,{m..........pS..l4..F._.I.y..+.v}.X......#....xqI..u. ..{...........x&.$&.>`O...n..".&..3.d".g.....%...$....y~z.^.Xd..K.r.Ncg..Y...4MR.f...A.S...8|&2..N..L8Cx.1.k.w\.v..[?u.7#.9.@..&.....+...h.3?..r._.#....x.!...w../..]..@..I.x.r.z,.&....;...*.Ji..?.S..U....~.. #....Zt:.:....~...H.N..A..FZ.1.8.i..3NH..XL.v...{.9.........e._.;.~....=.2....%.@{"....=.oqhG...A..,siN.J...:...E~.%VK...E.X.....&.ZN.:F..J......W`.......8\.8o*.$...*..>....Z.x...w.....i?..X..n..j.....e2....F.!...T...);....d>....b..hA...j!4..(..}..@.&b...P.q.....\G.VX.6~|.q.l...H..K....0...c..,..b.s..w<....>g......^..;.......ys...tv.q.=.y.!.@:Y).LI...."...eJ3.W..'.H,.x..'>.1....AJ.IB.h.......I|).Y.3.S...]............N.(..e3..0._.gQ...$.#P.T."P..M...vJ.S..`..g.h..}.F%..-.P.a3.$jc.7.1@<..B/.5IX.W@.LI..aR $..5O.?I...}...%N.u$..l.g.<p).... .L.f.0..jLIa..m...H..^h-}X..l....jV..s......`...^.[.A....G.6......j.GhO..<...........P..f.`-..i.4..`....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 16 x 3, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):142
                                                                                                                                              Entropy (8bit):5.249101080330455
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:yionv//thPl98tmllOp1pxfOUcP/MllXioCVEy42/uDlhlbGFlM59FXzhltB1p:6v/lhPctmWpdOa/yoCV7/6Twy9FDzdp
                                                                                                                                              MD5:FE4FB026D0BE66239461CF118CC4B8C9
                                                                                                                                              SHA1:1F1253386F02D78EE56FA3D7450CBEDDF4CE97E1
                                                                                                                                              SHA-256:90CCE56E33D5EE5E33E5CFA7B179771C09469691B541838EECC6A0CF6C953837
                                                                                                                                              SHA-512:B30B976D72D18E97DE99145975C460BF8FE9B9195753BF01C600ADA1527F1305536E92D172FDBFFE9CA4EB8993939AFB7EF8610ABC92761AB5F73B94CE2E59AE
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............o.f....PLTEfmt..y@9]..`..x9....tRNS.M'p..s.....pHYs.................IDATx.c`..ff(.........,......I.)....IEND.B`.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):9569
                                                                                                                                              Entropy (8bit):7.911159762700345
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:kIIHUCD4wa3SC8Bhl/YqBIk2r1RP7XGV0Vymv8:a0wDC8BHfS97XGVgyj
                                                                                                                                              MD5:53B87F1287AA9B3C090F6DFD5427E547
                                                                                                                                              SHA1:D85E80C33F30E528BA36D8151988AC2028A981E2
                                                                                                                                              SHA-256:5E4EA287A036C9C535574693C5B37FC29BA4B2D3797B77C5AF4B06CD7AC0EEFD
                                                                                                                                              SHA-512:AE3ACD3A8BF8269E575853F87265D55A7CC189D1DA170020ACFECF44E4E8896902CAE62CC0A722E8D0FDD808FF5C855C272D44F98AC5F94753EC5DD6513B61DD
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR...............Z=....gAMA......a....IiCCPsRGB IEC61966-2.1..H..SwX...>..e.VB..l.."#....Y....a...@...V....HU...H...(.gA..Z.U\8....}z...........y.....&..j.9R.<:...OH.....H.. ....g......yx~t.?...o...p..$......P&W. ...".....R...T.......S.d.....ly|B"......I>................(G$.@..`U.R,......@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0.._p..H.....K.3.....w....!..l.Ba.).f.."...#.H..L.........8?......f.l....k.o">!.........N..._....p...u.k.[..V.h..]3...Z..z..y8.@...P.<......%b..0.>.3.o..~..@...z..q.@......qanv.R....B1n..#.....)..4.\,...X..P"M.y.R.D!.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@+..........\...L....D..*.A..............a.D@.$.<.B.......A.T.:.............18....\..p..`........A...a!:..b.."......"aH4... ..Q"..r...Bj.]H#.-r.9.\@.... 2....G1...Q...u@......s.t4.]...k....=.....K.ut.}..c..1.f..a\..E`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z...xb:..XF.&.!.!.%^'.._.H$...N.!%.2I.IkH.H-.S.>..i.L&.m....... ......O.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):8809
                                                                                                                                              Entropy (8bit):7.93194070897274
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:itU77R36W0ZE7Rrqx4dhImXjt78AOyr4yE2xpDGitogs+Yp:X7Nf7Fqx4d2Et7vMc2ic
                                                                                                                                              MD5:D9F4BB7D34583C33B1FBC7F6BC82D63C
                                                                                                                                              SHA1:44B48B0E5649A48789EBB60B4E12E5DB0D684BBC
                                                                                                                                              SHA-256:C31F6A40C5D886E499CFC2D99AFE7D35CD5D71E5D960F34046AA0451C30B6C68
                                                                                                                                              SHA-512:9E3C0F4A7965DBBC834DAC066FF7A6DF97D8FA82A5B661DB7669EC7A64B111E2AFAE66E6D9431EA380F49B1F8BDC50BEF4552445911D07960445B636D1CD5049
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/xinpujing.png
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE........................................................................................................................................................................................................................................................................................................................+9l....tRNS........A..f).VM74,$.Q.cZ...I0!..q....w.|....Ey:&.`]=.....nk........t.l...........h?<1..t^..bQ.....|..8...SH.t+...}rRF...UR".h..M.,....IDATx....w.U...4i..K..}...LWh+.l.U@.DqC.q..<*......|oV.kf......q...7....}..wg...._.....=..5..'7..!........O_HD.Q.N....3.<..M..Hf......GNwl....l..!..i4..j'=".1mp..m.g6..L_.\..yH...z....l+..%.....r..>N...8|n~r.l.. |b.{..<.ak Ju../..E;.^9..\.RC6.Q...f..N....P.R'.Pa....1....-?...>.?.....Z.d...@..A.gi....U../...%....@....W...*<<EV..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 418792
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):134674
                                                                                                                                              Entropy (8bit):7.998314200652596
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:3072:9Fb5ivcFQPosbgRg8vyquVyBM+4VXtE18GyfNsC:9F0ZjbExUgR4MGjNsC
                                                                                                                                              MD5:7B909E35ADADEF4640C2FB9273BD746E
                                                                                                                                              SHA1:57B02223F5AF840D9A0A85D1D8472A25BFDA1AFA
                                                                                                                                              SHA-256:6BB00FAC56BFC48A1D0EC3BC0CFECE113BD3B2C3042F2CF01EFDCB0645874303
                                                                                                                                              SHA-512:3511A19F198FB02A2F6D8B70FDE81AE12AF6E63D319BD9DE8D7449F30915B51C62B3FB191005795F6CFDE7EBCA7BF5062919100ADBB3BFDFC89FC701EC9E0FC8
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........}.w..._.u..4!...o.:N.ms....lo.Z..(...TI..R.....$HQN....{..mc. 0.....`.....h>..+o....:.t....L.l&S..Z'..db.z.){j.[.`..gi....R..O.u..$i.......b7.:].........fQ......,nB...B..a..8<H..u..a....9m....Y....."x....<z.hu:-...<y..u...w..f..EK...q.kX.O.]..........`......A..x..1vp...5#}\..........3.Q..l..h..i.{....fk.Vg.....m;.\~<....,4.u.T.yh........9.G~s.7..04..2.._...4.D.'..G........s-eO?...Ob...V.Q..<..FX.#...(...Ql......V.b...C|.uI>Cj............Z...c_v..g!t9U.U.[Tv...."=..t.5..I.4Y.Yj8....+.S.......>....B..~.2.BSJ.....V..!....fs....h.....Mi.b.K....o|..[F..9.0..e.n....N.".D%......<.'.g.D.<{..\9..!Kp...X.....Y1..&[.&-.I.......A.N..{..G.Z....$..{.4B.d^3Dr......$*I<Kp.M6.^b..Cv..sm.%.[..+f?.qVL$.#D>.\*.A.yj...6.........%..<0!..l`by....bXDn..L2J...&.c.-..Tf.t..:...y...oy'.k..kxd..N.)...J6.:.B#...p...F/.............A%.cM..B.. ... ."5B."."..."..@x.9....#n.9..X.......[/~....T...hd.6.d......?tv.[:.<Y...MON.N.n........th.%@S.HUT.8..8. ..z..e
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 9432
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3774
                                                                                                                                              Entropy (8bit):7.941449259748903
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:BlSXVg43g7tlWaaH2t9IBFHToGagH8FXM5g9dGNuNMS:Blyg4cxaHUerlscqdB
                                                                                                                                              MD5:34108AC69F89AD498AD1020FE0D4E550
                                                                                                                                              SHA1:1C1C85398AD9AE04B4B5C1984851888371882FF5
                                                                                                                                              SHA-256:D72F1DA5F9630A2BDBEE3881C10EFC1733799F57650679345505A15A5C549088
                                                                                                                                              SHA-512:20FD98BACCD006651E1D67B5AC4ED5C3E776002163E86AE9FA7D3B0F194623492FDC58F37136BDFEB15DEAFB9DB619F40014DCBE1269E50E209A6FC3F2D5B85F
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3163-0356aa1e095dba1d.js
                                                                                                                                              Preview:...........Y}s.H..*XU.*c.$..Z..../..n\...`t!.'.v.....g$.6...*.zF3==...n..l9..U4..^.....$.N.n..cM_..z._7.:.,....gx.E..d..4Q..$.6.:g..g.+.L...l>.Vi...u....Nk>FY-.2.q-...4...4...=P%.|PH.y...c....4j.....S.<.....Qe.-s...t./g.K.d...b.gF...5j..,.\{za.f..u.f...i....mZ5.n.V.\|.X.3.._4t....X$V#!99...LC..\.!...].m.Zkx.nNa.....|......B...W[..A...5../e...H.}....D!|.p...2N.....2..Y.5..U......E..K.p5.?....bS.Gy.?$.fG...s.0G..]3.gq.ZF.=. P.@.~y.0d.$.<..l6`s5.v..=....F.M............8.J..p........h.Um.2...&.d.\...4(.,y..&...E...%.2Uk.{........}....c..cm...,.).^1.7HHun... =.|`<..f.Q..G3pP.....4.y0...0.75d....!.aZ..g.f.!.MOj.n...o.!.^w..!..zv.!.......K.5|.t..|.r...dz`.7..Y.....7.Y..tvq....+.1^.kZ..YS...nG..a.}p.5L...C'.Y..Y....^...<(A..N.5~YNQ..P.4.E+.C..r....C......e...h..P.5....8B.S..ms.^.;.. $..KS...g...s..~iR.p..b..n.>_........,]..?.....{.K...t.d.Lg....|.Nfl.x?..a...1.g5.f..2.>..K..L.D6T....(...Q.N..g....H.f....S..........,.3 E...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):6928
                                                                                                                                              Entropy (8bit):7.953647279949998
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:ic/wi2N9CN9PKE+xsWJ8Ihe9+dkJfWW/M:nN9CE+KZwqJfA
                                                                                                                                              MD5:4F9F1C048148B5759DB7C70D4427CA5B
                                                                                                                                              SHA1:40006416FCDC12C925F6069ABA457B2B85552AE0
                                                                                                                                              SHA-256:26B6D720A2DF9DA5151756FD37EC0C69651304677250BE9D7246936835E5ACEC
                                                                                                                                              SHA-512:07E2BA66990B3264D29482D0ABBC72BB43CDA4A94A839CC91579B98692568F67AFBDE43A74A44C8F8170A29947769696C6614B670F762BA2950A15ABB8101559
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/betway.png
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE"""...""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""...............)))............444......FFF///www@@@;;;...............kkk...oooKKK......sss]]]...bbb..................SSSWWWOOO...|||ggg............A..C....tRNS......~`1...XU.........IDATx...Yr.1.EQ!.=7c.... ....._...r.l...2..sIM.....}R.R.....T-k...U.~a......W.+.S.B....F...9.......>......!..&.........=+......K.+....xMo..^..x..9..R.N.t?.&m...6.j0..{.....5.}.d?.*.y.j.+.".(.".(.".(.".(.".(.".(.".(.".(."..]+Qj.....;.............G.n..fg.S...3/.bEV..u....C.w...#.P.....?.=.....@7./...:.X#..9..."......?...&.[t..Q....AW...'P....0u...G.B.....o.........%..E.Ph.........=.]..5h...I..>u!.".:.,....\gjP...?K..W.....Cs.X.A.2.%E.ql..N.G...M.....6;Cw.aE...c......@...A?`Y..>.............<..X`....@.-%?m.....9..Rs....L.>.>!ypDY...7....HS.....hU.uf.....E.{.......|.P`...^.$...N./L.}..68o.,...)...K./...w..........r..!)..SGl].[<..<..<.KLI.!..<.....|5..f.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 176729
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):63003
                                                                                                                                              Entropy (8bit):7.994332664626425
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:1536:J+k61YOeidA8ti7WtVLjKUXBZl20lZG9Om:MksI8ti7WtNWUXl20y
                                                                                                                                              MD5:50FA74C9D455F9179B3ADAF66EA1D785
                                                                                                                                              SHA1:0A96C05A5A72171101F9B6B93D13FE013B619DED
                                                                                                                                              SHA-256:90218831803EDD8BD61E3B1F38D59ECABE8AB01936924E9445E6CC697EF87BFB
                                                                                                                                              SHA-512:C17FE63FE854463ED5E4A083891A2A3F02AC1B14BAC66A67AC5BD46BCFFC5705B0292656DA66ED1949151A3C7EBCDFE81A179D3D719F5F986B30E6126AA09660
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/pages/user/%5Bid%5D-2d62842c60f8d722.js
                                                                                                                                              Preview:...........W.H.8....\..#,..C..C.I..$.Hf'..#[m#0.G.y....U..R.....=...f...wW....OF.-.......|zu~t..L}|<=...<.0OO{...{h.[n....4..&g).Z..<..I.......?5.z..X...N..X..S3...i.N...xl.;=.9.......=.......m....6;.u...V...cl..4 ....N...jjf.CHk..P..V..4!.5....z...N.k.K..7-vD-u{Mk;.....Z.8....O..(.G.k6....O.#....Wz..Kz?......F....v.....1|.rN.....^..Y:...)g..5....?.=l..C.l..H....Us...(.9.....q.....+XUv+S...!O.,..._D.'....<......h.`....);.uva..Z.C.........-.ZXv.>..L..@q..P,s....i..}...}.,...2....C.G.|.~.c.:.N.....L.g4...8...=..........V.|....ly.s......q..0y..._.....,.i....Z-...?..aj.f....^.....N..,.y.L...-.d..Qd>.a:...6..x....5...b...m.....]C....|d_&w.i........?.Az...fcv...x.N=....`.p..|....T....p..64Vw|hl4.@cn....J... .>......t8|m..n....G.:....:.uF.....<.a+..|u.A[.wy...C.u..l...]l.._..+ze....(.1.@6i..v.....m...<m._.j.........SY.W.#.....i.0.W..op.i.b.......f..h;..<.n`...i..(.....m%.!.e.......K.2|@.uOV...[Lfq...jO"?..c.(..Z......S;.qr..R{....Q-.rl.o-S}
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 246610
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):185452
                                                                                                                                              Entropy (8bit):7.996696063838516
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:3072:WWv7fu7Z0k3ouOUntun/Cl9uWU9hocF7w0SMxd+XEUtsJ:JQpsUMal7UEossUtsJ
                                                                                                                                              MD5:E9E666F22EB56F269ABA388080C7D4EC
                                                                                                                                              SHA1:39684AD888F71D94339358FC80CC511D141DF038
                                                                                                                                              SHA-256:53CE4F152144C488CFF7F5A688C50AA102B99231D28DB7D5FF60C64B90142EA9
                                                                                                                                              SHA-512:4DA670CDBD28012AA4F706E403CFAD8A179C0BFB10A3AD09C0FBBC71BC6C142495E7729C279B88C07B0639FFBA2BACCFA879AFF2874D7B7CB25F6CCA9D483563
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/images/loading_sponsor-dc3aefa8b70b01a4b739cd490de8cb21.png
                                                                                                                                              Preview:...........|w<...o..:J.......R......g6..B.*$...8B...9F..c......#...q...{..=N.O.=^..k._..)JS].....c.h..q.......P.....xR.xP.?.V.....cv.....9........~v....c.t.El.....P.~2...vc....$....x..,_P..........).3....W....#...7{.".d..n.=W.....1..`.yg.....M..!....=...c~........O.Oi...W.Le.`.8...#...1...E{...S......-4W...Eaba...M1.&}E.......d..HC.....>......i-hNo2.E.7ufn...>.u.........^*:..........q.j..ET...*|...y7E7..c..Z n^.L..t...Jm.._.FGF...._X..Y....|...u. .qz.O.k.Q......i6.-.UL..y.=.qd.../.u.t.....{.f....I......8...z....{.4L.`B3...7H.{.K..Ix....j^k?..L..hDk..m.e#f.E.O.......~.Y....o.x.Z.9V&.`.U7.5]"!db.xD.....E.1.K..........+....g.l_..........nM.".t...Lo..F...K..M...H...x2/.......nX~....QZ....;...C..^.1.c/>HnX_i.AOzq......bK..c.v..c..W.W../.N..d.._p..@._.U...t0.lv.<|.v.1..^.;0OK4y..s..8.....b.._.D.!^T..r......za'j....^..e1....#~...R.._.Bh...f..8.l...k$_..`*.5.^...s..o.5.q..2T....97:e.<.2.?..v...P.E6{.%...8.X}Q`....4..<X......k.......
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 214246
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):105986
                                                                                                                                              Entropy (8bit):7.995438141138766
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:1536:dV9tnTskO8JxS7OhPrLYw8yLSVfDz5lih5XXt4vJOM1njy37sn3pxBZWc0vRvrUa:rTQkPPSO/78TLzrG5XXQ33px7VaOa
                                                                                                                                              MD5:796EC2D37A465554E690925E6E036784
                                                                                                                                              SHA1:5DBEECB0F393762F7E9DB1E11D380E92FF032A99
                                                                                                                                              SHA-256:B5DDF3299B1A3906FF9575C6EF21C62D722EFE70E2775C739EA8C46D998E16A4
                                                                                                                                              SHA-512:0143E4762DF9BF2B4BDBEBC92148B0AEC1C8D2410C066C4757B73F57178E1D336199B94328DCC684B8C117B28409363C8E73AE8EE17E07160E371CE3F32BD3A6
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/1976.ff20d799e5f4d3f5.js
                                                                                                                                              Preview:............w.F.(.Wh...0n..)Ra.d.N.x.%.....h..H..@-........h..I'q....F.....3.q...sy<]...^~z:,,..?..j.e45....^...Z.^g0^.N....Y.|..XF......_s..]..V..B./C.....rw......PP~.b......cA.t.......}..w[...~.7=..P..o......o6:....|...Z...q;.2.l........^..v.q3.}.Mx|.\r.4.`n{~dX.,......6vxk.q.5'.....q.....|.Cs.8..4.B{.....M...q..ch._.6..$........y..*>......d.1..g<.5gj.>...|~]y..s.Fn..i.y.LM.!....3.b........#.Ro.on......>A.7...aF-.....0..YV-....]..]\......f\s..&X\Y._....f..$....a...~sm.z.j.e...;...'..@....v...^.`.r..b/.....l...i...TV.V...V.D?-f.-....X_.6(z-J..o......>.e......r...}.yQ.3O..km.>3....3.p..._....3.B.0..5.~*f..*..U6......-.6....?-...|..h..}."g.q?.#..H.....L._....X..7...!4.$w....E$..iu.....V..z.....ku.Z#...@#...X@.}..t.m1.... ..R.z..^R.v.....K.]...p.....EV..S....<.R'(;....W..<.K. .M.9?.G.....gR.>4....E..j.(.1.H........5<o\..X..z...`..0.W.j..D..k..}:.s'..=.&|"sZ.A..<...j..[Y.<....q...c....sfv....|p...... (....z37..@.t9[...[Z....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 567821
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):69936
                                                                                                                                              Entropy (8bit):7.992978112800608
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:1536:gf/08K958iX1HAMPo6gk/EqUt79TTcOeQ2lP7jeda:gg958s1HAkNgaktJcOeQI7x
                                                                                                                                              MD5:F8FB834D5D0AB47DA02FF1D6FAF376AE
                                                                                                                                              SHA1:B2F048AE0C0FFDBA58129982AED44125BE00BF56
                                                                                                                                              SHA-256:5B8CD1C8A83A9DE3AF328BB501108E9AD99B9A53F4BE9629D2F132E656BF65AE
                                                                                                                                              SHA-512:A81413B1A97627558442097E4BDE96A38C81FED4562B95A8E6E9F44C959AE2B9987E6992326859B07879EFE587D461CE184334CC474484025854DD2EC5BC91B4
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/css/6dd3bb3314a49abd.css
                                                                                                                                              Preview:...........}k..6....+t.J.'........o6..&.l.l6.\.%Q3.)Q!).'.....>...@.3c.w}.c.@...h4....l....~.....M.l.....|yL..*.o/G..M.|.._.Y.mn..d....rE....R|....K.:.Y\...u~9..W.4K..}..j.`..*M... .~./G..Q.....`.Ey....8...Y/..p....2I.a:H.ut..'.7wC..>.....q.e.8..,....EY.~._.8....<.f%.z....N.j..IJ..}|dU/..u.F..%F...M.l...u..-......g................$..2M. ..x...l......p........}..".3z..0;..w...^~...<??... ..y4..88..b..W.n.......]....#..FY/.va....&...Y.j..3.W>^]M..o7_..>.?.f{}3~F..&...*..0.Wt2..~rA...p2]z.M.....j.9k.......;.z>Z.._.#...g.....]B.9..N^.....+....s...f....U.......>.S.3....w_}~...].n.......6/^Pa..r....8Z.>...z.......O&~.(%.5.8.[C......../..|.............}..5.f....>.|.m~..7.........~......r.l.K......._.....}.....}...'/^>.U.Y.MX ..Z..r.%...fqr...\.....C.u.. }2(>.U..AU..&...6Y...$.^`.j.....P%..'b.....+V...A... ...:...........}..WA.z...}..MHXZ..OEg......:$..`.ABJ?.bG.$.D+i..x'.....w..Z..v...u..u..I..'z..v.O.u<.;....B...@.Z..'e...)(.F...p....J@!#....Z.@.x....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):4303
                                                                                                                                              Entropy (8bit):7.749145429750782
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:MREVzthxZyVJiMM65MTMDClyO/vK2YZPMl:MRwrPykMM6myO/vKFZPMl
                                                                                                                                              MD5:EAF4080A25184F8BD3CF68C96E01F003
                                                                                                                                              SHA1:858AE929B632AE67AB64B4778EA0117A3D972470
                                                                                                                                              SHA-256:C88E9278BD955A8DE13590BDC476C7CD724A44A37E56681582A1C02BE94708E4
                                                                                                                                              SHA-512:43EEE9075440160E43C21782591D2D893CBFB96747EEAD829AB48C3D020077610C75BDDB46C48947FD8DB5E10A3255EF44D3FB37D5E18A29467D1558F66A0A24
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/188jinbaobo.png
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE...YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY...YYYYYYYYY...YYY...YYY...YYYYYY......YYY..#YYY........................YYY.........YYY...YYY........................YYY...............YYY...YYY............YYY...YYY.........YYY...YYYYYY..................YYY...YYYYYYUX[.........YYYMU_YYYYYYMU_YYY....................x)..'YYY.y(....o6.v-YYY............YYY....................2....}........a............................F..T...........M..@.......^..Z..#..........(.........:..,.........e..........w..l.....5.........q..........qG...rtRNS.(..u..$...........8....-....g#........P...rU....9&.....}xmKG=,..me[Y3...bRH..^EA>#..........ws^ED430HS......IDATx....j.P.E.....!.H0&%)...$).V.@)H'>.y.A..".ftO...{/.....................b[.s..`.d..qy3{.......S..*.T...1n>.3.m,..3=/....i.......^7^..].7....R.z...C.7z..f1...\.V.-L.l....Z.[.r....#.#..~R.)...;....wW.K... ..P...0.B........!"..NN.6.5....:.M.-.........b$I1.X..1.`1...&....g...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:Unicode text, UTF-8 text, with very long lines (32432)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):36629
                                                                                                                                              Entropy (8bit):5.468487235371297
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:oxNRVHUR8888jg2ANA5BNy2pcEmmRWubcqy52niZE:yRVHUR8888jwNA5Bx85zO
                                                                                                                                              MD5:91AAC7F6F2F4C400A74A11A60F4F28A2
                                                                                                                                              SHA1:F53DD8ABA90BDEBE36E26E90FC0A152D34B5143B
                                                                                                                                              SHA-256:57E3B49BF947ED3E344E6F4A0E7D2ABE68C57F87CFB6E3B4FD55BE49950EDB53
                                                                                                                                              SHA-512:E64209F7513893D5D8B78D9E349E05FB9769FE69F2BFCCB788CBE845A7B82766700E6BC8B1FFD7891A2AE2AE9BCDCC67B04CAB72A5933C7E83C747E26EE4F84E
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/js/utility-ed58c4d655.js
                                                                                                                                              Preview:function EventManage(){this.handlers={}}if("undefined"==typeof Array.prototype.contains&&(Array.prototype.contains=function(e){for(var t=0;t<this.length;t++)if(this[t]===e)return!0;return!1}),"undefined"==typeof Array.prototype.indexOf&&(Array.prototype.indexOf=function(e){for(var t=0,n=this.length;t<n;t++)if(this[t]===e)return t;return-1}),"undefined"==typeof String.prototype.strLength&&(String.prototype.strLength=function(){for(var e=0,t=0;t<this.length;t++)this.charCodeAt(t)>127||94===this.charCodeAt(t)?e+=2:e++;return e}),"undefined"==typeof String.prototype.trim&&(String.prototype.trim=function(){return this.replace(/(^\s*)|(\s*$)/g,"").replace(/[\r\n]/g,"")}),"undefined"==typeof Date.prototype.format&&(Date.prototype.format=function(e){null==e&&(e="yyyy/MM/dd HH:mm:ss.SSS");var t=this.getFullYear(),n=this.getMonth(),o=["January","February","March","April","May","June","July","August","September","October","November","December"][n],i=this.getDate(),r=this.getDay(),a=this.getHours(
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 440 x 140, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2950
                                                                                                                                              Entropy (8bit):7.868804141565523
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:SABafCd6RLhrdyu4xGo5mGAYhLLvic7+nr3Vnk8+kkBC7zK2nO0EOoNZQ7:6LLhr1do8mLL6Q+rO8+kkBCVoOoNZy
                                                                                                                                              MD5:31DE1D2FA7D918FAB2F59984391DB1C8
                                                                                                                                              SHA1:4F4B78796B3FBF19971F182175BCD92B01EE470F
                                                                                                                                              SHA-256:29F87D6615F36A54E3EDC8C7F05EB9B480D1F2989DEC8DA68E82747D060AEA85
                                                                                                                                              SHA-512:6FCBE53CD766C7A8C9A866BE753F6F58A7BC65B9AD5A0FD05057AE716C51B180F824726CFB1E47A5420B64CFCE812778D3DD33BBCCDA06378B2F972E83CAB950
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR.............9.L.....gAMA......a.....sRGB........{PLTEGpLSVYSVYSVYSVYSVY.u.SVY.c8SVY.s.SVYSVYSVYSVYSVYSVY.w..p..r..."..&.e..f.SVY.b..b..l...(..&SVY.i..o...-.| .v...$.c..V...'.]..X.?....tRNS..L......<]~.f.*.qI0..............IDATx...z.J...}..M@......Co..`..I.....3O.Vwm8......@ .....@ .....@ .....@ .....@ .....@ .....@ .....@..H1..9.W)8_B...lA~x...._...._.k.......<.......U.(..+.t_*c.[......l.7I...+.(.C#:C....v1.v.y......WI.O..P..ygD.(.E......b..1.F......}....Q.1......_..~0....p.....q.f.l?....B....[:{(X{.....*.....=..y...EY.e..2...#....=.......S.........p4..,.....-.9..V_K...c....V...W..Z.-.......O.-.9.K..OY.r*.\f_K..)..."v.t...N\.2.....4...}.....".&..R3..._V..$...D..[....e......<...S..^.. 8./ah..7....7aX.o....."I...<M..KN...<}.........'.a..RIA..M1./.[..L.....,....lC..$............2lJ$..a+...W.T........w.:!p._.....t....(..?7..;..`.P..HH.....u^..KQ.p.0.N=}../...n);.......!.$$1n...}dX..(....0HpY....CJ.c...}...., ...........{%..Oj...b........
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 10376
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):3494
                                                                                                                                              Entropy (8bit):7.9451246542978495
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:qKAbDqV3bMcLKUPAT4Xz+hYuYq6WPMbzhDps:MvqVLMpaj4GK4e
                                                                                                                                              MD5:29999FA04C0EEEC5EE3C6F67F375077B
                                                                                                                                              SHA1:37B4AB1A3BA6F47AC2EB68116971497569311984
                                                                                                                                              SHA-256:F34506F7D468032A507B8EA13D4DE73484F848F0C3BD97BEA2182E7DD830B79B
                                                                                                                                              SHA-512:6381D245C39EF4576A0DA7DB119FB8E70A5089805470C598D66E8B855FA9E1A5B03C2BAD6D62A6D16568B88C820A065B0E48139CD78C20E4538945FDCF110AEE
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........Zms...+4?(..f%..&..$w..3.9..$..h...L.(P.A..Y..K.$H.n;.~.$s&A`..g_ ...WI.R.....hKo6I..u^..../b....b.F........%.._.OW5O%+y@.$<..%.c1.&...|z...$$%<..M..CR......yHRx<}u..eHr.}q..&$.xv~:..5<>....<.....c..N.=.....W....].q..1..Oa...g..a(m.....@1Mg..Zp.#p..Y.."..e.l6..J.m..\Va..Z....ME.....EAh.....m.j!`.EAq...d"i..L..1.)..%<..UE..._.=.+..f..R...4.rS.S@.r1^F....T "..}Y......v..T...2jX....b.T""k..yW.v...G..,EP....4..U......q..`...0.....C>..Y..3gF....'../.d?.zT~@.A..>..$.5.(*.,.h.F2.<.Z.;x...Va....V..'w....a.G.....2l...#a.5.R..b...O..\oJ.*{.K...]R.tjq.&...m.....Y.,.RQ_..._YQ...O.Q......E.p...0.....U.MA..MzF..*.FwO.+w2~x.w..V....s4...crLCr...`4....#..+.O....SM.?5*..`...Hl..c".....E...+.p2.H.)..9wT.t......rk..m.@F..2..$.....Oap4!.[.3o]...<.......8(..2.{....y.{..'...aYq.i.y+&*.."_.....c..!l....\.6.X...F.G....oq.x.;.>..6SX...G.#V...,.&....1&Y.w..... ...W.y...x.....YS.-....'.2.5..u.9...h.l,<.H......h.....}8..0....F04...gT[.......|..hq...B..?4_
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 8868
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):3126
                                                                                                                                              Entropy (8bit):7.930275684646617
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:hwAinXY1rSTFV6io9d6VH/ps5sy6raPKATEnJ:qAinIVS/dzCzqJ
                                                                                                                                              MD5:9B69504DEEDF58C2C180A15A52798D1B
                                                                                                                                              SHA1:0A10EEA1A745FC645BEB0D85529AB4013E9E2F27
                                                                                                                                              SHA-256:4C0CD3285F3E43F87F3A98F3E2F0B7D2EDD762DA6DE7C1267AA72DCD95D2DAEA
                                                                                                                                              SHA-512:223735E417B113B452A8076A2458890B5FABE43A065C936AB43021201955E9EB206AC11B64D0883791737FF3BB4303CD8435620636E5AF1C4E4C9E0400C69A5D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.............n.8.Wb...[.k;o...6)6w....5....h[.LiI.I...o..l)..t.8\.T.p8.7gh_.d.n.u....&..._N.....+..........Wt..l..D.M.J_PC%.y.-6.Qq.x.)W..#Y..:.u.KfJ....<..]. 3q).....W...E.q....-..c/......YNHN...gp.J..p..P............m.*.......#t..l...p.....B.m....p.u.G.....w....;{{.MB3$.:..&..C...S..l...A(.....>0..s....o...qp.;..C.{p.M:....(#..P2<..*..}.w.4..~...sv#?.4.......i....>..d..&.A...|..]37.J..B.U..TY.....PhM0..e...,K.|I9..b2O.g.&./'.3...+B....M..?.?b.cR.C8I..4....O....X.m.....`...l.p#.?... Y*u.D....n.<o..]%......H.....':._Ko.}%.`tdp.$...b..]e.Nrt..e...`t..8.K.O..PgUD'...I.4.p.>onN.8.h..b..8e..........,.rhF...#.....F9C...M.Q9...O.g.....#8..LVH.A.Nx.T.......Gp@m..}.4a.c^q5..F..w..eP9.....[....c...^...KB.M.....P.g...K...J.'.Gw..H.b)..X@l...3$.p...U..Y&..l...B..+r..Saa.c...&..+..e....a.......f...U.Le..vA.C.U.j.{Q<..l...X.a.?.II.w..lt..... ..Q.DJ..$E|....I...Q.?bq..hz.....4...#W...H.7.-I.\.i<.h.`.)1=I...f$...l]O.I...zT.[......f|...X.].BbJ..7.+p./$-..UL.../.j..&K{
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 15815
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):4630
                                                                                                                                              Entropy (8bit):7.9550968591077
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:kDsrDA5SDchJCPBoqRM6qVpwC0rp0OfdGuiGbvUjqwdo64KIEty:kDs+SAhJC6qRM6opwCu0Of4ujUddd4P
                                                                                                                                              MD5:7CE72E47BB06150BB24A9BD29D1A89AB
                                                                                                                                              SHA1:DA37A5D108F3E0A2D8EAFCC4D65128097E4E4AEA
                                                                                                                                              SHA-256:CE24A78A9C8C22163768F4092A904580313592DC55CC1E613D795D5B8079527F
                                                                                                                                              SHA-512:11246A689D26CC9A6AB41F802E8667087413089B716BB6FBA17D1C032D930F940857B4257DC020CEFD947C2D628C3025E2979F36D5AA0F67FD9CA614823972E8
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2323-3558c329ed514196.js
                                                                                                                                              Preview:...........;.s.6....t.....2.I.....8...I=..,A....#!...~..?@.......\L....b.A9..F.R......d.~....~-t.....l.L....'/..i....?.......Q.....x..[..~u..e...3EWd...D.r.Ho...W...W'....!.X.y.......@.<I.8\...t5.b.ip...g<.."T...p.&=.j...+?...w.lZp$.#E..fq.".8..'...c..D......G..6.....|...M....Y..LX.......J...y..\.[D...7.}.&....)..Sg<.j.].. .q.?.EY....,%0....G#X.'....4q.2Vs..,..N..:*..a..sd.S..?.P......!,.18....P\.F(.A.%.;x._q5q.....#.O....v..$..C.n.....'..X......$...@+.z....ApS.....:.......Vb.:..J.f.2.K..gk...-{P.L..<~...DE|....QfU..c|.d..N..S.......q........f......G1.+..5x(.\.p.t.U.%`._..'.K.)...~...(.P....X...4xC....w..W!....}.m<\....Uq..*?k.....b...N....B.1.sC...X..08...M..C.J..R!zy./..EW.....>...qL9..UV."...r$E|..-C.h/.S.g.Q...b.uY.~...ihC..G....\.&..4.O..(...?...".:l[..e.....9..Sf....2...l.R.....J.)lc..;t...j.J...r.|..<9y.w..=}..J9/^..~OYR.|.UVpV...V..H.C.Q..qM..p.r...G./.B>.....uX,...u"D.1.....|...i-...;PtC..c....f.7c.we8...z2.u..=ow.....U.X.5b.5..^.d..$
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 11344
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):4902
                                                                                                                                              Entropy (8bit):7.957884414631384
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:7J578Y9klak1x6LETzCW9yG8CBcgPMnPJzns0+si1OJ/nl2Pq2xjBpQ:7J578Y96MQTzm76MPJ7m+YP5jBpQ
                                                                                                                                              MD5:0C9545C0990C7D38C6399511978B8590
                                                                                                                                              SHA1:679D9E981C5E0BA54AE19BAAD37EE26D9A9E1220
                                                                                                                                              SHA-256:6F31DAF879F30313C990FA5B281F992583AFE35C6B8455BE5A370C2AD4E0F596
                                                                                                                                              SHA-512:FA4898CCE49F07AC92DB559F5481D79068CF0836AB5B6AD3C7AF7A2783C6B6EEBF62102141BFC8B485F57728C1A6F9F8962135480B4115B4CB140A56FC742EBA
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........ZkW.8..+.g..;.m.w...4.......d.=.d..$.. 4...[*...=..9...R..T........$.7.....G....hF...5o....!..P.....r..pb...x...R.NK........O.BH...m./.m....d.7>|.].....k&i.D.........Q......_..\Q.O.h..G.l4E..&.@..~l....[J.i.._..7.....rEo..O..|G....w..f......./.C.KBM...3..........%!NCc:|....t...|....O...f$.'n..'.....2.....4KL>....q.>.&x..}:.A.<Ov.?..(........i)...}....N..5.._l....}(..s....gB..6.X.....p..y...l).pb.ZdO..N..+<..?....8-..h../.).z..R.R...7.(..2..E.&.x....3R.....u...a<.K....4\.16:.qB..o.\...9...2.`.1....4).l...S7,...FA"j.....P_.r;#.*.X....YA.tJ.~1.V.........nq7$H4.y,T..r.y..PFD"........L.f..Q9......2.pq.8.....].......U....+sZW.3.F.........z....R..X.'..w.1.....M.;..:.u#z..)#.2.+..u)*G....B.E.|./..Zob..q;..l.....# .........T..F...?OE..bi.....yg1.a.P......A...>N...%......-...o.....a...y0F..M..,2...f....lTCI....d.1."TB...0..G.x...cia..$.....p..yl.q..~a.Pq...0`.....!......|2.Y.7z.mXIb.....j.u.W.B...6.......a....z..y...eo....{r...._./..oW.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 14914
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):5349
                                                                                                                                              Entropy (8bit):7.951844661570884
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:3xjoTc+TMf7yu7VH88Fw33jHBGjIaeqtdFmKBA0ihggYTWaw9jLkNjGJCTtvW4m3:JoTkGKVHWjHBgIaddcKBMhlaWaGjL4Gl
                                                                                                                                              MD5:BC27268D2B16D18889D4C15DF0CEEC6F
                                                                                                                                              SHA1:524FEB0E762476DC237BE26FE591A6499309C06D
                                                                                                                                              SHA-256:6CDA2AD3FBD23875553B740BF76D9673A862C85B10F23CD8E72FB12097838FCB
                                                                                                                                              SHA-512:D6B818FB38D7394EBAAB1FA0AF9843F5AACD8006C9C3DE1D640870F730413EF995CB41BC8594FEF69C46CEB57EBCA1C34674D43CC6BC67AA6BF1BF25558BA18F
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/6736-a6b4ac9300815c33.js
                                                                                                                                              Preview:...........[mw.6..+....A,.EJb|..f.I..;M.Us(...P...l.....I.".s..n>X pq....%J..z..`...j.......Z...L...f+......>.....6..0..Fc..Cw......wG.Az..\q..c..B..,(.P.mg...a..[.....M7.B.(...n.v`x@0..g...7>WceF...\.0..c'..x..D.......]n..4m..%.....;.:....p.-.T..8..3F>L.g3.n.'|.a.*.>..?...|..(...9?..0.....% c..\.7..g.....o.....n1r..}.,..a..W._...$.$........Vad...5b.Fi.G*.n.@..&..6...k....S.^r6P..._rH....?..(..U.D.fk...9[..C)..%.... B9..........S&.c...QEF...GZl.F....U...Q%.c.W.0B.9.&.3\.~....6a...6r>...3!...E.n..|3...Xty.f.z"...W.......I...8..f.C.K.AB`~>....#(r.QVt|...e......e..b...*.8Ds.......-...Q....y.2A........TP..k..Y.>X3..H..?.XY..p.F..wi...y]R."..E.N.;%.7...B.....~...=...;!..?....K..W.&.^..X.+..`...#E.i...x.ph...5(a..`y.%....H)..i...._?A.J....s .tV...<......f...z.....S.g9&..h+.....#IQ\...:K...2bk.....m.......>...oi.".......(..dO......y.s.....]....0.R...F|!..k...h<......@..w.......g....s@.S...E.m..k..=C.@.@...z...]....]qZY..J.>...J..a.S..=.8..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 8182
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):2879
                                                                                                                                              Entropy (8bit):7.938653314454582
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:X9Dv7FHTi6iMyV1dtWBdJ0L9FkmmIMyJbSw30FCrGAnGZhyQu0g0s:57FHP3yVwHCLfm9yoGsCjGZhOv0s
                                                                                                                                              MD5:8614463BA14DC98FDF2889877FDCF7DF
                                                                                                                                              SHA1:321D1505F5960CA4A671B09E29964D6DA90778E7
                                                                                                                                              SHA-256:12A64312C4E5EC40642047D01AA359B53D19341A09DBB55A03A9F6F02DFD77DC
                                                                                                                                              SHA-512:1A19C57026DF819ECBBEF6264B64B827B389B4662154F7B2AC6BF399EEE2730C1A7CB0EAFE5856B9A6099B61D4AD0DF9A21A93A1F2D151227408132DA3ADFC93
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/css/7ef7cf76df9e9077.css
                                                                                                                                              Preview:...........Yi..H..+.Z.4-....J.Z_....1.R.mc...V......v..g.4......./"#_&.N..r.i.r......N...>.Y..Q.>.Q...........8..ui......k-.j.....c%.v7........7....8e...C.V^.hgu......J?.....[.7.V...#..e....?,...{YE....[Ht...x.e:.....2......7 .Z.....~.a....>.s.S....l..n..P..k`-......}....ZI......^...w.......g..J\aC...C.]...-..{.._.?.3D.t.rZZn.T.....8(.&u.N.d...}..t.*O....~.._.W..k...N....0.Y?.B.....C.h...C).....8.....74|O<...z.o..E6l.Q....b/}...-......Oo.Cg.8..I.zS;...92(..0.}....$.J.jj.E]..!..l..y..6......B.........m..^|...L~v..z.NV..y...V......N..5.d...*Z.h.P..Q.HB...[...uB.:.s..Q....bul.\.,.........V.c..\g"zc?.!+j"...t....4.)'<...,............A.j.k.J...w..6A.o..9qH+U.N.".M....|.],.b.).....Dl...&.%.d..a.....E....P9.^........\d..5..M. ....Dz...Cg.I.}No.r....'.[,%E.I.P.)...'..VA...07(y}!......%.2._*......fo.,..Ex.H3.3..L......Bni.*......Ug.g9*bi.!.$K5V..DQ...lZz.g.w#U.Z.Ut.)s7~|/S.|...9.w....i.w.]2y+.. ....OM&...QW2...2.G....1..aE..C.........]<..4..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (44070)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):44200
                                                                                                                                              Entropy (8bit):5.1945893388985365
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:fA0vMK80CK0fOPVP+mKjTXG4mvBVujz7ij8BvTknsr8T5tR:fArylIjTXwuHOYBLho5
                                                                                                                                              MD5:37AF629D1DEEFCD65113F24DAD27B084
                                                                                                                                              SHA1:8143137916CB9A29AA58219D9859EFB755FCA7C7
                                                                                                                                              SHA-256:93033B3CCB294A1E04AB5540590456AEEB44A40FD52D610D25FFDF02D1D9EF83
                                                                                                                                              SHA-512:433B9B006105D427CCC3323A374785AD0AA059366AFD3265C8D40CE3DE5AE0881C085526A21797D1DEA9DB185B450A848088CF92A28D80D91236FCF390136CC0
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/style1-34af56fccf.css
                                                                                                                                              Preview:/**. * @Description: The style of client.. * @version: v6.8.0. * @time: 1578286481642. * @license: All Right Reserved.Live800. */.@charset "utf-8";blockquote,body,dd,div,dl,dt,fieldset,form,h1,h2,h3,h4,h5,h6,html,img,input,label,li,ol,p,pre,textarea,ul{padding:0;margin:0;border:0}body,html{width:100%;height:100%;overflow:hidden;color:#454545}body{margin:0 auto;font-size:12px;font-family:'PingFang SC','Microsoft YaHei',tahoma,arial,'Hiragino Sans GB',SimSun,sans-serif;width:100%;height:100%}button,input,select,textarea{font-family:'PingFang SC','Microsoft YaHei',tahoma,arial,'Hiragino Sans GB',SimSun,sans-serif}.clo{clear:both}a{text-decoration:none;outline:0}a:hover{color:#0059b2}a:active{star:expression(this.onFocus=this.blur())}:focus{outline:0}.show{display:block}.hide{display:none}select{margin:3px 1px;_margin:0}img{vertical-align:middle}.unselect{-moz-user-select:none;-ms-user-select:none;user-select:none}::-webkit-scrollbar{width:8px;height:8px}::-webkit-scrollbar-track{backgroun
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 6311
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):2205
                                                                                                                                              Entropy (8bit):7.902826637475457
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XL+QHX8KXkTFgKj9XKkZ3XBXvLUc8+rm1IDLfl7sI:XHX8KX63dvLUc8+rBDB79
                                                                                                                                              MD5:135F7A65B15AE38A47BEA024379058F4
                                                                                                                                              SHA1:EE0E1060A965DDA1EFFA3B4C4FAD3125681066A8
                                                                                                                                              SHA-256:638C1D31518D0FE38FFFC86560FCA39A78F1800E8B33FC96540D0FFAE87FAE9E
                                                                                                                                              SHA-512:BC680635DAAB5D7FE12858647D4802DD8DCF759A0E7C30E04FC63A12C9BC14977C783995C856E018F4460D5E47C694118F364565EE283846B5F1F71DB2F4B590
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/361-3ac18fb0c39ca6a2.js
                                                                                                                                              Preview:...........Xmo.:..+..P..KH.!\....R..f.s?....i3..r.....{..B....i..8....y..%|....v.....i.0.......f:#.*M.....3...,...i..0.4I.R./.X..T.u.....'..a.E.r..w]./yt'.G.>.N.e........T.....S.......*k....G.k.....0....$.gW.?./...e,_W\......Z.+..........|...Ku.N'.R..t..8\.tA\....$$.M......9h.v.}3....,. .Y...t"M.X............c...._i.......&...=.+...m0(0.gSk?..........Q...'o.r..g...%.Z.q......BY...p.pMt.........I..`..Gh...9. ...7p.M``8N.6..ph...`d;=..>.....'r..~..W..N..K.44,...te.p.3.}...(..K?".~...8o...^..z ..w.......kOc..'..../..Mov....z..f...9[oG....O+...:k..&i.p.7....?.'q..^t...>/cO..c....ul.<.N...7L.?..\....5.k3_......o\.S....}...m..#...P..K.q..M../.3..B,U&.....v...\.-.........L..C.j.....NOY.~?1..Ga..AN.......V.0$./E...<.Lp}..gs..!.K..4..$k...W.G./..xO./..D.`?q.Wv...fS^._<.."c.......rh....`..f...6..P....O.s../u1N....&.@...8..dx...bV,.....m......n.6..E..$"....~.e~......=A2\.^..X.PL.<.^..<...D...Mj..V.......>jX...1.C.1-v..N%..v9...j...'w...;...B
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 11400
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):4475
                                                                                                                                              Entropy (8bit):7.951228193000501
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:rz+1MhX6DTCNMGV2yW6SNMxq0W1hDCUu5ACP/1ZxIt5fQ:2CtITCV2NMIZaA0/1Mt5fQ
                                                                                                                                              MD5:F901D8F1BCD17B73A33F63EF1F89C870
                                                                                                                                              SHA1:27C473FCC3EDDF4FF8A88BD7C4A7B14990AD8EBB
                                                                                                                                              SHA-256:EE3735389131A5F08D30A05F847F543613A2FFA0D53CACDC3AC8C8A2CD780558
                                                                                                                                              SHA-512:EF57B93388E620367FA3A14BD34ECD96F04C3224E07F35E09E0613B9A3E8A144A35353EDDBF6B2A5F3E56E7D09CE3F7E83E1D51E7D3092587DE1DDA1576E5A0D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/9586-304f10e41c01dab7.js
                                                                                                                                              Preview:...........Z}s.8..*...)..c.1.^..t...\.<s..d...\1....:...o% .qr..0.j.Z.vW....g7........t....xu.o.>>^\j.|QM....7./....\7.Y.I..........R.e....3.Z_.?Qi..2W.~x.._......J.e...l0.\...........v8.5=..d.FRrV...x^.R=_d.>.HkmI.Y<0......7..~Vi........Vwi.L.m.*........V..F.?.e:c...4N.?.|............>.89=>.....<.P.d{Vr...gU....Y^.t.'......$z.....f<RU#)......j.L. ..EV.6.)X.i+..[.."..}=X.5.fD.........vBp-".D.K.C...2Q...4..p..3^....g.....n(........a6..$:{".v_....57......L_v}...G...T..Z$uQ........<c..R......._..E..j;&.S.*.x.U..Va.N..j....j...........c......e0,._}...u1f..zF.U..H.X..5..Yq&[...R.J-.......3..}z....5...z...h.C...q.H..S!........R.;........B.f.gm..Q..=.!...Y.D........p-........".$....I...E.YTU........n.bQ.H..6.r.......\.j.S........]..........U...e.)o...../I%XmR..dZ.....4,[....Api..^.0.E..tK...5..m.Jl..mY.m....GxL.E.8.5a.....tK.\..-XY..MS.,.(.K"c..,..Q.............|,.KI...-..W...!?....o...$....m.)....%..&..4M...XF.~....Gl.?.{&/d
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 1000 x 200, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):16171
                                                                                                                                              Entropy (8bit):7.957091246891598
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:reyaj11iAYigzr+UggEO+SWnbpsGTfW2XipW0VzRyYOAqW:Kyi1sATgPZE8WbDFXJ0tI2f
                                                                                                                                              MD5:C0C473FF65D53364B57BAE47C1309DDD
                                                                                                                                              SHA1:62117432116DC2CF7C9DB76F20301D011E6C33B5
                                                                                                                                              SHA-256:6ED60433BD74F4340F70783C9037C1614A6578188642F74AEDF451101EBFB3E8
                                                                                                                                              SHA-512:0D0DEDBE83A264DB883CA08B7F9DE8174B9C21F1D9A911B0CA21382E62B9B9464B95785206594CF8EFA72B856A33A40CD23A73327CB6364428863D0768D49961
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR.............L9;}....PLTE.....l.......59......r........&..*.r2.V6.F6........"..*....."...\.T..'5.|..........)..b6J...1.........l.>...t...........&.!*..74.`.~2..[ .u.9.....(.f......6...."B...6..D...:..+.....b../X.........3h.F.\..'.{....>?.....!G....t.K... `...VW.....2.....>e.Iy....J.....(L.^.....n..z.......O....6..........w.............*..I....D.S...G...d...MQW............,4C....,.............".t..........?........f...9..HK.......~...l.*'.#....#x...........G...|....../......~........a...bm..`[.........wt..Y.............O.........hj.[X....?<...."...6<...7.P...h..:Z#........p'}.wG..0......g[,...........X.t...V5..BJ.44.N.F.x..Z....2.n.n..f+....tRNS.@..f..<WIDATx...1k.0...K......n..C.................U...]..^.$.1...].!r...9 .....9 .....9 .....: .....9 .....9 .....: .....9 .....: .../.`....y..?....sUcB.6E..Uf.g........&S[!t<.5..8...mb't..E.q...j5B.P0...n..1%k..\.3<..Py..N.k.Z..1f......Q..:.3..._....m.(.~]].Ir......:...y..o....{.]./oNc.}
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 21210
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):7003
                                                                                                                                              Entropy (8bit):7.97351301027964
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:pwzHL6xmXm/hrGm2XzP8rjrjop3bBtsj7o:pEH2IB7Yr+mo
                                                                                                                                              MD5:85C4CA9F1A6C39ED1C3077D45DE6C816
                                                                                                                                              SHA1:8F41953DC482D0E1A6CE01F94572081B2C0B71D1
                                                                                                                                              SHA-256:C4BA22AE4D91BC8AD43471A99098F8A981404F1AA0525B257769BA745B7C9217
                                                                                                                                              SHA-512:43ADD94185DC659AE2EBA35131B05B94C74E8BEE8520CBBC13EE1EC80208ED96945B55F829C8FE39B518856BC0CE35240A9F53DF6415134B2BC2A5670844D232
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3578-9b91da2e5461ec98.js
                                                                                                                                              Preview:...........<.s...E...J.EO..XTaR.n\;...-...X..!q%.........V..I..}.f.[Z.....k..._..t.vg.G.M......m.....Xo.6..O{...u..e/6.,..@.$!..S71U.$.f.:.......y/}..d..Jt8..)..h.^....y.0.w..`...A%n.D...z.../[.v...?....,..&v.>....T=........1.f.&.l.....ku...7....53.]......4:M.e.AK...5....w....~W.?M.4M..>....W.-..bg.Rp..Q.i..^.h.".xo....v.....v.l..."~.<m..l+..@R......@.w...."QI....n.....6..";-.}......3f.u.z... .B..r3.....c.!.v.B.t_..a.p..~......t..8..@p....9....G7...........G.........M......g.....Y.m..`.-'.........0..U.F.f.4k..g.Y@A.K.~..q.`ElV....A..&.3d.3.g....S...{X..3.{..E....f..U.~..m!...u..Y:.,......^...I..dZmx..u...u...g..`.s...O..=....93....O-.{...Cg.......@[.d...L@....DX.....w$.^.i&..?t- ..N.h.Y.>H{*.o.J.|....>...iD...h...x..=l......{s..U. ...._DS.J..Y........0.!. .w.....:.`.so.K........2..6#.E...-... ....Wg....?V...Pc....w...]G.:......M.x.#...I..O.@."....^.t.n.|.X.I..t..{.S^.f..W.C9...y9.hx....#S.......@..h..-Z.A....?t.^...ci.#.n...<..9..\..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):40
                                                                                                                                              Entropy (8bit):4.239822782008755
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:mSnuZoS+NzNhn:mSnuZoSyhh
                                                                                                                                              MD5:829C6EE578B6EEBD3F4BA006B63C5B8E
                                                                                                                                              SHA1:7D560641648DAA1D54883004597B521870015643
                                                                                                                                              SHA-256:B30CD049D0324EBDF64AB1982051E8255895DE44544F612BA904B4DFF1765B04
                                                                                                                                              SHA-512:31BEB609CBE14A4B3B9D6051BAA4BFEAD8E914918313213581EAA6334CD7CD90F7370D4A9C086D9424AAC414252D5559C5858692EF04F2D338B3DC28583D7A66
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHgkyp820PSx24hIFDZFhlU4SBQ01hlQcEgUNNYZUHA==?alt=proto
                                                                                                                                              Preview:ChsKBw2RYZVOGgAKBw01hlQcGgAKBw01hlQcGgA=
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 2957
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):1772
                                                                                                                                              Entropy (8bit):7.88258191318022
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:24:XymKTH8dh0K37dAb524AVFlUZOMR86cBbwsOqfxau5+/aM+KnCVedfmRUMFeLtVr:X9KTHA2YV4A3f66MpqferBdMCrr
                                                                                                                                              MD5:D6864E9F154D37C030CE3B1F7E20FEB1
                                                                                                                                              SHA1:360637D973A85C468265E602ECA43455AE630AE5
                                                                                                                                              SHA-256:1FED0D2CDB467FC28FB7787F22DD398954704B9FAC5B7D1CDCFC46A6507B6D15
                                                                                                                                              SHA-512:B4EEEB5E899F768F1676E5D8165165488CF0E1729B9FA651EF4E0BFE7C71EE087EAE266FFAD7A05C327700B218745ED1DCFDB9C93143A86795E6F58E3C8E6BCC
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/1054.5cec8df787d4f7ef.js
                                                                                                                                              Preview:...........Vi..:..+...F..=.U........-.I...8......'.4....(......Q.Kde..u.HB0...?.....o.vV.~....#..Z.yUQ..[$6...Z...."G.r...0.Q.7H....O..j.2.....@.I.T..B....f..<.v..-L.....VD%N.;\.......7?...\XD...w.;F..I..J.&]hQ......`..........Q7h4.v..h......Q.}...p.A..Q....;.....;..B.1.Z.k}-$.e...B6..].o$i....a...2.Pm.r.lA..;...].u../N`.. .O.=...G..".U.k.....'-.i...n..v..4Fx.....l....~...w.~D...y.>].......,)...oA.".J..H..J..r*'.k..It...S..t_..]qU.:].(..*Y........t.*...o..U(yL...k.....Gj.Rn.h4\..v.^.....U...m..OU.S U.r.V+G\X..we..........U.d...@.]......O.u..d...3~.^..hk......l.a.!.en....Z....j........i..w..O...B.....g...^..pZ...q..zJ...w.....0l;.....c..S.2..-..Z...2.S...N...\.?.cG..-...A#..I...3..s.6Y..o.\..z.q[V..|..^..<B..9)...N=.u....(..1..I. ....+.M}..B.2Hw.,t..,..z"...u_..'..9..LKc.E.y..U..].U^n...(.....4p'}y..gU.;W\....rIe^G...p..x.>+.H4.G.w8.<....n,...Gv=./.e.t....`.. M...0N/...~.?.k{\...$B]&..U._(..9+...C..kO..&..~1..;...]..0;.......f.<....2....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (21084)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):21218
                                                                                                                                              Entropy (8bit):5.216818536486825
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:knMQG5rwVO7dV9nNbRGCB9D45Hkn5vj2xpOxvIAgD75zBi5vISg3gzopL9TidOg6:P5sg7X/jD45eSxpOxvKD73i5vTzwL9T5
                                                                                                                                              MD5:C6946DFF4854D4611DA8AEF36666B938
                                                                                                                                              SHA1:9118198BD2A853BAA4644C6E819427150CA35160
                                                                                                                                              SHA-256:7028EF6262D35DB7DC22B05DF3CBB3E93595CE90CD340FDC356620D961B01224
                                                                                                                                              SHA-512:BB613298F726B820AA39F55851F2E11FE570FC7620C8CB6322F5CCD5726A2D230BABEEA76BDA3FC7D25BD11AB7F2F64B5BC138C177C5C42DBEF92EA20F3C4FE3
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/popper.min.js
                                                                                                                                              Preview:/*. Copyright (C) Federico Zivolo 2019. Distributed under the MIT License (license terms are at http://opensource.org/licenses/MIT).. */(function(e,t){'object'==typeof exports&&'undefined'!=typeof module?module.exports=t():'function'==typeof define&&define.amd?define(t):e.Popper=t()})(this,function(){'use strict';function e(e){return e&&'[object Function]'==={}.toString.call(e)}function t(e,t){if(1!==e.nodeType)return[];var o=e.ownerDocument.defaultView,n=o.getComputedStyle(e,null);return t?n[t]:n}function o(e){return'HTML'===e.nodeName?e:e.parentNode||e.host}function n(e){if(!e)return document.body;switch(e.nodeName){case'HTML':case'BODY':return e.ownerDocument.body;case'#document':return e.body;}var i=t(e),r=i.overflow,p=i.overflowX,s=i.overflowY;return /(auto|scroll|overlay)/.test(r+s+p)?e:n(o(e))}function i(e){return e&&e.referenceNode?e.referenceNode:e}function r(e){return 11===e?re:10===e?pe:re||pe}function p(e){if(!e)return document.documentElement;for(var o=r(10)?document.body:
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):5313
                                                                                                                                              Entropy (8bit):7.933189242085673
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:VB8d47I7O6++59andvI7N2ntL2DvvSq8cWLaQMTC6ANQMIgrkfieWpfmby:V4t7O6x/+pns783L8ANQHxWwby
                                                                                                                                              MD5:759534A3C80E7AD77DEEE14DA3D94CD8
                                                                                                                                              SHA1:12D6FB2D8E7D74D3235E095D3C3C667E539702DE
                                                                                                                                              SHA-256:121DAD2A5CA7AFFDA231FC459B5ECA6E6141E5D58061681D76679436E1DC5FC3
                                                                                                                                              SHA-512:25B27948DE8FBF5C087D82C9571769B6ABF2D8B05DEE7688F33959D659B010D58F032D59666543E5EAC82F26FB00A170E9F5525BFE5BD9768675CFA399BDB908
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............2.....UPLTE.....*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*...........(.....!........,..o....$..'.....+.................3......../..UON...k......#!3...........?B[>AZ..(...JDH..........q..5../2M0-;...kZSQ)'7......}..mpf[..,..%..e\VB>F<8B%%8........{_WT..,...p..h...................w.xezo`FAH.........z.|h~sdbZV20?-+:...........ulcZi`Y63=..'........|OIH........vvmbri_NHM......................v..n{paQKM.."............vl[*)=........r.ub75B.....s`WO*-I$'C.........y.........mA=A..........{i.....WXkILd................jl.g]I..._bv1.B.....tRNS...[.....1.....|.....y6.....IDATx...[n.0.D..#...@.....T.D..g.....c<.).e].e-}L...Ie{_?.......c..7a..R.....!RB<.........2N..i?S......U..D1......^W...rF....p...7......?:.2.....4.>..........._.2..G_8R..r..ZAU.n:............................?....... ..A:.D.E.E.E.E.E.E.E.E.E.E.E.E.E.E.E._..I.a......$..G..z...D...Q."..DJ.5V.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 12328
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):4903
                                                                                                                                              Entropy (8bit):7.963247343452939
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:4SwL/DlgwLZnybG6D/zZ5FhBv4RtuEd1Me3/SJ:4SwPl3LEbpDd5rBvitrdGePY
                                                                                                                                              MD5:4704DC8565D0173E79628D6390752AD1
                                                                                                                                              SHA1:3826A45FE4050815E13A569E557587143D844F15
                                                                                                                                              SHA-256:F0AE6ED7A693FC452B70CA137135E4FD28C4EB1CA93C25B50BAB8A48CD2E270E
                                                                                                                                              SHA-512:F9B331E0EBC4CA6A81A6ED498E9ADBD5E75AFB56A952C531340CD4D6C10B6D33C0F254E2F06A95DD9A7B9E84CED49C2D15EC2DA8F58BCB989C677D5037179832
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3197-ecea0e3ceb609e4d.js
                                                                                                                                              Preview:...........:.s.H..eB.Z..P.......5f.l..B....Pc...=...If..m...~v...k.3....:.x...c..u.......p....EM}.^...h.=......<.b_.IH..Q...s..V..^.V...D...V[,...|sJQ...5..\..........y.3`XTU..~)..r..ST..B..E...L......r.n.KE..a..5.f..U.E...M+(*..p.,....../.,.(...-#......RPf..nR.....s3......w.TYd....Ky...CI.E.4GR.bQa.R.|..#K..yc<v.h.....'#.E!.X...e...r...wl........r..yK..x....c.h.A....gNd.r...dZ".G.A.........#.4.\..$s..........5...{.X9....B.3.D...7.#.J.=..8.....L.Q..W3..q.9f.l..m..cg.*.O.. .9.'.+c.oXVWd(L6A......bV.....X.>.......4.f.*YE.l.n.*.V.M.....;B3.$.g.....F.*.....BQ.3Z......?*5{....C2.A....Kf.$j..... ............}..sJ.o;nD...W...D..f..#0.........KPR\D#@*/.a...he..E!.^I<..^..w........{...+-W.{............%.....n...q.....H..Q..'|......G....1r.m.bX=C....!.S"?.A.:@&R1.j..R.y..9P.8..........6..{-b.$.t. ..n......>...I\.c..R...J-...?....M}..&.S.0...o9!Z....H.!-..}.?J.....w7&... ...&H};2"..:|..r...^x.*.%>p.R..a...r,w...Tw..Y\x.....(...&..R..hF...).3Q....E..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 14764
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):8535
                                                                                                                                              Entropy (8bit):7.974782431163619
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:5+jiXEfqDeclRZVhjXCDl+RsVeXzpyOU5c0Hb0AUjwJHQqtGFtytd7Scc4giSizr:s7qDeEVGl+q88oAUCwWGutdTgDizr
                                                                                                                                              MD5:69D147DFF015E573F52F5651179DE845
                                                                                                                                              SHA1:0D83E365C616840F9F458458EC745F65C4F4D653
                                                                                                                                              SHA-256:4C25D901EFE6D54F96B76C27A1483FDFB003165DB8A1FE54D4DBCB73B8A0C2DC
                                                                                                                                              SHA-512:A283FF46DB515AF6A0EF3E7795C4E7E6753A66A8E0422EBB058A7C25F73049D05BA81A83F6C92057B280E647A2D35C5E0307186F1B11462D0C7F38AD12587A7D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/pages/other/restrictionIp-79e99fbf944d553e.js
                                                                                                                                              Preview:...........{......2_G.../Ox..B...$@..pp..$n....B..c.........6*..3++...+?..;..n.GM.|.~...p.........T......6..........".........T.OU].n..Kk.?..z....#....4/..A).z..`H!(B?.#0$i.g....K...4.^.(.i.....r.)~|....g...j.?..}......yU.r\..@.i. q............X.\./pO...{0SN...,.....X..=.*0.[.A.6.......~.d.........>..x..f|.X.uS........1...........c..I._^...;.~...]Ydq.?>~y|.~]..[.g........x.7i._.....G[..O....N.<.....n..................-.........>....}zyd?}..._.E..8......../..?_.....*;..~..._.."..2....B...=..m._....)..`.$(.\.iL0.2A.......?M.L...~......O.{L....=`.....S.....iy..M>..ee._.h.!.~^W...?.7f...W.....y...<...y.........^....O.....}....l...:..<.n._.'.....'e....N.....}....8....u..ES..?...q.A...Z..Cs.-....y..|.i..?./.5;..R..cf.y..v...>..;.;.....|/............=h....O.+mua.ny.a.g.;..@N.$=.r'"...Sp.. B..E..D........I...........J.w..W...@.....#.I.....$.{..F.PF.d..wI.5...oU....i.w..J.`h.N...LXx@..........-0?.s.04L...F.H.O.....]G..(...@....../...........D....G..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (21084)
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):21218
                                                                                                                                              Entropy (8bit):5.216818536486825
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:knMQG5rwVO7dV9nNbRGCB9D45Hkn5vj2xpOxvIAgD75zBi5vISg3gzopL9TidOg6:P5sg7X/jD45eSxpOxvKD73i5vTzwL9T5
                                                                                                                                              MD5:C6946DFF4854D4611DA8AEF36666B938
                                                                                                                                              SHA1:9118198BD2A853BAA4644C6E819427150CA35160
                                                                                                                                              SHA-256:7028EF6262D35DB7DC22B05DF3CBB3E93595CE90CD340FDC356620D961B01224
                                                                                                                                              SHA-512:BB613298F726B820AA39F55851F2E11FE570FC7620C8CB6322F5CCD5726A2D230BABEEA76BDA3FC7D25BD11AB7F2F64B5BC138C177C5C42DBEF92EA20F3C4FE3
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:/*. Copyright (C) Federico Zivolo 2019. Distributed under the MIT License (license terms are at http://opensource.org/licenses/MIT).. */(function(e,t){'object'==typeof exports&&'undefined'!=typeof module?module.exports=t():'function'==typeof define&&define.amd?define(t):e.Popper=t()})(this,function(){'use strict';function e(e){return e&&'[object Function]'==={}.toString.call(e)}function t(e,t){if(1!==e.nodeType)return[];var o=e.ownerDocument.defaultView,n=o.getComputedStyle(e,null);return t?n[t]:n}function o(e){return'HTML'===e.nodeName?e:e.parentNode||e.host}function n(e){if(!e)return document.body;switch(e.nodeName){case'HTML':case'BODY':return e.ownerDocument.body;case'#document':return e.body;}var i=t(e),r=i.overflow,p=i.overflowX,s=i.overflowY;return /(auto|scroll|overlay)/.test(r+s+p)?e:n(o(e))}function i(e){return e&&e.referenceNode?e.referenceNode:e}function r(e){return 11===e?re:10===e?pe:re||pe}function p(e){if(!e)return document.documentElement;for(var o=r(10)?document.body:
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 28635
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):13686
                                                                                                                                              Entropy (8bit):7.980972521962793
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:HDmLFoCxYDROPoPqoiamRbWPAeF/vzWo8bnxyxtdC45djZ0ZzcStLEO:i6C+hPRiHZWPAeF/v6tjx6d30FJEO
                                                                                                                                              MD5:FBCB238B4DC7FC266F53418A11D72838
                                                                                                                                              SHA1:AABDE2C6CEA7359158DDD51F26F674A6B23CE183
                                                                                                                                              SHA-256:6949C7C8F370A9FF0128723E30E732CA721E6DFF6DEAC258CAA73B36172ED5F9
                                                                                                                                              SHA-512:C836E38EAF759EB4F634FEA22754858F6629A24E7FB2CA672BCB71F44C5E793D9BF54CB22FCCBD7118083FE572FF5B376A039F09F5B292E8AD809B335490E754
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/css/30f2c15527dbc727.css
                                                                                                                                              Preview:...........i...(.W.N.8'(.3Hvt....$F...R.<.3.._.m...k...H...3...?jPi.s~p|..@..d.~....>..wm.;}2.....w0..... ...y......Gq-.-.d....4{*......xY.VC..5x.Ue.$.w@.D.!..d.{.._.."5.^.5..w.y.rc...j.o^..)..z..3..w......I..2......k.%e..I..P.|0E.S..t.jQX..:..j...OL.....'@6....4-i..j.ML.#.a5.. .y.. <..]..QC.....O...m.x....$_.uSR...dSp..k.wC......;....y.1..e....;...?.>|.{.:]@`?..=.G.M=.....o.....v.......%Ds.L..M{{.F.Ba.>...)...jn.t.=...<P6..G........h.....{.....{.^.PyZ.[.n#p.,...G#......./.GKf}....R4K..{.... .b..).N......ky.}....t....W.{.w...."@P].}..$.../......P.(L...?>.H.(..\D..-.'......Q&..qp|.._.m....\....>....6r>=...P.............:.y....?.`.\.@*.U......-=. .....<...}.l>..e:.........K.p.j.;.`.....h.V**....F.-.1.....(V*...W[...0..mXt..!.....(.O.6OC.7o..I.O!r..|.o...[EDq..e..L...$Z.oi.N,.z..@a.lR..DS.q.`..D.....h..6s..W:.#...$........._d..e..z-.../q;......&.x...h.....{p.t.J.ye..O.q..A..G...g....<..]...N6e......;.f.../T.].j.>.4u.b.bgO...5._...M3.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:HTML document, Unicode text, UTF-8 text
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):2559
                                                                                                                                              Entropy (8bit):5.425405810703348
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:IO5ARXDWwELcgalJbcs7ak+dV02cOaPSXWcd8fGFFOQ:+RTWwELxaX3ak+dV02XaqknQ
                                                                                                                                              MD5:DC0272602494991DDD6D455893FEEF45
                                                                                                                                              SHA1:F555A8DEF67E839767D309E835160EA70203F01C
                                                                                                                                              SHA-256:4997E840914D8288A8BB8A96482A1F8929B1F5B7BC96B7973689E4D828E869E0
                                                                                                                                              SHA-512:DE34F4F0D1CAB28B8F92A8EE99FABB0813EA2F561CEEC7DED6CC5C6F3562A8FE383B4AC7B1D48FFA8B73142B4844B0703018D80E5285F951CC4C546F03BE15F4
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:$(function() {. const str = window.location.href;. const idMatch = str.match(/\?id=(\d+)/);. const id = idMatch ? parseInt(idMatch[1], 10) : 0;.. const obj_slides = [. { id: 1, title: "BET365", url: "https://551007p.cc", src: "imgs/banner/banner.365.png" },. { id: 2, title: "...", url: "https://p399224.com", src: "imgs/banner/banner.tyc.png" },. { id: 3, title: "...", url: "https://l21714.com", src: "imgs/banner/banner.xpj.png" },. { id: 4, title: "....", url: "https://665339c.com", src: "imgs/banner/banner.wns.png" },. { id: 5, title: "....", url: "https://789400.cc/", src: "imgs/banner/banner.yh.png" },. { id: 6, title: "....", url: "https://service.sdqhwtvbtwdf.com/C.ashx?btag=a_18017b_2484c_&affid=2017190&siteid=18017&adid=2484&c=", src: "imgs/banner/banner.wlxeozb.png" },. { id: 7, title: "....", url: "https://e977110.com", src: "imgs/banner/banner.yl.png" },. { id: 8, t
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 816 x 192, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):36050
                                                                                                                                              Entropy (8bit):7.963546451293137
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:GI25A+f//Cfbr7yIzK9ftm1abJS8P5qT2rnUUmfi1Teke8BvvQ1:GFhCfbPyyK9fkYJU0UUmfi1Tebc41
                                                                                                                                              MD5:DF857D64F193D658E997D91D31F626AC
                                                                                                                                              SHA1:0B3CE14332458EF207E8D9CB5DAB6D61C52CDFFD
                                                                                                                                              SHA-256:3D737A76B3F165E99840D801A08F19472C87F6EA074B2D862CD0A996C2189AFF
                                                                                                                                              SHA-512:412FD6B2C5D2FDB7370B2DCD682BAD29D195D6CD2D92032BAA4AC205822E3A27F4ADE6FBD159DEAD129455061F576A4CC9FC3FE61C90BA482A519DA35DF928A2
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR...0..........v.....gAMA......a.....sRGB.........PLTEGpL................................................................................................................................................................................................................................................................................................................................J[....0?..............................gr.kc].........."0..:R...*.......vH.............g{),.........5)#!...tsqRRap....,.{.%>....&5.......(.%''...59<>BF.0.....4..%\sjg...hi...T._=.<L.).....BL..K..J.+:./>..........2@....................*....!.. ....j.!..$6.XW_O. ......`s.@V...) ;......4 ..+.....'.}:AB?.......}kO..(..Z..?.....#>Ex...0H...)p..-.+..)...........~Pd...%.......W....s..t...GpL.N......tRNS.. ....3....!..#2.2+1*%..3.&'')(*.,.(")+1%.-.0&/$.0./.-,/2.$"0!....- t.#1."$.,..!2...3 #.3..404.V...^[.QPoSc?ErK-..n2h7...:Y.w6.'..&DJ..C.:}!..m.A:..`
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):5313
                                                                                                                                              Entropy (8bit):7.933189242085673
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:VB8d47I7O6++59andvI7N2ntL2DvvSq8cWLaQMTC6ANQMIgrkfieWpfmby:V4t7O6x/+pns783L8ANQHxWwby
                                                                                                                                              MD5:759534A3C80E7AD77DEEE14DA3D94CD8
                                                                                                                                              SHA1:12D6FB2D8E7D74D3235E095D3C3C667E539702DE
                                                                                                                                              SHA-256:121DAD2A5CA7AFFDA231FC459B5ECA6E6141E5D58061681D76679436E1DC5FC3
                                                                                                                                              SHA-512:25B27948DE8FBF5C087D82C9571769B6ABF2D8B05DEE7688F33959D659B010D58F032D59666543E5EAC82F26FB00A170E9F5525BFE5BD9768675CFA399BDB908
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/wlxe.png
                                                                                                                                              Preview:.PNG........IHDR..............2.....UPLTE.....*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*..*...........(.....!........,..o....$..'.....+.................3......../..UON...k......#!3...........?B[>AZ..(...JDH..........q..5../2M0-;...kZSQ)'7......}..mpf[..,..%..e\VB>F<8B%%8........{_WT..,...p..h...................w.xezo`FAH.........z.|h~sdbZV20?-+:...........ulcZi`Y63=..'........|OIH........vvmbri_NHM......................v..n{paQKM.."............vl[*)=........r.ub75B.....s`WO*-I$'C.........y.........mA=A..........{i.....WXkILd................jl.g]I..._bv1.B.....tRNS...[.....1.....|.....y6.....IDATx...[n.0.D..#...@.....T.D..g.....c<.).e].e-}L...Ie{_?.......c..7a..R.....!RB<.........2N..i?S......U..D1......^W...rF....p...7......?:.2.....4.>..........._.2..G_8R..r..ZAU.n:............................?....... ..A:.D.E.E.E.E.E.E.E.E.E.E.E.E.E.E.E._..I.a......$..G..z...D...Q."..DJ.5V.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 440 x 140, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):2950
                                                                                                                                              Entropy (8bit):7.868804141565523
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:SABafCd6RLhrdyu4xGo5mGAYhLLvic7+nr3Vnk8+kkBC7zK2nO0EOoNZQ7:6LLhr1do8mLL6Q+rO8+kkBCVoOoNZy
                                                                                                                                              MD5:31DE1D2FA7D918FAB2F59984391DB1C8
                                                                                                                                              SHA1:4F4B78796B3FBF19971F182175BCD92B01EE470F
                                                                                                                                              SHA-256:29F87D6615F36A54E3EDC8C7F05EB9B480D1F2989DEC8DA68E82747D060AEA85
                                                                                                                                              SHA-512:6FCBE53CD766C7A8C9A866BE753F6F58A7BC65B9AD5A0FD05057AE716C51B180F824726CFB1E47A5420B64CFCE812778D3DD33BBCCDA06378B2F972E83CAB950
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.sogou.com/web/index/images/logo_440x140.v.4.png
                                                                                                                                              Preview:.PNG........IHDR.............9.L.....gAMA......a.....sRGB........{PLTEGpLSVYSVYSVYSVYSVY.u.SVY.c8SVY.s.SVYSVYSVYSVYSVYSVY.w..p..r..."..&.e..f.SVY.b..b..l...(..&SVY.i..o...-.| .v...$.c..V...'.]..X.?....tRNS..L......<]~.f.*.qI0..............IDATx...z.J...}..M@......Co..`..I.....3O.Vwm8......@ .....@ .....@ .....@ .....@ .....@ .....@ .....@..H1..9.W)8_B...lA~x...._...._.k.......<.......U.(..+.t_*c.[......l.7I...+.(.C#:C....v1.v.y......WI.O..P..ygD.(.E......b..1.F......}....Q.1......_..~0....p.....q.f.l?....B....[:{(X{.....*.....=..y...EY.e..2...#....=.......S.........p4..,.....-.9..V_K...c....V...W..Z.-.......O.-.9.K..OY.r*.\f_K..)..."v.t...N\.2.....4...}.....".&..R3..._V..$...D..[....e......<...S..^.. 8./ah..7....7aX.o....."I...<M..KN...<}.........'.a..RIA..M1./.[..L.....,....lC..$............2lJ$..a+...W.T........w.:!p._.....t....(..?7..;..`.P..HH.....u^..KQ.p.0.N=}../...n);.......!.$$1n...}dX..(....0HpY....CJ.c...}...., ...........{%..Oj...b........
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 11344
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):4902
                                                                                                                                              Entropy (8bit):7.957884414631384
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:7J578Y9klak1x6LETzCW9yG8CBcgPMnPJzns0+si1OJ/nl2Pq2xjBpQ:7J578Y96MQTzm76MPJ7m+YP5jBpQ
                                                                                                                                              MD5:0C9545C0990C7D38C6399511978B8590
                                                                                                                                              SHA1:679D9E981C5E0BA54AE19BAAD37EE26D9A9E1220
                                                                                                                                              SHA-256:6F31DAF879F30313C990FA5B281F992583AFE35C6B8455BE5A370C2AD4E0F596
                                                                                                                                              SHA-512:FA4898CCE49F07AC92DB559F5481D79068CF0836AB5B6AD3C7AF7A2783C6B6EEBF62102141BFC8B485F57728C1A6F9F8962135480B4115B4CB140A56FC742EBA
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/pages/user/register/rt-16598a0e04b26a45.js
                                                                                                                                              Preview:...........ZkW.8..+.g..;.m.w...4.......d.=.d..$.. 4...[*...=..9...R..T........$.7.....G....hF...5o....!..P.....r..pb...x...R.NK........O.BH...m./.m....d.7>|.].....k&i.D.........Q......_..\Q.O.h..G.l4E..&.@..~l....[J.i.._..7.....rEo..O..|G....w..f......./.C.KBM...3..........%!NCc:|....t...|....O...f$.'n..'.....2.....4KL>....q.>.&x..}:.A.<Ov.?..(........i)...}....N..5.._l....}(..s....gB..6.X.....p..y...l).pb.ZdO..N..+<..?....8-..h../.).z..R.R...7.(..2..E.&.x....3R.....u...a<.K....4\.16:.qB..o.\...9...2.`.1....4).l...S7,...FA"j.....P_.r;#.*.X....YA.tJ.~1.V.........nq7$H4.y,T..r.y..PFD"........L.f..Q9......2.pq.8.....].......U....+sZW.3.F.........z....R..X.'..w.1.....M.;..:.u#z..)#.2.+..u)*G....B.E.|./..Zob..q;..l.....# .........T..F...?OE..bi.....yg1.a.P......A...>N...%......-...o.....a...y0F..M..,2...f....lTCI....d.1."TB...0..G.x...cia..$.....p..yl.q..~a.Pq...0`.....!......|2.Y.7z.mXIb.....j.u.W.B...6.......a....z..y...eo....{r...._./..oW.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:RIFF (little-endian) data, Web/P image, VP8 encoding, 5120x1860, Scaling: [none]x[none], YUV color, decoders should clamp
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):124060
                                                                                                                                              Entropy (8bit):7.990984664385903
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:3072:jazqGVBSUs0oBKHZIcSTfxau91/zL5BRSBuaAti:jlGzSUs0tFmb/zS
                                                                                                                                              MD5:88B1EF1F9F07B890387B2AC0A7BEDE72
                                                                                                                                              SHA1:B90E7F2689483DD2A49459952F008F18F2A658F9
                                                                                                                                              SHA-256:AFEF2B2B7EA3F79319675E2B8C31F63345C26D7D6DB1BAB0A84A625A976CE072
                                                                                                                                              SHA-512:7C4030EA62A835CD6C6F3AB2326B780DF3BB7029F1D3342642DFAD886AFA739422BE645E7FDC00E65D3D92DEF282716FAA46B1661E50CBB52F7E4E7175F48B0C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/images/background-d54ca37e7278e3e1b5e4b5d6b86145e9.webp
                                                                                                                                              Preview:RIFF....WEBPVP8 .........*..D.>.F.L+..*.5)J...im~.....O>...s........hp5~{.$./..?.......?.}.......'3.g..x=d..s.;...5.............g......S.+v=.....i/..V.G.....y....S.....`..............W......n.A......Q.I......?6/...x..?....{...n......L.<......m....O..j.?.9.X@..V..:...RFe.:.I...AN.~u./...*+....Q.].k.2(..w...,....3......w.....w.....w...j.....w!...#".e)=./.......].qf....W~}.].p.~u./.....r..a{\.iqg~}ym.w....|J^Xdv.O..Z....T..%.....Y.k6.Cz.P.7.....Z:...h..Q...."...".;......9..6......T2vP...L../..n.j...s..0`.$...._...v....<..2 .....u..':.........?>O...XO\.V`..-3..m...g.......e..;.uy0kc.W.Wg...}:...w.....r.L".a.x.IW"..8..Z$../Q...G.3{z.g!.a.U.g~.S*|../...Md.......dV.\.......x@e..!.......9Dnp_L..)l..`E.Mc.z.CV..^....v\f..P.....=...F......./&@+m.>ZV.=..Ys.w{3./.fD1.12\.W....G...HML.GH._0.l6.l...p....W>H...........w'j......w..[.~I.0.OG.D..}.].....W...E.....\.^...vR..\.j.wn..&.=....rQ.iB....JkC...y\..]5Y3K8gZ./.&.D.k.u*g'5._UW.[.II..F....b....[..0.f..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 7670
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):3188
                                                                                                                                              Entropy (8bit):7.928676305686423
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:X235qAv02CEN/0O7vrKPZuGCH1sd1z0o1jBbCDU3DHYt9gVSEODurOQB+/UmnKrm:msXEO+rOsGRd10orKUqg1Y85iKrm
                                                                                                                                              MD5:3676DDF77998D2B88F9E29F8A12ECF1E
                                                                                                                                              SHA1:2A83E401D0B212968428838F3F7F059F00D7F8AB
                                                                                                                                              SHA-256:CDE17FDD67009FC409CC46A85A806E29D146CEE89228022061C78DDEF4A893A1
                                                                                                                                              SHA-512:81602A720713D03250926EF109DEBE2E88A3CC2F523857D209625DD247E91293D07ACA3E8C28FE4120EE46015CB4FB9D463C7CA30038CECBE39DEF3952C752E9
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........Y.s.H..W$j...c.B/.....n.Y?.9v.....H....A.....=.@..r...U..<.{fz....So...(....i.?./.g.......E..x*..7.F.....2{..w8.|.'.pe-%1..<b...\ueJ../%...(O".f.d1;0.......J.nG5fq..i.M...SY|c{.=...._0.bG.z...a...>..B*.%..*........FA.??.S...M7...\n.z.OSb.F..S...8.K.}PM.cW&.A$.o..$...G....j.tQ{.E..NL....k....U....d.N?_.........m.X9..v;.v./..M....Zz......7.....M7.....0.nW!^i..4...kq....8.m6.....htL....X!s.k.<.L..oT!Sl..+dhU...q..Z..Be.....\.....x.f.N..r._.Q..T..<....#.2............G..'.W....C../3.."|..../.6g.....#Z.......6.m...bg{..s)..3.n=.G.......@K....47....%....#E....IDr..N<.-.L.J.A.d.pQQ....@.SdN.l.Z0..!....iq...t$..,..#.c...#........./.ks:...3...r.....da..<{.p^.$....,....d0\5..8...."6a..m......,...3_^.s.....86.u.-.F).....fz~*..(.r.K.....G{...-O..<.W].QA...o..0.VA.@...8..g..,Pc.....*g!8Y..";..9.PM...<J.....{i#.la#..(.~@.|w..<J.....v.A...%.I$V..r....L...X...A.$.N.;6.9.8........Q.%Jo........../.@5....9....#......F....`7@.......Y.....~....."T...T'..."=J..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):6379
                                                                                                                                              Entropy (8bit):7.945124258614392
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:JYpCfXM/cHur2CY9hFx/40ynVl2WGw3/X:JVMd2Csl400UCX
                                                                                                                                              MD5:6498A9D97304B0B805C98ABBDA8ED0FC
                                                                                                                                              SHA1:EBBC775BAFBCB958B3E4111A08AA30A8EE04500C
                                                                                                                                              SHA-256:07BF983F17C6B63C74E12BC837F87A19F4656B6D901F91AFF0646A0AD1390245
                                                                                                                                              SHA-512:497FFEA39EB48825137988609B8204258C8F41362368D7574217C664D77596EAAE0DDF8BC0B9400EC90E7CDCA368ACBA65CE311883A10196BDD983A37342A228
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/kaiyun.png
                                                                                                                                              Preview:.PNG........IHDR..............2.....|PLTE....%N.%N.%N.%N.%N.%N.%N.%N.%N.%N1...%N.%N-...%N.%N.%N.%N'..0...%N.%N5.....K..8..&..-..5..D..p..@..1.."...%N$...%NO...%N...`...%NF..0..*..!i.*..)..$w. ^.$...%N6..j..e..5..9.. a.J.. ..1..:..*..f..*..#k.6.."..E..!e.=..!..`../..#..1..N..`.. f."..^..Y..+.. d. _....+.. `."i. ..6..$o.>..6.."j.:..J..7..N..&..1......%N7.....l..*..8.....6..!c....&y.3..)}.E.. ].%..C..7..@..+...%N ...]....!b.-..............4.....;.. ..;..*.....e..=..9..'..#o.5..,..)..4.....6.."..+..&.....'v.O.....F..V..)}.J..>../........B..,..7..(..*..8..... ..9.."j.8..5..!g.)..3..$..2..$..%..\..A..,../..2..#..0.....:..7..:..*.....;..4..5..=..!..)..;.. }."...v.?..O..G..B....`-...{tRNS..?...#.....\i9.....Iu.b"*'.S...y.h.f.CD63...OG2.U..J......|nd..}S...n..T$.......@.....`............o...........u....IDATx...1.. ....8`.@. .....wMR..........I.W.......8..=....!......U.....P.`u..N.9...f...?..D.k....'.\.'......Y......$.Vo0.v..t`.._.i.........s.6y.vC'...-\!..~}G.....p.Z'
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):5294
                                                                                                                                              Entropy (8bit):7.937849280289421
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:Q0/zqWkEB5tP/GGhqd+9BWfV2EIWIKJFensiSCLhnLEARybIDf1V7:Q6oEBrPeGhE+bWd7MnsiSuhLpR80fD7
                                                                                                                                              MD5:B5F40F3C38B9464DBFAA82F5FCA1921B
                                                                                                                                              SHA1:1F3CDC4D8CFEBB93899220A15C26943E24973849
                                                                                                                                              SHA-256:0160DE7C57628AFC1694999264E44C99BEB18DFFDB2992BE7D8223ED5F3DDC94
                                                                                                                                              SHA-512:A193D308CEE71CBB01C7675D572134655FBF6778A711422E09EBCEFFB8732ED74D502335655F75D5A783601AB955E640F7978DF7D07A6AD30AD6D06A2713A812
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE...&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5&-5%,3&-3...&.5#*2%,2)08#(/. ).#+,3:.'/..$"%,\..\..|.....8>E""')7A....B~.W..,>H .!/HTFLRkqupuz...KPV]..;k~=l.agkV..Z..X..2O][..._.._...........c..G.....=p.^bg3SbOTZ.....! %...Z......16=............>t.49@........?EL<BHx|.ty}...fjoCIN(3<....Z^cTY_...@z....8cvimr5Zj^.....Q....W..e..E........<p.6^p4XhK..B..N..I.....i.....x.......tRNS....[..~1.............IDATx...YR.0....-^c;I...`(.YH...../...<.:...l..2..[1e6)O...>.Y...6..K..S.c.G.@..;.B..tW~...M."s....=?..Q)...!.....z...en|.{&..](.O!x.d...%M......@PT.3....FH-....W.......j.M...9]...9]...9]...9]...9]...9]...9]...9]...9...9.......o=Hg................(.z}$.Q..D0....F.>..@.^..`..#... ...B..>.3r...Z....Y+/X.d.C'u>.II.m..bsU1.|.T.=R=&...q.S..a... .Bm Nx....&.N..T..^:.-.......Co$..W.i..Z^.ASi].A)...2.}g.hx......0..( ...z...Zhq...4[E........=.>H.[{^..7.F.....Up.I]K....u...'f..F...H&..1....X....B{(EK.D..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:data
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):397
                                                                                                                                              Entropy (8bit):7.51129515793566
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6:kN3xf+9yVBsQBlLYJV3YWwRR1UmrNXUBbhsNLgek/jyK1+Rap5oNg8Rl:k3W9jXV3BwRRmmaBaNLAGg+gq
                                                                                                                                              MD5:60100C461BF5C2F479B637609953EF3F
                                                                                                                                              SHA1:A2D52C0F9EC07F3E487DE11793632CF65F3910C7
                                                                                                                                              SHA-256:546E8B0A19E23CFA07851B6C8693AB504C083A041C749EECCFD3ACE8E2896325
                                                                                                                                              SHA-512:BA293953E208CF2F619FB4B2DA3CD75D9B08826607568D9BD93DB2BE5B02B25D8360DC35180615C7C4D0CA9FB83EF02CE220E18EE32C5359F84BB2AEEE6F8558
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/api/json-cache/y-h5-main:ky:prod:platformCounts
                                                                                                                                              Preview:.h.. ....L.....g.....C......`..zmg.........q...]....T.O.P..>..F.....nX..&..M..Y.....|.!.J.....^..d..E........y%.My....0gth....u.....{..k.5.Zb..H....B.....V>0F.'..Z.R...O..x......XMv..CZ..S.h<&...c.%.5...r.o.fx....oH..D"K..)/...UO$^b..>]d...e...~..w.v`>.D.u...[..y.u...4.......22%..np....:.....`.../..p.7d.R.5....0*....X....R}...\...JY..p<a.'.LY[..H.g-.,..d.:+...`..).PQ.??.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 268 x 411, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):16719
                                                                                                                                              Entropy (8bit):7.98171793482572
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:GVs8oiHguE1GrFCHWk9DxPjkG0j9X7JZ3c7mor1VtrNteisU1:wRoTuEgBCHWk9xLkGi9X7JFc7TVoI
                                                                                                                                              MD5:9C4488C5C4BAAAE0286BDA2A5CA555EB
                                                                                                                                              SHA1:0103D52A175D0D91ED500B11F67D73457F7ABC4A
                                                                                                                                              SHA-256:B7B9498D1BEABAE57D14A7806C87265571A0A5BBD1B5D49BC7029F1AAD3959D6
                                                                                                                                              SHA-512:1FFEA5410878209B78ADA1C4B105B229C691E789E0ADF31A38EA1E8CFADAC857A1317B4A8DAFD52EC7CC7BE119B22B3CADDC43613D91E97D8C42F02E3573F275
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............1^Z....PLTE........................................................[.........-....EnJ.}T!f>..g(....l)P...u,.y,.1.U5.@&...1.&...3.}6.Z#\:..r+*..vM.9#.....CvG..c'.w._&F+....;...X.C'..A.]$aA..S5.`&.S!#.....<#uT"..u.D.d.a.r7www.n..?.n).m*2...TG ..c.Iq@..M..>..>.X..8fH...A..L.I..n.l.U#...._&....;.g)O$...P...G....]>k6.....J....L.~=b2..a..X.e.R1%...3......W.c'.........Z..M.J......Y*...w.a..L.j5......1.|,....U.t>..0qqp.j.?XA...m.Q.......F......{<.....f..=.s.[.v/..y..aG6.....+......o.j&^F.[,.zxY-Gze.........t$pR.kMZ.z)N>.`6............a..W.oC.F4.Y&6cO...^**(.L!...K.*.U.pGFF=oZ./.6(....^.A..... #.976...d.....[[Z.,..c..taR1.0D.pv]H...j...uY..z_.H....tRNS...C.....1.|_'..Qn.......>3IDATx...[n. ..P.....&...Z..*j.QU@..9K...................%q_.k..z...J...nWrr:..r...>....v....uD<.t-9....B..u.8.&t.0.~|.#P..B......v.H...LB.........E..6%....y..*..B...j)Z...Gjg...*....Q.g..Z.........g.W^....O.je}
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 1780 x 2251, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):32644
                                                                                                                                              Entropy (8bit):7.829276987696952
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:Clok4IJkWG10A5zCtUQ/aVS5GYqj07NT0pvUi9VJpM:Cqk4IJkJ+4tQ6ZVj0pTpp
                                                                                                                                              MD5:8F0CD5F85D6DE29491700D70995017FF
                                                                                                                                              SHA1:91B6374B9717A6D9DF3574AD1A246D7DA44DBF1B
                                                                                                                                              SHA-256:EB0BE5A9C93ED5EF86EDA2EC2DE2D8BDB24BF08E048DBDB7E8161444F46AD63A
                                                                                                                                              SHA-512:EC35EB9E5C185DE7A87AD56A25C6AC430718850653532EFD0A4DFDE4A731085EFE07EBF595BD665A3F59F937A5BD3D4350A7CC0C74B1E9B1937D3F56A9AD0EAA
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR....................PLTE......................................................................................................................................n....+tRNS.2_.C.....T.N..p....g...!w...H8=.+.&..X.z../...~.IDATx.........................................................................`..@.........TUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU.=8........m.UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUa.^w...(.O.P..;$.......e...*.j..8..%V:3;.....xsM...u.1.......J.y..X..N6U.;....f..V.ou.....n]..|.............q.................~....w..Ekf.Mz.oz.....l..B......V:...(....M..P.<..j...RO.......@........E.C.......n.t.[.....d..M=...0`9...2.`...n.z4......y.....!g..........M...#g..r..0.."g.Gs..0.u;_W...tVR.....xO.l~..S+.@Y..We.j..(.j.3.....2..=w....w'*..Q..O.. .F.R..1...a #......<...9.P.....~..P.A...v....e.M.$.......N'.....O&..#.....$5A'....{.ij.y..Z.M3....d.....fi..|+p2aO....bf`........{.....T.4.........R.=....4...p6M3.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 61356
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):26989
                                                                                                                                              Entropy (8bit):7.9917384215218705
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:384:KJOw9hchc2x0cuGAaQablRhi+mtwNd4QJY0PMXXVD3e1La76u:IcO2xsGAaQaJfi+mA6uP6D0La76u
                                                                                                                                              MD5:E19163D4BDA33F68FD5984AA488DB5F1
                                                                                                                                              SHA1:FDC5DB741B682BD9DA186B3B856EFC3E1F15501A
                                                                                                                                              SHA-256:CE38FDC40A3248A140EEF1426244F7F64E1049B05D3215D2B8C4DF7344E08118
                                                                                                                                              SHA-512:7C3FAD441AD7AC53C6E18C4E5FF7CDD2283F6F46F127382DF789DC7CD2180AD92F1950CB3FE64B957D2F59FA6F2070204328DD457C7C5347853EE5F11362E984
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.............WU.?~.y}.3g.ud(..+.<...()g..8 ..dvq.....y0..3..bYQ......nr.......)..f.M*o.n...n...>k.s.g..#.{....g..^{..^{.....5.0...u.fO.........m.....O..GGQ......nt{z..[.oW.W.E~8..Q.DO.i.t..n|S#.7Z...Q]T.a...}......K..Z.j..%KW./..X.d..K..d....M...t..).j./52C.y..ikZ.|.%.WL..|.......N_1.T.FJ....k[.T;...n..S.&.L..l.=t!..V.]..y....m4LkC......e...../;.L.,.2.aVR.7L....m.D.r....k.i.&R,.Ri..+e.L'Q..d..9...T.J oJ)e.iW.Z.&Ov,eT.).q...gd...wM.um.M.F..gT..M./.X....iY...V..hn3Z*b9.4.^.n..xX,..Y"./.E.hkn6V....4e.*3iy...Uo....m7.u.-y.....y........v......g..S.;.s..._.gu|...s..5...=.0{.......O...[...~...Z.P.+.%.Q.....$.o....{......0.^m..8...UV..p.=...^e..',..S...2a..S...?akW.....z.^..qQ.......|...7P.Y3...a..G.......).^./....0..;.......gpN.1.....6g......d...m....i..b..,j.j..N..@...b4....j....6j...4/V...V.yW.~.5w....I.k.].@e......&2.d..._.U..O...=-..Q.).&..t...Y\A.b.+..tpc.~.1..E.>+X_.-..o....Nd...7!..z.6..xzo....$CrP...n.`.. mP...&._z.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 73680
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):15771
                                                                                                                                              Entropy (8bit):7.983590108086906
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:ClnvLxYVri1SVUzDFzRMtQp/gavBvOuFGIGza8+4pcgJsG:4nvdYhioU/FjO5eGHCG
                                                                                                                                              MD5:572048A682F369E9B7948EBFC4204D36
                                                                                                                                              SHA1:1FFDB7EA813E4E1E0009FCF8F353DFAD015EC4C3
                                                                                                                                              SHA-256:48BBFD796FEB8353F2C073ED6036DD79D0F67DCBF3B1D34C0A2F232F8568D191
                                                                                                                                              SHA-512:73FCF52CD4EE3A5B4F5C927797D771AFB61F377A86EC3BB882416264D6AD7248F9560C6173D39D2331AB93BE04E79651D768497F3C62AB68C261259C94FA3C92
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........}.s.G......U<..@=.+*...tr.6...`..%..........(....E...&.t._o/.Y{.)/.............W.....s..rq.....q....W"...^.U.....b....5.\4[..|Z-'.f7.....v..y.s.S1..m....;........n.].B?.vv...0......,..pg..vu...ysp..+...f...ly[.`./..n......g..o...?............/...N.h.....;..........i1=.}>..Lvn..f...d......|{[/.._.fy9?.Z.5gG........;......5.p.z.?.Ln...........I=.4...:...ys..o.o.b.xR.6{..N...b:[..Ot....]....>\........p.....[....]...c...@X....{QYt.H."..W-...^.....k....7..Z.Y...u:...]t. f..=.B_..woI..7j...4."1L...!.-.....D......*X.`...\.....~..)...M5N..>.M/.....s.jpq...]^%..M........J..[.<.b.S,R..+..;S......7..Ae~K.#...L.'.+..n..V.E.. .40...~.k.^*.m[\#{]....e..v.g|.9I.wsH.P.M ..vM.s..]...[.W..9f$.......v''Q..6_....db.h.b..2._.8.a.V.......2....+.v.(.<...<.&....@b.d.Gh..I......8..yZ.8.{.vc[..Z<....d.F.w.4....7.d..[l.Wq.'.[r.b?M%.@6...8g....F;[bBb.Y[.7v'[....iq.Y..T2w..........e1?j.{..rV..tR...?..b.e9....(/...3..(..d...G7.......S.rq....y..1
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 200 x 200, 8-bit/color RGBA, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):9166
                                                                                                                                              Entropy (8bit):7.943044395390699
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:6SR6qSQiN4jFrNuFYJzUYUbI04bYPaJBxKqZcGVlX:1R7GKT8YzUYON4b6sOqZcQX
                                                                                                                                              MD5:2DC231BC7104153AD42E898E7D4E6779
                                                                                                                                              SHA1:9ABD8A5A5CF86DC95EEB72F882B40E69E2A7D23E
                                                                                                                                              SHA-256:1A622555817668F36C77A472DACE4390AA8C2160A1AF60330E9DC04DE9F91E4F
                                                                                                                                              SHA-512:0EF4E68315EE37E5AC0A947085101E55930F6956DB6B01D324012FA709108C375AD2388E699920D6B29CCBD8026399F035C8F657A7D27673C96CB8079783B489
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/sansanqiqi.png
                                                                                                                                              Preview:.PNG........IHDR..............X......pHYs...............#.IDATx..{.]Gy.._.;#..X..F...m..........`B...]*...`IQ.qv.X.J.lR..d.J.j!DKBB.3.......v...%.H.=...H..5sO..G.;s.....s..H..X#.>..._?...kQU".Hg.r....d..D".D..D2....d..$.. *H$.AT.H$.. .H.QA"....D".D..D2....d..$.. *H$.AT.H$.z^...7..(V...~...l. .V.V.}.M...... ..`......Q......(..O$5....q..F.AH.R..:.*....j."...&..T.!A.K..+.....Ke?.....c ...h!...4......xYQj.U.....;c..I..4.[...N._./..~..]..*HW.PV.o.6....K.6.g.2.S...\N..I....P.R`........r..d........i.}.E..r._.l. .>Q9....N...r.'"......MH..(......Y.J.j.q.QR.."TA.5......^..].........s..P._...~.').J........d?......a../.~_...>........YJ.h.....-.<...p /Q....0j...-.Y..,..T.#.~..f.o.1.p@^g |.&.....@...~XE?..].k...t.33.....IU%....c.*G1............eA......o%......<|:.QQ.3A.Z...H.uE.k.....H.r6......z#N.}.YV...._T..,../..g....H:.Z....V._.L...=.d_j].xS.....8...\h.....Z.....W..y*..s...,.r.2l...}...dv....$WA...Q....%...*z..^H.C..(........\....s....b..=.H.Hr?.......}.R.T....GY..z.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):11205
                                                                                                                                              Entropy (8bit):7.960277474462424
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:n2xLuGiAwWCPL6DLIA9PnrUrqTDlgsjpkbK7akvawa8BAULBEANfZ6eLoOI70N6h:2x3iAIj6QwPgQvpkOOkval8AQMTQoFWm
                                                                                                                                              MD5:65FB72A68B9DCA68ADE34ADA3253FC2A
                                                                                                                                              SHA1:5260A46F7843F885A7552940A68975ABF2D62BC7
                                                                                                                                              SHA-256:5BC5DD8A9766BB21896DB9DB9EA8C03E0F16098F1EB46C6BF3F8A33E57D33702
                                                                                                                                              SHA-512:D72B4660ECF6825888E7FEAEE64A3DA20172155A9143342147407C02025671761A6DDAF617E6D1A8297F5FA3D22980CA05ABEEA32AD0423A40DA71BEFAD29493
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE.._ .g..c..a$.i%.j..b.....e..b..^..!.....a".h..`.|X.....[.~b..c.....e........e.{d..`*.m....{h....yT....ye...H...~h.....!..^#.]...n.FB.T..... ...K........?.|5.u.wf...$.`..(..b..$.uPj...yj.. ..'..6.YK.R..Bu.G...;.x..;*.\...[............Z.O......e....5..9.."..3..-/.Z........@..!....0...F.WR.Sg.Lm.K..1............/.q..>..>....7..&......`.N...y....+...a..=.U.....;s....B..+..(..!.}_=.ZQ.Nd.I..4U..O....8..,o....&z.C..1..,_.J~.FD..2.]..?..$V.N..<..#....ti..*....nG.V......tRNS.........N..).IDATx.....8...}.#9...j]X....."b.(h@"<.:..-HH .LA..t.._..$...q.ww?n.;\./.9.s......J....~K..?..._~..".5......2.f.F.....#.$.(U....w...#..[ER.!.....EH......O.z,Q........?..YX..................#;5..r]...W.M......FFl.....\.F.{a.....hzB.#`...rH......k\...-.XE..Q.]Q..4.*.g.......n.....E....c.C....;aP7+s...z8.g.....[.K.{n.l.....V...tL.b.......?....D....\7n..j.vB....\.....<".{.H.a...!...(.z..]..8....I..t..3.3.....S..NHd...Fit.P.w.2..5B/<.#...%x...u.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 23666
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):8009
                                                                                                                                              Entropy (8bit):7.97535595893295
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:A/Dn10YF24KJfq0MECsL4dXgM6M8/eD5prvLSuPbWGRufkY4wtToo2A:A/qYcJSSgXgMh0etpzOuDWAy4+Too2A
                                                                                                                                              MD5:65CE1992B2602CED08520A6429EB8551
                                                                                                                                              SHA1:43FFB4DAE7A6BE836D00AE82593E0E3B6EA8DF11
                                                                                                                                              SHA-256:8C48CE0B757E378977303DC2B64BC1C8AF40A4EA32F4E347A1CF0860502A6E72
                                                                                                                                              SHA-512:FD6BB093FBE9333F978505CB528A6C139B8DAA5C651F930F4DB9466F1E8284707C0AAC9930B25FF08E6278C6B538AECB1CB1732D8C6F5EBCA1EAED5E33DB5E21
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/workbox-50de5c5d.js
                                                                                                                                              Preview:...........<is....W.X...sh)..}....e9..+..'....H."'.F....>.. ..U.E..8......8.K....jY.J..qx.*g*..PE.`%.H.:..`......QpY..N.......?...x{.K.5.L....U.T#..*N.DD..u!.H.jZ....H.Q......P>L..&.....wo...<.O.C.5_.X6.Y.I9.#q.D9......5MS.f..a&...j).P.C..E..2;....s.....l..z.j.`..T.*}....../.xISu....H..z...BL......e..|.1.............|..s......B.......3.e.{.4<qn.5..AS..Wu1..n./.6(.Wb..dQ..h....6H$U...e..E.....7.....I^..U....,..w.&.).`...^.JKq9z.-y.yl.fp[...zh..d..s....KX...p;.x.p!Je....,.CeV.#...R.....v+>.m.....4.."TR......\-BXV.!$..l!..\H......V%.Le@M.O._.|....!PT....H....*......~_W..IV..A...cE...-.P....RK..73=.....8"...u.b...../..h...,W.J....X%$Q.a..h....m!J ;...=....c&........*=/...].....8.-}Z....T5...-.LK..,.Z..d...........1..$o.v@... +..?..p...[.%.w4....$....,..s#.4..l3.?..h.Y....`..T..&.7Q.....3..4..3.....,.q....W-P.ha....+y...F9............f.@.g...a&... .8a.!.z..ii.._A.\ HK.. .....@.\....vI-..rT"..f`........F)-..q.6...h.9:...L.F....#..&.PX?.wB$.C.0m.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 23369
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):6735
                                                                                                                                              Entropy (8bit):7.966923658690445
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:nHpKYZPCDOpSGnmUBTbC8PvH4UgbIAi3ePoEvFrTDmZK0m/9m5WP:n8YMDrAmaTxPPvBuP9Fr2/SGWP
                                                                                                                                              MD5:33EA6B9B7B27190DA2DD780012DE6064
                                                                                                                                              SHA1:42D90A36C0CC3EE44589B4FEC3E8CB3106F19035
                                                                                                                                              SHA-256:C1D4E69547F416799EA48179FDA11C0A2D8331A889EF7AECF3215A61D1E98061
                                                                                                                                              SHA-512:2481935B82390EB2B40CEAB2E94CB1D8B26B6455AB4F0CFEA80999947A3E0A7E703E518347B3E605F1A4BF2EF70BF49F72D11CB4818E530627CDE1ECE9290B7D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2899-f0727f40979579d0.js
                                                                                                                                              Preview:...........<.r.6.."....h..L...g3Uq<.;....`...C.......... ..l......F..n4...~..yx..:.|.\g......}x....b]-...w.._........:..$...~C^.|.n....7z9.A.0B.{o].^..d...-{YL.7o...H...^.y.6..n..;......y/.*N.)..=..|Y.......vR.y.{.4.r..4...4.U.._O....3z.G.CG....1=da.._.i...K..%..g!..+V........d.4...b-.w....yI..vw.,.-....rv..6....}*........d......+._.Y.....aQ.<..9.@.....u....3...1.A...f.4..s..|.D...dU...../.|.z.....-.b..d.3..c... .P....et/D.q.e...ly..f...c-...,|n$S.)+.?.....]4..n..x../.._~yxp.....9k.$Ez......{+.&....i.7..w@.\..\H..Nl.A.n.d...`..Ol.J.{J-:_&UoI....5f..'4M*6..z...40p......i..F..a...Fb.e"P-...3/6t.E)0..J=.FS.%...:wZ.jIW..Z,..&_.4.p..;...@Kk..y~.v*[.._w6......m.....U.R>].z.3.l|#.._X...PH0......Ahm.1..Dd....C..H.lX..q.E..1j.C.T5.Ffn..|[...L*..`Jx......V.....x~.....].;L8.N....'7.5..q^.).?.. ...Ke-3....ci.....<..4.2......'.qT...^.0.4n@...XD....l.s&.;9.....Q]...D?'............<..tU.Y0..|..rVq..MN[....c.........y..;Og.,..bq......W...e9...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 57765
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):19002
                                                                                                                                              Entropy (8bit):7.98837061140078
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:Hy87OSCbDjnbLAeL+E0d+4kCvTf4muI95B5zd:HyAh2LAeKDdxkWzMI95h
                                                                                                                                              MD5:E5670D6BB7BDD7184B272610FBE03EA6
                                                                                                                                              SHA1:092501374C2A3A2D6D398433402397D37C90DEB9
                                                                                                                                              SHA-256:88DF0F1991D008A28F128F8294FE2E355DD00716870B2387A93BC6ADDD571AC5
                                                                                                                                              SHA-512:D6EA05C4FE57B39867060148B040E84A2B464A7CB1B50E95DFBF2EC39A7540D412083E9CCC0E34C356097160739E6B1C56015B722DC091EB5AA69318DA6EF8E9
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3377-f07df2894253d87c.js
                                                                                                                                              Preview:...........}.[..._1...I....x.8.....d..%.nc.Y.Hm..........{..;.....Guuu..9.x#.i8....h...`p.=...../.~......mMg..9;..x..=..x.~.f.@.I.p&X.>..#..i..}H...qc.X.. m$~.x..z.e......{.....n..,.".....I...........d.d0..{.Q.e..`.q..S.{g..i .......Yot^..k/^.^..^.^5.k..Nc..|m.9\t.[.{.......ux.Xo.ll...6......nS.5,...Y.....PM...x.z...X..h..F.ucc...n_5:/ZP.K(EW..P..m.z..\{.y...j.j...."....X./X.L`..1.\7..s.Kf".c>.........s...=...Ik..@.~.....Z....;..V.e.U.<,.gP|..F..\w..[.0.F..G.......i&g~..%.m........{.~.j.?.Z.z..X..b.....'.f...8...x.z...P...M........z..`mc.'.%...*......=......t..^F...........p..Z.>. :.Bk....tkC".".!...^....?.-v..ObE.......a.....u..y.r..\.9..p.......fx..y.O#?n...e.x.y..e.e.....#....x.)\...x..eC,.........^.x..P..6\..3.+...../^...\.gmh...........5....v...\qqp........~r.D..*..+...U'AH.......S\[....i8.IJ}l.x6.)...]..D.[.t..;1K..,^...B..0...T....%H.f.FY+...w.gz..,.V|S.L.....a.....W`qb...]D.~0..G......]..f=U`.G...@....O...g.iI..........pq...<.p_
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 39323
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):12233
                                                                                                                                              Entropy (8bit):7.98281155448161
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:AeD6oD/gmBVCoPZQtAfuJOqEzaLjxSsSCbiHDxLW++KfxbVQxNdFrImKQ510M/Pw:TD6orgKUorxqEzaHU0+H9LJWXVwQPN2f
                                                                                                                                              MD5:57C543D5663D56742DB810A00E7A31F6
                                                                                                                                              SHA1:60526683355A47FB25BF306ABC3D070EBD43F4BE
                                                                                                                                              SHA-256:0063B69BD96066EF2B2F4BB2A9121952C894712AD8D79DF65F79AD875E37FD94
                                                                                                                                              SHA-512:644C17B6404FE08DCD6FE1FECF43FD603B38622CBEE05391975100D0178B5F61E6FAC248B20BBDEA11A1B99203A6463170699A7DB1968906F16AAC6F159BA506
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2116-6cf3ad83077d6186.js
                                                                                                                                              Preview:...........}.w.H...:;>R.`.6.E...qf.....]3.\......I`{.....~.%.Mr..=............n;..y......t.}...o.^...j0t..E:...N.......n.,.Q...Y."..Z...fI0.^....{..K9....IT..z...~RK..>i.Z....xtv.O1<...u.1......Rx.t......Q..a!>.wO...a....|.`.V...1<v..OO...f[..P`..;.......7G.......(x3.F.b....o.y..#?.Ny3..C.}.f..l.}.f<..<.>y3.P<.....=..c(...M.:.G.#..1....y.kf...r`..}+..k].Y..,fY.Q....0.;.q..e1.j1._d.e...<..ff;#.N.vd..a...w..O..z..T.u6z..u...iU.....\`A..`.a.....6G..3~....2...K.=..r.Fk....-.p....g.'..!...!.. r....SHP.G.v.&qb......9O.,...9......$....7..B*.....=..8....;NOC.......<k...$.....G<...'!...'..7<..... ......2.#...;..|O.......(....4...".7._..On.8....}.F..7.~...eWM.>...l..L.w......Q.}.k...)P../jF....7..Hf.....).LjKrj"......r.g.$F>'Z.....<y..\.E..s.sN...... ......o....-.+...7...+N=K..b...~.....h.J^.....a0......G-..p\..5.6....E..5Oj..v.ekY\.._xMV..k.q.i........S;s`.s{....c.~.q....F9....aG...8...d........}/q.m.....1..0.S..@..T.I....,`!....../&|.r:.L.7
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 309 x 497, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):27838
                                                                                                                                              Entropy (8bit):7.978845809426652
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:ENQIj52VS0YMGzCHsbOorT9S3hnQ05bm/hCGCkiZXQ7yHAydwp0C:0j5uYrzmsbOorTknQ0xkCGLNOc9
                                                                                                                                              MD5:48F648A53CD03787CAB32621F6088895
                                                                                                                                              SHA1:408FAC6305133287FDF50315D8212E07F4A0C89C
                                                                                                                                              SHA-256:FA5C757347298A9B2CD0B3823D37D4C1C5A2C75520207F37B61AD9873DF50557
                                                                                                                                              SHA-512:4BFEC883A611D6311350F2266BB168BF8D99B81CE2067A36CFF81447FC684BDB23B1FE5929B767266DF49CD98F8DE314223FB1CD9FE3A5F09C5709A5C3BB6675
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR...5.........;......PLTE......3*)...5,,60/...+$#.1d.X.$.....|Q.....Ay.8j!...<p.*'......hA.wI.M..c..W..].pE.\ZY<..D..:55.+].#V...5..`....=.....Jn.....iE.tpo`....P........p.....OX._..z.9..2.+]u..(.......:.....@<;..*..5...b..GDCg..b....Tc.TRQ`x.q.1e...E.....HXj.mihNLKh.$l..f.j.\q....m.(..=..-pM....h...;k..@...d`_.Bv..D...{xwc...J...dB....U^.s.............\F.t..gdc...w....W..b..g........ZZ....~b....aR.....}}..Q.9o..;...QV....rm....S....C.o.sh...I....X\..J.....;s..S...s_......Ss|.Q..?.P..i.._.3.#B3..LQ..Nu..J..l.]dm..,dG..`..N.......}..7..~@.l..u=.p...f..5|Z. ..........j..._.2y..s..s\....w.....%Vd.J......_.....Kc...UA...t....{.....U..............y.e.C{....\.-w.Mq.w.A.K..i.IDATx...K\W....k....D7.h.CqB..0...)..VW2:.e.E:$....6i....$.E..."..H.D.Y.EP...s.=..;.=gLh......{g.m.....oT%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D....i...................W..|O..^.[.n....h.....s....z.z.....{..w....~..o.'.;;o..|.....>...>{.,.>.B...V.m.[...*x.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 1514
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):451
                                                                                                                                              Entropy (8bit):7.433167046214199
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:12:XvYJYDkpcQRM2DumW3wsn3EOU/XswONgZuCCZqBMjB1Y:XvZDwXamTRdYNMuC1B+DY
                                                                                                                                              MD5:8E8E815BA9CA1F1C9FA6F4B73D563F4E
                                                                                                                                              SHA1:15E703015CC5971373651A10D293376C4CA2CFC5
                                                                                                                                              SHA-256:1533AB66CAC192605EF318E4D439F3E517D0F54DD9A8889D7ED8EE48D51FF705
                                                                                                                                              SHA-512:CA422AA5378D6A78F78F281EAF1BA3AD7818BC082D2AC6C16D98EA52BD05C45E1737DEEB313FD47335B2EFD00A2BF18078BC54FD8084E3C04FD57E0D6D34F27C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:http://www.car1997.cn/@public/jquery.cdn.js
                                                                                                                                              Preview:............J#1.........4.eU.....,.`em.D.4I..6..3.....}.o...Y...3......".....$9.O..............ai%.g."^.2...H ....R.....U.j..,g..5......R@D..EH..\..C.G..;p.M.j9IH.g.......6..$4q..x63.M.........TW.F$Ho.@.6.P..3......yf.......L...eAC...A..$..#.'.{..O..L...|.U.{.%.Fq...mw.|g.G.a..j.......m...(.82.2....^[sQ.F....D..9E...Bx.v.)...CG....>^F8.F..K./6.`.....K....].Y..$.#m.'...G........uu..v.-}.|k......}`.99.....~......]...kr.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with no line terminators
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):44
                                                                                                                                              Entropy (8bit):4.516027641266231
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:HW7uCkp0KthCjNz1Gq1/:2ypBEdMU
                                                                                                                                              MD5:0FE90FC7C4422962ABFC41125D21069E
                                                                                                                                              SHA1:031B5BD4C1F10B6C19807EF412F6E213894F87E3
                                                                                                                                              SHA-256:102BAEF37AD23D0479372EE81A6AFC93119C1B2C40ECE456397C2828B4E471FC
                                                                                                                                              SHA-512:1718875E159DA06DA4990A42D740E47422B9516EE4583CB562F8EBD1F5B7F22B97254C99404E9DEECF7D41F6ADC4E5BBAAF10DCD8C6E6C70DE958860449DF396
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAn5eMPs1lEUjhIFDbPIejoSEAkwt3nqG0oCbBIFDVKKSaMSEAl58OQ7oZyx5RIFDT0fUzw=?alt=proto
                                                                                                                                              Preview:CgkKBw2zyHo6GgAKCQoHDVKKSaMaAAoJCgcNPR9TPBoA
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 400 x 400, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):9392
                                                                                                                                              Entropy (8bit):7.943672888109917
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:FLeHbTGkczyhHOurYuHx3UQYdFy55vLThpzucWwIHUejt+qWm:lSTGkceh9YuRecLTD/WwIJb
                                                                                                                                              MD5:9F896A7E45532C2A4BCA04D3A38EF507
                                                                                                                                              SHA1:86E133B2FEF50175944E489C6133565383C9E5CC
                                                                                                                                              SHA-256:D2BCCBB01B038CB2F450809C36BCC9914FF404FD132EB9670453F40168A061BE
                                                                                                                                              SHA-512:63A43063C39199710FACA3C0C78FEF893B4B2A97D6AA6045F73F34753D35C21AFBBBA72AF86FC494032E4ABA3BA0673DFD7B57D010EBC523DFCB458853915A14
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............a......PLTE....%N.%N.%N:..)...%N.%N.%NC..-.....'..0..,...%N.%N c.A..\.."m.1..-..+.. c.1...%N0..)...%NQ..%..`.."..0..!d.6...^./..#..5..... b..%N:..h../..#..#v.>.. ..8.. ..!d.2..!i. ..8..\..3..#h.R..2..6..#l.5.....5..5..X..9..X..o..X........e..+.._..-..$..3..%.. .....1.....U..A..2..j../..2..5..5..@..9..>..W.....h..T..-..)..4..<......%N ^. .. b. ........... ............[...."i....;..6........>........!f.@..;..8........#n....%r.B.....7..,..8..G..M..,.....Q.....)..=.....c.....=..5.."..&..:..<..U..8..J..2.....#..;..Z..+..2..(y....7..)..+..:..g..5..+..D..*..)..^..7..9..%..8..,..#..6..-..9..-..1..#..(..6..3.....!..3..4.....4..1..'..5..,..1..p........&..)}.'v.&..%..-..k..:..3..'..0.. .....8..(...w.0..,..)../..:..*..;..(..>..=..@..&..F..*../..#..!..O..(..'....>....ktRNS...>.... 0@ @.` .`0.P`D0p`p.`@.p......|P...`....`U .......@.p..P..0.p..................l^...!.IDATx..............................=..m...8......#...&.H..&j..T.Z.....U....iRU...7
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 720066
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):197420
                                                                                                                                              Entropy (8bit):7.998584550189086
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:6144:70DPrDIh2maNdTZhPrc30XXv5J+BRtjLNsQ:ATnIkt1Xv5J+BRtXl
                                                                                                                                              MD5:F5E5A28D40EFEEBC7822F7CF4F0745C3
                                                                                                                                              SHA1:F83714E4BDD33DB0FA488C573BE8C2CE8B7AA1AA
                                                                                                                                              SHA-256:C63DCDCD3FF9011738D90ECD94A60DFF76F68F72442D8FE50C9EE7656968A36F
                                                                                                                                              SHA-512:35CF4E312CB2C58241FF1BCE67EDD542C4FBE23FBDA3B655C0F8AA3753551462F2BB12C62E936C68D3F62DDD927D96AAB1B906CB1034D522ECCF5922E47DFF37
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2101-a1e9e0c0c97a7391.js
                                                                                                                                              Preview:.............[.8.0.W.w_.n...G.n^.i......!..D.o.;k;P......H..C(.{...-.e.F.hN...Onj..z...........S..X..Vm6..f..l........o..0....,f..h.#...7........g..l5.-...nc.e.y....a.9iy.........0......i|...8.S.j.<.......?2c.8.|hm>..P....A..(..C..n.u..Eg...al......~...k.0.B.{7Z.xm..w....5C.6..*....Z..c..k?T...n.B..9....F....n......;.... cqm.N&f<.".)..$.N.dc..M....~...k.Y.`.5-.^..k6q.xhZ5...[x.k?_..._.vu........Z.%..v.{;[.lJY.O...s.......x.Cu...z....3.t....8....N.y.. ....V.@l=z...-.k.l,.r.c12<..D.Q......w4:..Qd..:n....l...k03..z.O.;../-kY...q..+.....o......a.wu........h>.&.Y^..R.{.=..FbE...C!wG.F..H...0.Q84%..CF.`r.0.\.t....k./.DmA.6..6.%+.g....5l...h.....8..Y.6f.:..X|.D.Lq.*...rM`;......aPb..(...A...Yt..s8.C@c..T.../.qm...x.....l.6ug.v).Z...4.0... ;f.H;V..z.....].....xx...*....2.6....i....t}!.a..^.C.t..,...Z.\.1..$......V<.V.mHP.._s......$.B)../3...&g.....Fj.......).Cx..w..yf....]......{...,(.3bH...........2..y.^A..,i.\....q.x.Ma1...p....sZ.l.I....0Z..p.Jr.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):7076
                                                                                                                                              Entropy (8bit):7.950564894223784
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:8u2vJzscWVb7BpUg+OPXr8aeSUDAcBWalDIytYuvpLEmLAgKUR2Af:32vhdWbpHLP78bNoalbaIEmLAgKhAf
                                                                                                                                              MD5:F54529F769913035E9BC66A8B12628A4
                                                                                                                                              SHA1:307730FFE890FB6CCB68E0B4B3A1035CF06B5B2D
                                                                                                                                              SHA-256:EEE83710DE65BDE638DB3085F8A1418FE482523F500AC67AB4029D7D34E2F480
                                                                                                                                              SHA-512:BD386A341E7EA0E1992F51AE25445DA862C12AACCD6712C8289CEC99E81924D2194B6C3BD85E1ECF973094A9178713E15580613A0983E8472149955FFF45CA85
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE.....x.rc..t.pa.`O_=.yR?.n`.[KI$.e;$..u...]/.tJ3.td.gX..q...D..g9.uTG['._3.N).]2..fU.iU.U@zRBY6.oF.lF3.qa.[K`5.yP:.k[yWFZ0.g@1]1.zTCY4.^).pA.b6#|XE.}mh@.f<$kB,.`Q....mZ|]O<..\*.zU@_9$.Q;:...gWrF2.}lfA1c4.c7.Q#.c6 .]G.hY<...lUgPFk9.W,.a2.c3.wN5k5.rI5oJ=Q%.Z..j@&P).h;)iA0c;"~W@o?$rC*hB0^2"\3"a...zigC4.whZ".Q..W+.A..Z+.Y$.M..P..T..z^R.[F.\H.]Cb5$P..I..N..R$._2.Z-.|`RN&.mD,mI0o>%.`HJ..a..wZHhC0nO;qB/eD3=....v...`7"8..b,.W%.h= uG-Q..n:.^*.nOB...=..pD..kUB..7....G..-..{P=.wa..Y$.=...vaL).|R=..y.}i0..Y(.[&.V'.^(.U..R..O..M..Y&.V!.[+.U).N..S#.N..I..K..T..W+.Y&.K..G..C..X#.I..G..[,.Q..Z#.l;$Y*.G..Y..C..:..?..W).S#.W"._..]".d..\%.Q".....bS......%.r....tRNS.......o 3..%...WP....D...F.ba.~<<..~+#......RD:.]:,)"....wgSN.....tt]X......K...........xjf`5..........xgU......yp.........o^]KF4......wN...iU...r&......|..pp....'IDATx.....A.E.!A..$$..X...(...N.x,.`>3l..3.u.-i.y.t...5..................=...4m....$=.>7GS4....L.tS...y{(..)..+v.)..=..&..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (59765)
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):60003
                                                                                                                                              Entropy (8bit):5.144554391978608
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:wfAnnayQIk8HVheIE8Dg76TXQI4vPKMEK6viTlCDFm4n6xOp6Pxg3/wCVaAk1:wfUnTcWCw6xJxg7aAu
                                                                                                                                              MD5:77CBAD27852866CEC1E32648EAAFD22D
                                                                                                                                              SHA1:3EE3E67EDDF2A6A59A46EF6644F93BA97EFEEFD1
                                                                                                                                              SHA-256:2CED6F997D7FCE10A38DDC75C2F24C9F8945F44E746128F3DCD61D923EA3FDCE
                                                                                                                                              SHA-512:A21CF01B710E11583B03EE215163E45B0531FE30D6EB641310B8DEA5AE23360ACD6F5F27AD9404258ED190701C418F4F85386C640372CB38CD0061F10DF48F7B
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:/*!. * Bootstrap v4.5.2 (https://getbootstrap.com/). * Copyright 2011-2020 The Bootstrap Authors (https://github.com/twbs/bootstrap/graphs/contributors). * Licensed under MIT (https://github.com/twbs/bootstrap/blob/main/LICENSE). */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports,require("jquery"),require("popper.js")):"function"==typeof define&&define.amd?define(["exports","jquery","popper.js"],e):e((t="undefined"!=typeof globalThis?globalThis:t||self).bootstrap={},t.jQuery,t.Popper)}(this,(function(t,e,n){"use strict";function i(t,e){for(var n=0;n<e.length;n++){var i=e[n];i.enumerable=i.enumerable||!1,i.configurable=!0,"value"in i&&(i.writable=!0),Object.defineProperty(t,i.key,i)}}function o(t,e,n){return e&&i(t.prototype,e),n&&i(t,n),t}function s(){return(s=Object.assign||function(t){for(var e=1;e<arguments.length;e++){var n=arguments[e];for(var i in n)Object.prototype.hasOwnProperty.call(n,i)&&(t[i]=n[i])}return t}).apply(this,arguments)}e=e&&Objec
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 10931
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3843
                                                                                                                                              Entropy (8bit):7.949372740933828
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:XbjoZ0nLAiJWz4zNeqD6ZRjNI/ZQEtET1EFSuptJT78DkfGhJ:ru0nL8GNeW63pI/Vte2J5SH
                                                                                                                                              MD5:8217208588A037CC472A43713406A21A
                                                                                                                                              SHA1:DEF0979BDD0BDA0BBE3807893E8F6B22A7D5DC45
                                                                                                                                              SHA-256:C525CF706FBC2297722CBE17474BEA655E36C11F8AC334A33D5C6F116FBA46BF
                                                                                                                                              SHA-512:19F9E9441DF60D00CAB656DA715D68D08B660222C49DBF21A3A313DC0A454B96C640DA75392F2F7D80C0BD79A9D1A3610BB2A5B845F030AC97F4E52527D9D8F1
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/1087-7d84e547f29dc5f4.js
                                                                                                                                              Preview:...........Z.o.:..WJ4.b....7.f.*....{z....!.....M.m....s.$...w.V+....c.....c..D<w^..:._..e.8}./.....s.li..n....~..F..w...7..&.U$.[q....6...T....n..&....kw..K4.6Z.Zn..s......ghv.n..x.fs.....Po.9....A....'.c....o7[..hR...0..g./...{L...V..a...]........#...w..ej...D.b.>.....N...}-.e.......H...q..)...%3....N.F.n'.t.+..a4..M..|U.[....DS.o.e.BU.?...e.......gcm..K.."Y..P...[c9.}..:..5{H6+...(.F..n.....vH...Mr.+..|.<3..V.fqk&..&Vh.A....$...."|.....;....k.+.]lX...c.u0..^.e..........sf.Ybf4..c=..xZGI.%......~.h.d4/.....@1.E...e.3....u6...6.X.F.(....`Y..qJ.aA...N....N.0...d9...^...z.T@.)-.q.<....y.v.g.D..T.q....8`.V1*.S..Y.......F.-.e...5.,s^.`../GMi.z.....v..VI..PRC.h....{N....k........O....!...Jx..sX.$....P&a....V0..>.y...F...i....C.....|.S.MaX...>0U1.L.X7b...`.B.1..o.g.&9.......4dJ.z.7N....!.+.(.E[..M..D..wZ............. .<O.#....$.4,"...l'#jxX...DN<....w..IiIn.G3K..'.*.W.W.'..~..`(g.S.a+Z..........3#%`^........+b.....ERd...|.<....'..E..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (3711), with no line terminators
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3711
                                                                                                                                              Entropy (8bit):5.0622390478438515
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:5mIye9kXARbKZ3O0e8WdWyKZSz7lo/S9dgyOn4BdC:Xygkcw5sDoa9xrC
                                                                                                                                              MD5:A52EE49FE4AFFF274F8C30FE880DDC13
                                                                                                                                              SHA1:6E9F90F5D82324DED047FCB1EE3A69AAED0F9C91
                                                                                                                                              SHA-256:0EAA691F4B80B80FE92BD5DCFA943126C6BAC2E4F6AC1E586DE155FA1C287360
                                                                                                                                              SHA-512:FCF79C53EB405B42ED5D0AFE2B309BE3B96CE3F80562CD3669F3239764B9CAFF8FA16BC01D4FDCA12A2E2B624BF259547E350DD205CE77919A1CE0544251F252
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/quicklink.umd.js
                                                                                                                                              Preview:!function(e,n){"object"==typeof exports&&"undefined"!=typeof module?n(exports):"function"==typeof define&&define.amd?define(["exports"],n):n(e.quicklink={})}(this,function(e){function n(e){return new Promise(function(n,r,t){(t=new XMLHttpRequest).open("GET",e,t.withCredentials=!0),t.onload=function(){200===t.status?n():r()},t.send()})}var r,t=(r=document.createElement("link")).relList&&r.relList.supports&&r.relList.supports("prefetch")?function(e){return new Promise(function(n,r,t){(t=document.createElement("link")).rel="prefetch",t.href=e,t.onload=n,t.onerror=r,document.head.appendChild(t)})}:n,o=window.requestIdleCallback||function(e){var n=Date.now();return setTimeout(function(){e({didTimeout:!1,timeRemaining:function(){return Math.max(0,50-(Date.now()-n))}})},1)},i=new Set,c=new Set,u=!1;function a(e){if(e){if(e.saveData)return new Error("Save-Data is enabled");if(/2g/.test(e.effectiveType))return new Error("network conditions are poor")}return!0}function s(e,r,o){var s=a(navigator
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 25899
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):9400
                                                                                                                                              Entropy (8bit):7.975070533025643
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:kRB/W9b1+eKjdS3CdEGHMcIxGJlndMTvKrPxCh40Aae9EizXFeCX9Wby:kL/W9pYj4WEGrIcJlnaskpefjr9z
                                                                                                                                              MD5:A47396A282843E7188AB743F5AB4E0AC
                                                                                                                                              SHA1:A9324CB6C6ED4B3BA2B85814701B89C0357B274B
                                                                                                                                              SHA-256:379B870FEE22B9F1AA66402743352812DEDC346291BB82E3CB9CDFF9A9BBE750
                                                                                                                                              SHA-512:55F86E7C73FD7530609F64B8B49855280589474C7E7DFE7D9314E3DBA27570D27CD74B4A298FC4D3388FA1EE91A0BD1F547BBEE96F432E8FD388D838AB30FDE2
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3067-4af06219e3c735f9.js
                                                                                                                                              Preview:...........}.s.8.......`....)...7$!.y..C6.c......k....cvf..vk_.....K.R....&G.HX..4q..5...}{......k...3.Ks...L".M.dG.m..#....~.....lS.m.f.?..I.\"M3f^....fxx.Ie......A....l..#1..N..EG(I]Q......(gF...x.b....U.L..~....:W..e.9=........P..}.l4?.K..d....IK..w'..3.W...7...w.T<C.._{z.gR.X".9Q.......a...L.{.@.l2.%T...x6.....h..d*.ehF..,..A(,..)........~8.1.........vt..V..7....(.n...i,.io..`h..J......//#j^..f#3...j..=.E.Y...l.$8F........4..D...b.m#:..{.3}.....\L.<.....K..+.._...#v....6.........D...D(.U.0.<....dX.&.:3.%....V+..|>?y{.0s\o@.n3.<.z..E.1.\A..hc3.....).k....a@....JV.y...\..j.[....i...L.......L+..oFA..6o#:r..L).........u..Td..B....K2D..nG.C.F-{...+d...S...t............i!2...}...lB.........#{....G(." ......&b1..}..]^.C..M`|.....i...1.``....)]^.....y.=}l.......0......Pg.-E........%......E1....H.oo`..(....f..K'....l.....1aHk..Gc...}...Tqv.u".XHl'.Pw.3.....k..46.9`<.N...i.O...\e8..]^.....{B.............."$1.`......#Xf\v.ySQ.......-.......i.E
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 1200 x 400, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):40362
                                                                                                                                              Entropy (8bit):7.982468223427335
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:L+hhTB9EEiY7pwXiDPy2QreNtKVNs3uUJKJysdKuBQMtmUqGmDYyxLfv:8tXiocwq25tKVNseU4Jy65DdmDVfv
                                                                                                                                              MD5:E8756F5A60A8553B7D9B26851BEBFA7D
                                                                                                                                              SHA1:09D5262BBBDFEC24E88B8FABA8A00E6B80B8E831
                                                                                                                                              SHA-256:5462953296CDF1F3EC26A1BDA5E1C1212FD09A07494B61BBA542100767600686
                                                                                                                                              SHA-512:BF8213ABC8E70852A572787AFD5BDA54EA525315D341410683A1C31A149AD787CD5E818338110DBC5DE1B17187C965D7B761201C75F3466E9D02601383943A74
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/gf.fc8d6758.png
                                                                                                                                              Preview:.PNG........IHDR..............kil....PLTE....*|.*|.*|.*|.*|.*|.*|.*|.*|.*|.*|.*|.*|.*|.ub.tb.ub.ra.ub.ub.vc.ua.iZ.s_.ub.vb.uc.ub.vc.ta.uc.uc.p^.sa.r`.|h.^N.OB..o..y....*|.ub.kW.^H....}k..#.ZC.wd.vc.aK.dO.ta.mY.o[.q^.fQ.hS.s_.iT........._..:.~.yf.U>....xf3.yT...n[Z..*.s...}..C.....f..............x.....P.....lg...#.o.O7...............cl...........{i...r..........rd...l..... .mI...s_......%.q..........>..n...iiu............F..6.{.an.tc...h.......w.fk..... L...pe.zg..$%.\z.E/.t).n6.X.H/K...y`..".nf`.M..7N.Q..9,.Z..,..l....\qC.T..@..*...n.I..'..'..2..2..>.A'..#s.........)tRNS.w."D..f..3.U...F.....+...[Rb..8xl..P.%.[.....IDATx...[O.A...~...Zl.R..d..twvv..u..i.....Hm.R*....`.IM$...L..Z/.lmKU....e7.d..9s2...B..{.....'$..'..^...K@....D82.t.....!..._w.._...H\../.C.1..B..qO^.K...!.,..M...!t...#R.E/.+ E....!t...)....+E.8k!...;8.s.K..M.....j.X.!L.0t....a.B..u.'-.._.....J.:.k..9.3..J..hD..F......s..Z..)....v.#..........(.3..k...;.....'...........[G...........B'.........y
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 7670
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3188
                                                                                                                                              Entropy (8bit):7.928676305686423
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:X235qAv02CEN/0O7vrKPZuGCH1sd1z0o1jBbCDU3DHYt9gVSEODurOQB+/UmnKrm:msXEO+rOsGRd10orKUqg1Y85iKrm
                                                                                                                                              MD5:3676DDF77998D2B88F9E29F8A12ECF1E
                                                                                                                                              SHA1:2A83E401D0B212968428838F3F7F059F00D7F8AB
                                                                                                                                              SHA-256:CDE17FDD67009FC409CC46A85A806E29D146CEE89228022061C78DDEF4A893A1
                                                                                                                                              SHA-512:81602A720713D03250926EF109DEBE2E88A3CC2F523857D209625DD247E91293D07ACA3E8C28FE4120EE46015CB4FB9D463C7CA30038CECBE39DEF3952C752E9
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/pages/customer/main-04a59987abf32104.js
                                                                                                                                              Preview:...........Y.s.H..W$j...c.B/.....n.Y?.9v.....H....A.....=.@..r...U..<.{fz....So...(....i.?./.g.......E..x*..7.F.....2{..w8.|.'.pe-%1..<b...\ueJ../%...(O".f.d1;0.......J.nG5fq..i.M...SY|c{.=...._0.bG.z...a...>..B*.%..*........FA.??.S...M7...\n.z.OSb.F..S...8.K.}PM.cW&.A$.o..$...G....j.tQ{.E..NL....k....U....d.N?_.........m.X9..v;.v./..M....Zz......7.....M7.....0.nW!^i..4...kq....8.m6.....htL....X!s.k.<.L..oT!Sl..+dhU...q..Z..Be.....\.....x.f.N..r._.Q..T..<....#.2............G..'.W....C../3.."|..../.6g.....#Z.......6.m...bg{..s)..3.n=.G.......@K....47....%....#E....IDr..N<.-.L.J.A.d.pQQ....@.SdN.l.Z0..!....iq...t$..,..#.c...#........./.ks:...3...r.....da..<{.p^.$....,....d0\5..8...."6a..m......,...3_^.s.....86.u.-.F).....fz~*..(.r.K.....G{...-O..<.W].QA...o..0.VA.@...8..g..,Pc.....*g!8Y..";..9.PM...<J.....{i#.la#..(.~@.|w..<J.....v.A...%.I$V..r....L...X...A.$.N.;6.9.8........Q.%Jo........../.@5....9....#......F....`7@.......Y.....~....."T...T'..."=J..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 13012
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):4857
                                                                                                                                              Entropy (8bit):7.953282293167122
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:5zcR//7411BwQCzVLddA0fPSf8mvvbAo71z8LH0UUpV:5QR/GBjAVLddw8m8wYLHxE
                                                                                                                                              MD5:2AE7612935BE22A84EA7ED77B0210816
                                                                                                                                              SHA1:22A4360ECF39A1E8818A8DED1B1907086D8A7476
                                                                                                                                              SHA-256:425EC4E97C3C8283FDBEACA73CAA2D9676AB4218E22E53A396F7A09F4BE2D3EE
                                                                                                                                              SHA-512:248991DF2CE195966813834A188F6159AF79C56999293FDEC49355590E6769503E685EC5CD62AD23C95C5CEE255CC1B269DAAC449FE326A21B5F78FCD30BA650
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........Z.w.6..+2..!......jY...:u.?..j}(..hS.B..eI.}.....8{o{.s{R..A`f0.o.Pc...1.l.vo.............$..WW......6...%.#.0P9.,.J..Z,"..J+.]U..r.6..H..v4.k.;;.yV.6676_k,@.....m..h..\74f..m4...s...lnch,{.-.%....Ba.7.{..u.0q...&x.o..Qo..p.t.kM]~.9..{.y...`.o....b.c.`...?.M.5..[l}..a...._46.z....k....[..f..v....S._..^..G..C..Y..).L.....-<....J.....&.=.....#s.3.D...a...\7 ...c.hh..Vs....#+.....r...G...Y.7...-..*.Z^O.z.\...'Q8..O....<.{ch....z...<_.HU.}.../.b..N.D.I.u.$C..P..H..n.F.D.....9.u....|6sY..+t....E....wl.M..=X.....#.U...M.r.....a.~...<..&..I.h..P...K.y?....F....N.8.........l...)....N....p8.....6...Q.......^AbP..k&6/.T. G.....m.m.z......=.[6......f..d..l...hh.....z.(.Q.....r..x=.....s....b.`u5..UaA.U&.Z..".......@...u..\..-.^.k....Q.0.r..oB/P.^{...{.$.E.Jjs...~g...)mo(.V.)],s......D.F.p.E0..R]kcO.jx_S^.k..J.kC/...5%5..6..._@......a...@.Ql..d.7..F...:q}....|.&.q-.r-...w4v+U...._.......[3V,...w]...,. ...{?..0J7..=.....kG\.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with CRLF line terminators
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):356
                                                                                                                                              Entropy (8bit):5.200147268782827
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6:qgU3MrXoRLHRnIEVWg+8mgO9l3dAicLmqRM6L9GQd5RQVJbDRWUkEmkU8SNe:w3yXELHh5u3dAixqRMw2DRWUkEe85
                                                                                                                                              MD5:92973AF70EFB80F519FC84BCAAFC0CFF
                                                                                                                                              SHA1:108947685523423AB2C4E29EFA98D03CB55CD5DE
                                                                                                                                              SHA-256:992258FFE5DF127430141CC6D069E6D46227D44DA4E2EE3905C1055B988AC008
                                                                                                                                              SHA-512:541DCFD5B5E005EE2652DF47861C90AB172A6E0E0566EC2E5716AE957115453D283F2B21DF36B5B425DB4AAA8179EF3AACB799553D6EBD115AB035453A77EF28
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.tvwxbvay.com/chat/chatClient/refactor/scripts/robot.js?cv=6.7
                                                                                                                                              Preview:var live800_robot_server_url="https://chat.ybtest4.com/chat/";....(function(){..var live800Script = document.createElement('script');..live800Script.type = 'text/javascript';..live800Script.src = 'refactor/v6.0.1/dist/js/robot_new.js?v=1737320474350'..var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(live800Script, s);..})();
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (3570)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3700
                                                                                                                                              Entropy (8bit):5.078425834759615
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:gzAJWcZGy03kp5kv99lQnDNf2LpF9lVHQA:g+WcoyikkvhpF9lV5
                                                                                                                                              MD5:53BAC3D4A791A661E030A6EF46F7713E
                                                                                                                                              SHA1:102FB4B9323CC5A326870DC8887E8EA348327D93
                                                                                                                                              SHA-256:E289218B43535E4DBD586A56DA706ED5266933AB6E8A518BE8A7651CB28FAC86
                                                                                                                                              SHA-512:008750F1B4359B84F96B5F48D3DF9EB631B2460D24B80D6C20B5AE8D54C9B7AC26EEB5A5A75F6E3EAAEE91CA53086B3545D73AAE42A4A151AE3B585158E719F8
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/css/robot-8b4e8abbaf.css
                                                                                                                                              Preview:/**. * @Description: The style of client.. * @version: v6.8.0. * @time: 1578286481642. * @license: All Right Reserved.Live800. */..robotanswer .r-media-news{overflow:hidden}.news-item{padding:10px;border-bottom:1px solid #f3f3f3;position:relative}.news-item img{width:50px;height:50px;margin:0}.news-item .news-item-bg{visibility:hidden;position:absolute;left:0;top:0;width:100%;height:100px;background-color:#000;opacity:.7;filter:progid:DXImageTransform.Microsoft.gradient(startColorstr=#99000000, endColorstr=#99000000)}.news-item-first{height:140px;padding:0;border:0;margin:0}.news-item-first{height:auto}.news-item-first .news-cover{margin-left:0}.news-item-first .news-item-bg{height:30px;visibility:visible}.news-item-first img{width:100%;height:auto}.news-item-first .news-item-txt{position:absolute;bottom:0;left:0;width:100%}.news-item-txt h4{line-height:20px;font-weight:700;font-weight:400;margin-right:60px;padding:5px}.news-item-first h4{position:relative;padding:5px 15px;margin-right
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:HTML document, ASCII text, with no line terminators
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):94
                                                                                                                                              Entropy (8bit):4.308445100434533
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:qTkIDZxVsJYkARQJAZ97XHXbZ6iF4:qTjxVgYk0QE97XHX965
                                                                                                                                              MD5:C48D26518CEA9F7DA55482A7F8FBE858
                                                                                                                                              SHA1:F1A3832B8B47004DB025B6F750ADC6A7563E5EC2
                                                                                                                                              SHA-256:3E996545A33EA2F137DC6128B3BDFE00DB53FE4ECA124867531BB2674EEC5903
                                                                                                                                              SHA-512:106D62A657720046F165655811618ED93D357299F1BB4BA2F3D4E8B35698F014CA0BB2C45344A1285169F49E50962B599ED2058B03731B45CF0C54E96257CA23
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:http://www.car1997.cn/favicon.ico
                                                                                                                                              Preview:<!doctype html><html><head><meta charset="utf-8"><title>XXX</title></head><body></body></html>
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:RIFF (little-endian) data, Web/P image, VP8 encoding, 5120x1860, Scaling: [none]x[none], YUV color, decoders should clamp
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):124060
                                                                                                                                              Entropy (8bit):7.990984664385903
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:3072:jazqGVBSUs0oBKHZIcSTfxau91/zL5BRSBuaAti:jlGzSUs0tFmb/zS
                                                                                                                                              MD5:88B1EF1F9F07B890387B2AC0A7BEDE72
                                                                                                                                              SHA1:B90E7F2689483DD2A49459952F008F18F2A658F9
                                                                                                                                              SHA-256:AFEF2B2B7EA3F79319675E2B8C31F63345C26D7D6DB1BAB0A84A625A976CE072
                                                                                                                                              SHA-512:7C4030EA62A835CD6C6F3AB2326B780DF3BB7029F1D3342642DFAD886AFA739422BE645E7FDC00E65D3D92DEF282716FAA46B1661E50CBB52F7E4E7175F48B0C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:RIFF....WEBPVP8 .........*..D.>.F.L+..*.5)J...im~.....O>...s........hp5~{.$./..?.......?.}.......'3.g..x=d..s.;...5.............g......S.+v=.....i/..V.G.....y....S.....`..............W......n.A......Q.I......?6/...x..?....{...n......L.<......m....O..j.?.9.X@..V..:...RFe.:.I...AN.~u./...*+....Q.].k.2(..w...,....3......w.....w.....w...j.....w!...#".e)=./.......].qf....W~}.].p.~u./.....r..a{\.iqg~}ym.w....|J^Xdv.O..Z....T..%.....Y.k6.Cz.P.7.....Z:...h..Q...."...".;......9..6......T2vP...L../..n.j...s..0`.$...._...v....<..2 .....u..':.........?>O...XO\.V`..-3..m...g.......e..;.uy0kc.W.Wg...}:...w.....r.L".a.x.IW"..8..Z$../Q...G.3{z.g!.a.U.g~.S*|../...Md.......dV.\.......x@e..!.......9Dnp_L..)l..`E.Mc.z.CV..^....v\f..P.....=...F......./&@+m.>ZV.=..Ys.w{3./.fD1.12\.W....G...HML.GH._0.l6.l...p....W>H...........w'j......w..[.~I.0.OG.D..}.].....W...E.....\.^...vR..\.j.wn..&.=....rQ.iB....JkC...y\..]5Y3K8gZ./.&.D.k.u*g'5._UW.[.II..F....b....[..0.f..
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 1000 x 200, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):16171
                                                                                                                                              Entropy (8bit):7.957091246891598
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:reyaj11iAYigzr+UggEO+SWnbpsGTfW2XipW0VzRyYOAqW:Kyi1sATgPZE8WbDFXJ0tI2f
                                                                                                                                              MD5:C0C473FF65D53364B57BAE47C1309DDD
                                                                                                                                              SHA1:62117432116DC2CF7C9DB76F20301D011E6C33B5
                                                                                                                                              SHA-256:6ED60433BD74F4340F70783C9037C1614A6578188642F74AEDF451101EBFB3E8
                                                                                                                                              SHA-512:0D0DEDBE83A264DB883CA08B7F9DE8174B9C21F1D9A911B0CA21382E62B9B9464B95785206594CF8EFA72B856A33A40CD23A73327CB6364428863D0768D49961
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/banner/banner.365.png
                                                                                                                                              Preview:.PNG........IHDR.............L9;}....PLTE.....l.......59......r........&..*.r2.V6.F6........"..*....."...\.T..'5.|..........)..b6J...1.........l.>...t...........&.!*..74.`.~2..[ .u.9.....(.f......6...."B...6..D...:..+.....b../X.........3h.F.\..'.{....>?.....!G....t.K... `...VW.....2.....>e.Iy....J.....(L.^.....n..z.......O....6..........w.............*..I....D.S...G...d...MQW............,4C....,.............".t..........?........f...9..HK.......~...l.*'.#....#x...........G...|....../......~........a...bm..`[.........wt..Y.............O.........hj.[X....?<...."...6<...7.P...h..:Z#........p'}.wG..0......g[,...........X.t...V5..BJ.44.N.F.x..Z....2.n.n..f+....tRNS.@..f..<WIDATx...1k.0...K......n..C.................U...]..^.$.1...].!r...9 .....9 .....9 .....: .....9 .....9 .....: .....9 .....: .../.`....y..?....sUcB.6E..Uf.g........&S[!t<.5..8...mb't..E.q...j5B.P0...n..1%k..\.3<..Py..N.k.Z..1f......Q..:.3..._....m.(.~]].Ir......:...y..o....{.]./oNc.}
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:HTML document, Unicode text, UTF-8 text, with very long lines (673)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):59426
                                                                                                                                              Entropy (8bit):5.58164741735618
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:DpwZOKkIjsrxBLo8Z5tTrgbxwI1e4FSjnInAU8DIKIEDpfr6YIVn4kjhliVUbWik:FwZkIjmT+5A+2jwli+c8KxOKkKL9V
                                                                                                                                              MD5:73D9E4355DBF65CAAFC19428D611F02B
                                                                                                                                              SHA1:806F645CECDEF00086781669568571F7A20559CF
                                                                                                                                              SHA-256:C5F7A93DB272E6DDF8292FC64822FD62E8D4F387EBDD3A45CCEA44F08CE20934
                                                                                                                                              SHA-512:3E53DBD69DC18EAC6244252C33696B3748EFB600D0C9DD09F5C579EA4FB9D25CDA2CB60EBE10DE1DDD066A371B0B07151A8AF47A819B61326CF1AEEE38BC0060
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/
                                                                                                                                              Preview:<html>..<head>...<meta http-equiv="Content-Type" content="text/html; charset=utf-8">...<meta name="viewport" content="width=device-width,initial-scale=1,minimum-scale=1,maximum-scale=1,user-scalable=no">...<title id="titlename">....</title>...<meta content="" name="keywords">...<meta content="" name="description">...<link rel="stylesheet" type="text/css" href="/css/style.css" />...<link rel="stylesheet" href="/css/modalStyles.css">...<link rel="stylesheet" href="/css/bootstrap.min.css">. <script src="/jquery.min.js"></script>. <script src="/popper.min.js"></script>. <script src="/bootstrap.min.js"></script>. <script src="/banner.js"></script>. . .........-->.. <script>. document.addEventListener('contextmenu', function(event) {. event.preventDefault();. });. document.addEventListener('selectstart', function(event) {. event.preventDefault();. });. </script>
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 39710
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):12845
                                                                                                                                              Entropy (8bit):7.983464431670178
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:384:xFZdSH4uSFBEtXJtBi6WEV/V30zd/JyzUw:7ZdSAFuFJ/UEV30p/JYj
                                                                                                                                              MD5:A68A257656205E9D1D038DB35B9578A1
                                                                                                                                              SHA1:C9CAEC95E9C2B2DEEEB89BE54338ED54F3DB2A36
                                                                                                                                              SHA-256:43CAF410791E3CF974CDC77C5F8E306479EC0F4BEFCE7F27D31898465DA3E7B0
                                                                                                                                              SHA-512:0FE922D0A8D9F520B34EFA5D299FFBA476A8A5CB756FBA1A6DACEEFD8CEF2FAB0718D2FD8E4BFC47F23571EEBA8F545E3520D3D382E918BFDB07CDCBE7627F8D
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/9926-1e487a63d7adf9ea.js
                                                                                                                                              Preview:...........}.v.F..`&W.....%Y.....~.=I..v.@.i.. .jY.~..U..B...s.]k...P...]....f.7Y:.O..*............i-W...<:ju.....l.f.p..Qhx,e...W..%i.OS}.Z....E....^..Cm....'.b;4...Q.d...Q8...@On.u.i..67.w.}t7......u..f.t.8....3'H<}.s?pc/.\.j.N:..q....N.ji.~.j......Z.|......5.]....i.y.Y..v...5....i7.[...N..h...5..(h.......z....n.YGZ..:.w*...:U.Q.u.R.Y.z..F..Ch.+.......n...zGPA.i...n.2..;.V..m..GV_k.6...:.m..T....E5*.a.....u..h..kC.hN..~^.;8.i..G3...z}h..._./.x....c]............:....l....&=..D.h...j.Q...L..o.W[.:...o..,.{......=..#.x..C......h..4...;..l...u..L.....$.....-..d..RF..lMs;.-.O...~.......F.K.>.ck..N..f.onY..;:.....G.h..u...A ?<.X.q....P.E...o.5m........!...g..[....! ....o...|L(?......~.7;m.A...A..F.n...>....xy,.Q.1/..}QLt......I....a.}.n+h......>..'dn4.M..F.....X..D.m..8.k.Z...a..u.8M....mw.u...6..6MS...{hu.&...5.}Q...Sx^ .M...b..,0/.>D.#r.o.3.p.(3.;.N.;.uC.......g......[T;.><.mG.n..0..`Sh..z..9L......N$.%......-(}...L.3.|\.*..N.L......C.He.Z..8.b.EG
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 11375
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):3905
                                                                                                                                              Entropy (8bit):7.938186006820755
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:vfZpD+LqhciWWfqnBya9lTwZk6Joix+k10QJH13puAzAe:vBpJhciWhBya9lT0k6J5p0QJH1IAUe
                                                                                                                                              MD5:CB5CB2D293D4A87C13B9D1298DCC92FE
                                                                                                                                              SHA1:50BEB7182C516481C1561F8995F54FACB56C93E8
                                                                                                                                              SHA-256:7F830374227B14BE54834F4D2D3DD8C4A7970F008F7BC79D9D1F1EDC0FD4484B
                                                                                                                                              SHA-512:35748B4ED2F7BCC044F68668EA8C3EDEF15153F1DE81774C1BB6040BD06D2A187B90960A19DAD28E564CBB121CD11B86DC7622C80688792E603C7AAE50230CAE
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........Z.s.:..W..n..O..J.L..e`...3..sq.%..R.[....=G.[v.......z..}.;.9(X6.o..2I.=[....o.>.w.n6..$\.."..8...]..h...Q4+E............*..o...."xx2:=&......d@.....Gd.....ex~x..........&.....Y..<.%.k.../D.}_.T.io...5S,.....7....VK&g=F...S=.."y..}`z!.%-....C. ..F...t.E{0..L....7.f......0.-..ra.\f.@-xA....GV.=~xrzz..E8..].7..5.U..u.''.N......]_'.L.H.%.U$....YRf.=...d|q.og9+.....N.S.z.V.....h+.`X....s0.........P...........ut!.IgX.(.....N.D0..60s.l.L...O6.9..<|...b.\.J.....`P.....x%8@dm..pv.;.x..d2.b..6....K.....F.d...W.......7.U[i.)*[Qy.5..|.]..<.....a.z0<.c.zoA..y.......44.9.(.0i...7..D.../A......!&....I.tZ?..uEob.!.....V.?..B..P....P.=..\L..w3.2..e.S..:$V....4I.._l.J...5......PIf~.x@...a.H.{L<x..;..n...h-'....k...y..092H.T...QfY...fc...'.1.C.....0.X....T.k....!...&V.w.....@s.".fa...wW_...(.\.._p(...g.x..........u}x.5.Vp.Z.W@y.]._..D%..s..<..I2I.B....Qg.Vn4'e...9.1..v...n..\.Y.Va.d..z......*........4...j.hp.....s..s.BP:Tf@.....1.....L.ZMk..Z..l...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 250 x 250, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):6928
                                                                                                                                              Entropy (8bit):7.953647279949998
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:ic/wi2N9CN9PKE+xsWJ8Ihe9+dkJfWW/M:nN9CE+KZwqJfA
                                                                                                                                              MD5:4F9F1C048148B5759DB7C70D4427CA5B
                                                                                                                                              SHA1:40006416FCDC12C925F6069ABA457B2B85552AE0
                                                                                                                                              SHA-256:26B6D720A2DF9DA5151756FD37EC0C69651304677250BE9D7246936835E5ACEC
                                                                                                                                              SHA-512:07E2BA66990B3264D29482D0ABBC72BB43CDA4A94A839CC91579B98692568F67AFBDE43A74A44C8F8170A29947769696C6614B670F762BA2950A15ABB8101559
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR..............2......PLTE"""...""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""...............)))............444......FFF///www@@@;;;...............kkk...oooKKK......sss]]]...bbb..................SSSWWWOOO...|||ggg............A..C....tRNS......~`1...XU.........IDATx...Yr.1.EQ!.=7c.... ....._...r.l...2..sIM.....}R.R.....T-k...U.~a......W.+.S.B....F...9.......>......!..&.........=+......K.+....xMo..^..x..9..R.N.t?.&m...6.j0..{.....5.}.d?.*.y.j.+.".(.".(.".(.".(.".(.".(.".(.".(."..]+Qj.....;.............G.n..fg.S...3/.bEV..u....C.w...#.P.....?.=.....@7./...:.X#..9..."......?...&.[t..Q....AW...'P....0u...G.B.....o.........%..E.Ph.........=.]..5h...I..>u!.".:.,....\gjP...?K..W.....Cs.X.A.2.%E.ql..N.G...M.....6;Cw.aE...c......@...A?`Y..>.............<..X`....@.-%?m.....9..Rs....L.>.>!ypDY...7....HS.....hU.uf.....E.{.......|.P`...^.$...N./L.}..68o.,...)...K./...w..........r..!)..SGl].[<..<..<.KLI.!..<.....|5..f.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 3593x1400, components 3
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):296412
                                                                                                                                              Entropy (8bit):7.931124631952406
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6144:jsw/ojc+qPxyYKTsbcGPp5iD8PRCb2otJdY0b0raG0idjHlaDfBW:pQjc+qPlxS8PREFtEnDblIo
                                                                                                                                              MD5:ACC29E2A810DBB1885ED42BCCFCC3DDF
                                                                                                                                              SHA1:16175006F7ECBE64FEC2BF622188680E9620E525
                                                                                                                                              SHA-256:40A9EF15524032293E0F19486DD17456585762F1FCE3BA47349CB2E79E2D56E5
                                                                                                                                              SHA-512:32FF9CFCE71411FF45F847F19D4F21111E4DB8A058D9440DE2483D3F228C033C3D5AE14AF05A45DB93E1BF1D017B479D74F989E8A11AAE3F3E72BF5DEE87988A
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/bg.lanse.jpg
                                                                                                                                              Preview:......JFIF.............C...........................".##!. %*5-%'2( .?/279<<<$-BFA:F5;<9...C...........9& &99999999999999999999999999999999999999999999999999......x.........................................................................................@..T......T...T.:..`.X..V.....B..M................. D.X...e...e.............(..............*.....@.................D....P......Y@.@....R.....P...U........!...!.t.".........I .......P.....h..@..@ P......$.QTP...PI11[b.[+A@.I..`...............)M..%Y%@...L.U"Q6.J.aQ..........................@..L.......X........"...@...( .($..... ..X...,.........*...... "t.D N...B.......[.@........YEP........".:....4.............$.............B...(A....."-A.%Ye..%YX...).d-..$..V.....$..*............D.l.*N.T.-lb..PR..DJ........"..........M"......&P.......h........................U.................b..*.P..DM............@.l....*..Y..@......+ .............................:..P.(.@ P...L.H...%I+T...X.A2....ex....DEX..`....*.......jR....M....DI+\.".+J..PE"e
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 19125
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):11948
                                                                                                                                              Entropy (8bit):7.98047710734264
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:akrUNUJp6I5L/FfEDI2ZMlXh64D6us+Y3b9+EfLF53yCka9TFk79nLMyj:aqUNOp6Q/FsHZsFG3b9+KX3AuklMu
                                                                                                                                              MD5:8019B87B5A3166C97DCC474645AF5934
                                                                                                                                              SHA1:833779C767E528D34D6CD1B9B34DA8AEC537A82F
                                                                                                                                              SHA-256:E18249F767A22EF2F99B9FBABD9DCD663C91CE697B82F1EB69B7E0F49D274405
                                                                                                                                              SHA-512:E1727921268BE9DD639C6064B599E4A780E2FB8D09C5D10E2DE7E30E95056A7FEAACBB870E85AD4F61C926F70D3AEFFA9C9F06E0E739759B13D4D315F8843691
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/1618.3c29da88cf00bda6.js
                                                                                                                                              Preview:..............Xr..W|.<...4.MF....I...'w&wr<...J.z.gl_.g.B.H..9.../.Y?.i....Q..........wG......>..............G..`.s6..Tt.O...S....1..q..x..O...O...Z...._.`......... ....;/I..?~.....B?~..K.C..y.>.D.....p.=G..Q...i./...O..O...H...O.. ..../OR..O./...6l....u.((<.FT.3A@..h...>M{.>.0....5.....4t.?p.?..-..9...P.>.b$z.....:....@.eE\.....$....q.~.....\....O...p....?}...L....b:.C....>..?..?.~...N?.q-.....?=.".N.a.O..!>E.P.$>......-.?./.S........?}.f...=#q.1.........wF.~5.#.....G#}..f$F.k#.(N.h#...c._..~..-....&#..........7.|..E.`.m.. ..C..F&.W...5.....?...=.P... (F......j<..%...ji.FK.G-............h.. .?..?.?'i.....Y.........Z{..I...3..?/i;.t.k.8}.......mp..4`.3...S..d...B;../...S.K.s.s_.S.....se>.../]...x......s.sp..O_...O..!...N.<.:...7...X..e.I..^....<e.....~.Q.d5.u.)..y_'./.n.......w....S...<.........l....@.JM].[....a>.@...^~...{...?_.m....y..>.NV.......nr;........&.......+..k.....9..?........?.v.~w.....M...`...._.~......7G.}...'~P....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 176729
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):63003
                                                                                                                                              Entropy (8bit):7.994332664626425
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:1536:J+k61YOeidA8ti7WtVLjKUXBZl20lZG9Om:MksI8ti7WtNWUXl20y
                                                                                                                                              MD5:50FA74C9D455F9179B3ADAF66EA1D785
                                                                                                                                              SHA1:0A96C05A5A72171101F9B6B93D13FE013B619DED
                                                                                                                                              SHA-256:90218831803EDD8BD61E3B1F38D59ECABE8AB01936924E9445E6CC697EF87BFB
                                                                                                                                              SHA-512:C17FE63FE854463ED5E4A083891A2A3F02AC1B14BAC66A67AC5BD46BCFFC5705B0292656DA66ED1949151A3C7EBCDFE81A179D3D719F5F986B30E6126AA09660
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........W.H.8....\..#,..C..C.I..$.Hf'..#[m#0.G.y....U..R.....=...f...wW....OF.-.......|zu~t..L}|<=...<.0OO{...{h.[n....4..&g).Z..<..I.......?5.z..X...N..X..S3...i.N...xl.;=.9.......=.......m....6;.u...V...cl..4 ....N...jjf.CHk..P..V..4!.5....z...N.k.K..7-vD-u{Mk;.....Z.8....O..(.G.k6....O.#....Wz..Kz?......F....v.....1|.rN.....^..Y:...)g..5....?.=l..C.l..H....Us...(.9.....q.....+XUv+S...!O.,..._D.'....<......h.`....);.uva..Z.C.........-.ZXv.>..L..@q..P,s....i..}...}.,...2....C.G.|.~.c.:.N.....L.g4...8...=..........V.|....ly.s......q..0y..._.....,.i....Z-...?..aj.f....^.....N..,.y.L...-.d..Qd>.a:...6..x....5...b...m.....]C....|d_&w.i........?.Az...fcv...x.N=....`.p..|....T....p..64Vw|hl4.@cn....J... .>......t8|m..n....G.:....:.uF.....<.a+..|u.A[.wy...C.u..l...]l.._..+ze....(.1.@6i..v.....m...<m._.j.........SY.W.#.....i.0.W..op.i.b.......f..h;..<.n`...i..(.....m%.!.e.......K.2|@.uOV...[Lfq...jO"?..c.(..Z......S;.qr..R{....Q-.rl.o-S}
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (59765)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):60003
                                                                                                                                              Entropy (8bit):5.144554391978608
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:wfAnnayQIk8HVheIE8Dg76TXQI4vPKMEK6viTlCDFm4n6xOp6Pxg3/wCVaAk1:wfUnTcWCw6xJxg7aAu
                                                                                                                                              MD5:77CBAD27852866CEC1E32648EAAFD22D
                                                                                                                                              SHA1:3EE3E67EDDF2A6A59A46EF6644F93BA97EFEEFD1
                                                                                                                                              SHA-256:2CED6F997D7FCE10A38DDC75C2F24C9F8945F44E746128F3DCD61D923EA3FDCE
                                                                                                                                              SHA-512:A21CF01B710E11583B03EE215163E45B0531FE30D6EB641310B8DEA5AE23360ACD6F5F27AD9404258ED190701C418F4F85386C640372CB38CD0061F10DF48F7B
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/bootstrap.min.js
                                                                                                                                              Preview:/*!. * Bootstrap v4.5.2 (https://getbootstrap.com/). * Copyright 2011-2020 The Bootstrap Authors (https://github.com/twbs/bootstrap/graphs/contributors). * Licensed under MIT (https://github.com/twbs/bootstrap/blob/main/LICENSE). */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports,require("jquery"),require("popper.js")):"function"==typeof define&&define.amd?define(["exports","jquery","popper.js"],e):e((t="undefined"!=typeof globalThis?globalThis:t||self).bootstrap={},t.jQuery,t.Popper)}(this,(function(t,e,n){"use strict";function i(t,e){for(var n=0;n<e.length;n++){var i=e[n];i.enumerable=i.enumerable||!1,i.configurable=!0,"value"in i&&(i.writable=!0),Object.defineProperty(t,i.key,i)}}function o(t,e,n){return e&&i(t.prototype,e),n&&i(t,n),t}function s(){return(s=Object.assign||function(t){for(var e=1;e<arguments.length;e++){var n=arguments[e];for(var i in n)Object.prototype.hasOwnProperty.call(n,i)&&(t[i]=n[i])}return t}).apply(this,arguments)}e=e&&Objec
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 7610
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):2890
                                                                                                                                              Entropy (8bit):7.921041633248446
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:Xi3d9f673MDya84VhHcrLUZfT6Mz2HaZ/iiIvJ5nY9HHApw4iiA4gp5d2+A9B0Eh:qy7F6o0ZTuH9XnOHHAfXAJdL8B0Eh/
                                                                                                                                              MD5:32A9FBAE4A39B108F5D8BDB6C569713E
                                                                                                                                              SHA1:454464BBFEFE9CAEE9BE89A978F81EAA337006EA
                                                                                                                                              SHA-256:56DA32E82E84CBED56A03E2491A21EA74B36A9DAB568F1D9170C969340D89DB6
                                                                                                                                              SHA-512:90305777694E61CB2E325905C252AAC0B7D7E7AFEAA0D737FFB0B2DCAA76AC85C522AAE05DA70EB659E1C5B2386753E13528E67EC2C8F3A56469B2C1B8C003B8
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2957.feefbdd61933e39e.js
                                                                                                                                              Preview:...........Yio....+..)H4.V^hEO.. !d..@:..v.....[&.....d...Fj.+.[.....Q....DV..y.+...7[.......c....w.. .@}.>...n...GGf5.f.g....Y..v.}.j.Q^......8;RUA.*U...*.r...%.+P...Y-:.+...i..T..^.....jH....jJ.K<.5.d.4].|.k.ra....*.G|..&... .c..k.. .9..a..q..?b$....=Ey.FX*..UV9....U...fY...n.UjY.......A....IQT....Zf...*...P... >.90..`..u...W."...7..P.w........[.B...O.i.....P!o}+..q..|{.......R}....M......T.......K..X.zT.A.."...J../....qd..(.Mj..#bD..U..K..a...ur...dd[x...W......C...<..d./..7..(...C?.Y..P...$..:OQqV..s..(....A.b..D..B........C.%.7.@.1f.K6.H..!.?u......5.......Nt....l...<..<..t..X.5.@p..4M..f...59..U!:..T.DrB..6.rU...t".bm./.e....`......U..D.'2..&..C$e=@R%.q....p-.+#.?u ..@P.....Y:/..2b..Mw.....w......[... R...9d .2..?..A.......B..E$.."..........o)B.u......<......L:.J2..aq-...H..".JC.$.MRHp,..7.H.\r#p..'zX......Y.Ip...r.Z.yi.......I...........[.PdG..=Q.o..=..T*...HF..S...v8.S..".t...$t$..$z<L........}x.R..6&0.......:l..".$^...;..N...tb...2.YC
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:ASCII text, with very long lines (65326)
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):160257
                                                                                                                                              Entropy (8bit):5.076409168990226
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:1536:a5K47WIXUNnNFTpNNN6nNIr+ryEIA1pDEBi8yNcuSEtbADGzIuypq3SYiLENM6Hn:A7feOGq3SYiLENM6HN26R
                                                                                                                                              MD5:9593715F4442D1F9D4E1A79E04481212
                                                                                                                                              SHA1:B480B8701ABF383A48C32C7535E2387A1BF04CF3
                                                                                                                                              SHA-256:1535585D0A5316A2DD4237A2A10D314DD174701C571F244CC0C44528B8B7FB3B
                                                                                                                                              SHA-512:887CC8002AC28D602FC5D2CF6CBBB3C04781B5DF45EFA3320F80461D5058F964A6ADD81D31B6D70C48A10274931B4E37C5ACDA0D4061920A6672ACFBB8A6ECE9
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/css/bootstrap.min.css
                                                                                                                                              Preview:/*!. * Bootstrap v4.5.2 (https://getbootstrap.com/). * Copyright 2011-2020 The Bootstrap Authors. * Copyright 2011-2020 Twitter, Inc.. * Licensed under MIT (https://github.com/twbs/bootstrap/blob/main/LICENSE). */:root{--blue:#007bff;--indigo:#6610f2;--purple:#6f42c1;--pink:#e83e8c;--red:#dc3545;--orange:#fd7e14;--yellow:#ffc107;--green:#27ae60;--teal:#20c997;--cyan:#2770ae;--white:#fff;--gray:#6c757d;--gray-dark:#343a40;--primary:#007bff;--secondary:#6c757d;--success:#27ae60;--info:#2770ae;--warning:#ffc107;--danger:#dc3545;--light:#f8f9fa;--dark:#343a40;--breakpoint-xs:0;--breakpoint-sm:576px;--breakpoint-md:768px;--breakpoint-lg:992px;--breakpoint-xl:1200px;--font-family-sans-serif:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue",Arial,"Noto Sans",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";--font-family-monospace:SFMono-Regular,Menlo,Monaco,Consolas,"Liberation Mono","Courier New",monospace}*,::after,::before{box-sizing:bo
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 3641
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):1682
                                                                                                                                              Entropy (8bit):7.87912149491752
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XXTAti2aBppTAUeU+J3uG8y8ozjXyIstd:nTCiDHpsjXsVrEFsz
                                                                                                                                              MD5:0C21BD181E675ADA9BC8043448CEFA41
                                                                                                                                              SHA1:1656B4100F883151B82321DD73C16A5F92C75785
                                                                                                                                              SHA-256:87519FF603159E3B75D4A7BA6948F350F57F885ED616CF4AE05D8407CFF264EB
                                                                                                                                              SHA-512:F1946DA7A8DAD0937D6B08B23C7C9B6D3A99D4567A1DF47B9A19A0411BC6EC44B45902465CBBC6B9097D5FFEA5D489B0E102E99F2BC975DF96142E59716A62F5
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/1319.42142b3fe051c72c.js
                                                                                                                                              Preview:...........V.R.J...M.I.....k........T.C22Lb2A.....@p..7V.d.}.{..L.!"#...|........l..}{{x..?.]..!.Nj.."...QDm.=*2..XZ.Q..B.`..y.."..X......Z..5..:.R.$..<.eS9I...P1......T.D.-.9{...<R.hdE..[{..|.X.PQ.-.)...(..T..6.... ..%...)2..Y....b2....6...g2...j.Zu..ci....1.V...0U..E..:...dV.=Z"..o.WZ0...f.0)-.}.l.h)=...$...&.....{].F..`... "...H..x...+......kU....NFDd...sZ;..r/...M.....q....R^x.'d..f.`{S.....2W....M.y...N#B..'g).u....tLV.hq..f.aq..2./..j..y.m.m.hc.pk...F=._..y.m..#q.. V.....Q....d..p.E...p..H.......Q|...z.`/.9.z.>..G..h..k@..!X..b.>..X..r.......F..3....V...e.B.u..GGG..yV..w...x.../.y.-uF.."bI>T%...-........'..y..?.......0Ek.....?..3.....n.30...S.0. ...1.%R._..jF.<.....`s.y..&mt.u.y..e#....q.!..N.... ....DB`...+....W...:.@....P....x....g$oC.o.)."t3S6M..||.%.s...T.~..~..g.u.z..r....L.eO~!...N..#..f.JY...G^0S.....r{...4$..k[.@j...b.B.+.W.C..u,....b....Y~.h. t.......@..[>..=.DH..:..|_.B..].zQ`..iGK..wh....s...f......*.Cc....~Ty?..nr.nrW7...$k...}..1.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 8986
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3372
                                                                                                                                              Entropy (8bit):7.9426160616318695
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XLWA5Pr0UD+waGPj5UX8klFR8DCfoYdw/KCGxjd2wnfPzYB6tYj9TefxTIpBSFSW:6A5PNDX9y8ixld2YPzwryCOFSob
                                                                                                                                              MD5:6D5AC579AE896D409924898915A4F18F
                                                                                                                                              SHA1:3BB76E7CC3B5AE05FD81935BEA5650FBBD3F7C88
                                                                                                                                              SHA-256:6FFDD4ED0457095FDBBC8D8EB9DDED23EFE2BD5139BA9243C5BC3F1037F615AF
                                                                                                                                              SHA-512:A2E39830F57F4C9185B255CFCDA6513581BD471B7B787DEED41A2752D6947881B8A9FEE8E0DAE4FDE64E031816D9DB03BA320727B366580F78F59078A50164B1
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2345-caecb810b6387024.js
                                                                                                                                              Preview:............ks.6..V%G+..4iM....q..v...M."A.1E0$(Y...o..$e.I.../......`.g.........FaoI'...............f4.{I.........a}$..0.}.xl......K[...?=8....?=<z........uJE....|...yY..fS...!O-I......K....".E4...v:..w.......R.[...$).\...y..2~..b..(.8.v.m.Q<v9...R@Q..yI..,1c.T..B..\....YL.r...[K..|9.{..so.sq..(..f..rw..$ONx,.....G.%.NgL*.!.$.Q.(../..sttT...^..Ki...@.9..$b.8).P...)_:..e.p...-.%...!....>....4.=.....KQL.>.x.....Ubu.....F.j.>Bv........6....0..P.T....V.+J...)..#z.E.U..#.dZ......A.......o.g.q..?......`.U.....*..a...J.c......R...M{<.3*.W.._...>..p.LX.El$$z.#z.....B...pN..Ne.-.!...............%.f...O`.~....fE...^.^F....t]Dl.....c...:.....j).B...G..mE.._..$.OR.....R5N...mM."...J.v.UW...BY.Yt.@1(...J.Gwe..d.b..Q.@of..I{....cUr..a.=..L.*Y..=......j#...*X.w.J..u..Y.t+.x....f.%l70.G....W&....U;q]W..0.z.......%0...C.2PZ.0w..1..K.._#....pO....5B-o.Z.kz*.*..KI.W........aI.a..xk.?]......s...=..4}.4V&...s5U.Xh.Y...JY......U5.}.i.....%.....y.a=.X.).)...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 16 x 7, 8-bit colormap, non-interlaced
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):359
                                                                                                                                              Entropy (8bit):6.938583941884557
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:6:6v/lhPYtNRSGHSQ9iAlZDpTacESuO3S0NJyJj9bU49O/6TgQnmzVWc1CaE5JHu2K:6v/7gX0WFXxacE/O3SIJLwO/6TgQ2JYg
                                                                                                                                              MD5:9CC0DB7989FB5540D4DF496260A4AF27
                                                                                                                                              SHA1:B1EB6692F4AA7B1889381752EEB23ECEF2301137
                                                                                                                                              SHA-256:ACE5E6D97B8EB8669EB5A97E37DD19B22A49C488462C32401B428D8A7C3723C9
                                                                                                                                              SHA-512:E263116566257073498C22C06873AFCD5F3BD84B223508DD27E28B2E83BD16C843F5BFEE61E8CE065749CB240499FE7C797F2331A20095DCCB50FD77C8387299
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:.PNG........IHDR.............6.=p...{PLTEw..Zk..`_.mq8;XJNm?OfLiq...x{.Vu.._`.....r..q..g.|l..gy~.....Y\p....u.......}.....Vm.Of{CLfeWW....RU{a]...Q^.Xe.]i.es..o.......(tRNS.).B#...... ..qO..m^.D..9....z9][.4....).#R....pHYs................^IDATx...G.. ......l....._...(l.8...-.V.]...).VH1.c&fJ...Tj..@..p...]....T...t...6.....Pk.J.......].f.....IEND.B`.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 119892
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):44080
                                                                                                                                              Entropy (8bit):7.988298233104533
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:Samu/HD07jqcaWHBXPceB7qfJ7Vws7Mf+cJR4cNsEsA3o:5n/ujjqxZwgyJR2
                                                                                                                                              MD5:C74682A448B17CA9C4236127B8EB200B
                                                                                                                                              SHA1:5E9E6954CDB568BC8A4E68065E52F1883C0049C5
                                                                                                                                              SHA-256:6C10D4D0895CFE2D759790ADA9625732ACDDCA7B01519D4C6EDAEB71BF648925
                                                                                                                                              SHA-512:1D4CD82E782336BCCF3E883F6B2BA339269F5641F16FF0D2A3EACB35015A597D5A2FA1879F030E89ACF8C11089B2210893E0F07B87272226480878760EC1CD8B
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/font/DINPro.ttf
                                                                                                                                              Preview:............|[.0~g.lY...vY.lk..}M...8...$@.^.@)m..R.........R..M[(.BY.K.>.........J....;3.^m..-}..o..+.;s..g....1..d...w.....#|s......v._.c...0..O:.8.:...#..A..:a....^.C.....o?....I....p.8..3w..w...|.Q.v.....52........:.v.U0.W[.~.)[O.....&..*..:..3.D.~.....aL_ad8.......0.aLxG..$.3....a.0.72..-C......K...a.I..d..`_a...7.....q..x.......0.{p.....=..Z...T...+.;.Jt.=...&..g...k..~.....{9.#.....cd.dg..]+.......d...."{K....v..}....:o...{.^.7.m.vz...y..^..{.g.|\.;........Z....}n_..m...=.|.3.ONN.Q.`47R.~.~.>@.b+..>.(~.`..`.6.c....+...kd{d{ew..R.^....#.....o....l.....z)l...3._-.m...]...6..V.m;..Q....L.5....'.3y.........I..c~....w'.c./.oM..xs.g.wM....%..O|u..3'N.8vb...e..o.....V..9.u(}(y(q..P.P.....|......y..o..9.f.M.....7...%o\...8.3.8...o,y#.F....).5lN.......)..O............Z....F..b...N....|.@0..D.cM...D2.n.d;:..{z.......-..-.../].|..U..._.~..MG....-[g...m.w.w..;.p.I'.r.i...3.:..]....|.W..../...|.~....w...]y.......v....~x..7.h.o.w.-..v.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 4529
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):4398
                                                                                                                                              Entropy (8bit):7.960381304864253
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:E3aJQ3slCBZWkH8dziYDPSmRa18s33B9hRJstV13LYSi1+tTF7N8iUbyw:E32Q8lCBZ1YDPSOa1t33tR+tXLYWbNql
                                                                                                                                              MD5:521CB456512023509E8F5AA6EB26C2F5
                                                                                                                                              SHA1:DA33B0A6797E95F10A9EAF6593A9C2D02F544338
                                                                                                                                              SHA-256:D18140637F8D75B07C927F9708704609BD339F646BD138449E6F898CA8585459
                                                                                                                                              SHA-512:DBEF159AE4BF8375F2A24FC4CEF412B57C1CAC243BD693CE8AE38EC9AE5365008BF931AB82478D842E5DC0C0FB27730BB8AECEA08FD834133602457CB3720C74
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........Uy8...1.,e.Bd-.L..&.Q..=.B...De.!.^hd_..:#."./..=.....{........\.u.s.s?.y....:qV.&G...@..(S.+ ...._.@....S...^.. PM2..u(0..^1A.*{.....5..}..r.......b.a......*..2".A.L.....@..B..\XlI_<......;....i..G........L.....X..R....0.S..h{<.Aao,.=lQ(6....`a....[.MC.Q(....%4.2`..%...a....j...*..[<.g..&(..`0@.j.....*.Ts#< M..|n.k.Z..3......Y....].z5.....:.%U....-\.;..Z.#.F....t.g......+.{v...j.]O4...X.X...i.....[.X..eU.... ..b%.ni...H....y..P....t..*../)..r#..q.SS.n.n...n..u.d....}O....pI8.....<.....\.~f.....j..... .W4...:l.....0yc..........!>..H.d._...:..z.......l<.C....1,....[.."mF`....H.....9:<.`M.8.8..*...!.8.x..%...EA@|..;.....v......H/.yX...eI2.MD.... .;.T..}.}....IgSy.^..|.....u.~.:9..Y......D.Ce].6u......".,m...ZU}&.....&=....^..`..F..b.t.,.!..o..f.yI.....C\..KV..S\d.L...).7J.9...%......!<..x..?T.)..K.C.Lo;..\."JAD)....%....3......3....;#.=N`..M..d..V'8.....W.g.5.[;X.|."..e...m*.O..0>.9......D..../zn.....l.H.e..=...WB<y8..........
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 309 x 497, 8-bit colormap, non-interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):27838
                                                                                                                                              Entropy (8bit):7.978845809426652
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:768:ENQIj52VS0YMGzCHsbOorT9S3hnQ05bm/hCGCkiZXQ7yHAydwp0C:0j5uYrzmsbOorTknQ0xkCGLNOc9
                                                                                                                                              MD5:48F648A53CD03787CAB32621F6088895
                                                                                                                                              SHA1:408FAC6305133287FDF50315D8212E07F4A0C89C
                                                                                                                                              SHA-256:FA5C757347298A9B2CD0B3823D37D4C1C5A2C75520207F37B61AD9873DF50557
                                                                                                                                              SHA-512:4BFEC883A611D6311350F2266BB168BF8D99B81CE2067A36CFF81447FC684BDB23B1FE5929B767266DF49CD98F8DE314223FB1CD9FE3A5F09C5709A5C3BB6675
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://1k4ej4j1lxvjwz.com/imgs/2025shiyunhui.png
                                                                                                                                              Preview:.PNG........IHDR...5.........;......PLTE......3*)...5,,60/...+$#.1d.X.$.....|Q.....Ay.8j!...<p.*'......hA.wI.M..c..W..].pE.\ZY<..D..:55.+].#V...5..`....=.....Jn.....iE.tpo`....P........p.....OX._..z.9..2.+]u..(.......:.....@<;..*..5...b..GDCg..b....Tc.TRQ`x.q.1e...E.....HXj.mihNLKh.$l..f.j.\q....m.(..=..-pM....h...;k..@...d`_.Bv..D...{xwc...J...dB....U^.s.............\F.t..gdc...w....W..b..g........ZZ....~b....aR.....}}..Q.9o..;...QV....rm....S....C.o.sh...I....X\..J.....;s..S...s_......Ss|.Q..?.P..i.._.3.#B3..LQ..Nu..J..l.]dm..,dG..`..N.......}..7..~@.l..u=.p...f..5|Z. ..........j..._.2y..s..s\....w.....%Vd.J......_.....Kc...UA...t....{.....U..............y.e.C{....\.-w.Mq.w.A.K..i.IDATx...K\W....k....D7.h.CqB..0...)..VW2:.e.E:$....6i....$.E..."..H.D.Y.EP...s.=..;.=gLh......{g.m.....oT%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D....i...................W..|O..^.[.n....h.....s....z.z.....{..w....~..o.'.;;o..|.....>...>{.,.>.B...V.m.[...*x.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 43271
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):13981
                                                                                                                                              Entropy (8bit):7.9838149273182415
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:3LZWPccRLPrTvZcN3uhKNdCjaIW2ZObe05+Lqp3o4zyKB7XsZRYzV+vMe8mINnMF:1uAlNeEL1o6y4QZRYAvM9mIYb
                                                                                                                                              MD5:012DDE79CD578B75D02C42E828EB9D28
                                                                                                                                              SHA1:968ABBAEA50F0A7F7FD388C6EA9086697EF33724
                                                                                                                                              SHA-256:615BD8FD9C61B45C07EEC4FCDBADBCD5BE28BB7573AF5BAF01FEF677521150F9
                                                                                                                                              SHA-512:AC66776CE72347651FDA257DFC60327089488C1295352E7D8F711A1057B8EB94F6A8F4DAF71877A7137224B732A8D29BE49D86C79B37BC8FDA9DE1EB47356E78
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/3040.4e697a2663eb2590.js
                                                                                                                                              Preview:...........}.s.8.._.y.^.d..d.*....;..l.....nQ.d1.H....K....OR..L....U%..G.h4.....<..o.`....'....o.}.5.....A{6/'..........v.<....l(.<...,..y.7JQ$C....b#....OO...,....O!.C.....+0.I.....|..>y.....^<y.<`C..i..dH!..i.9.GQ...4`3.{.t.I..X...O/.6..y..!.GH."c....?.....?B...Bp.mN..eo..>u`#.6D.n...E{V.".w3....}..x!...8M.B.lm.v....../;[[~r._D....d.g.4....k..(B..xCUs.....t...l\.u.mq.P^_...e.Nyv)&.lg'p.u.]P.V:5SP^...|.x.r.5,%{.!......y.m$K6.|....A.{...y...q<O........ .s...C..k.'L.d.A......`^L.z..c..$%P..H7.cD..G|.C.d|..l...q.dY.]VjV... ..X...z..[..l.....P.!.@..y.... o^$.I.......j...........+...&b3B.X.>b...SB..*...\`..]dID......0-a&..()8............0...m<.0...W...l.d...l....H....c.q.rv...%;..<.......~......t..]..6.....L...c...F#....s....#C......<....V9."T..3.....%.t.pN. ...@.I~...V@.......H.f..z.....;..1..w.OS'N2.V.......@t....a.._.)..L..(.....a....=a7.33"....e.S$."..8.....Q.}.)N......1.Bu......}..Nq....q..E....`......^x.\x...,.B....JWh8=..+ .J....@^....J.K
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 8240
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3077
                                                                                                                                              Entropy (8bit):7.9211573097963095
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:48:XE5t2XhdU46w5KIGhirbcuV/gMAH0VW1w/iySYBO7OlIoWQ:Q2XhdUIQI+ijAUVh/iySY0KlIoWQ
                                                                                                                                              MD5:A7EBFCA550D2459EE30246AB4B29F937
                                                                                                                                              SHA1:92F187B3D6B1F51E32006D316B9599713649E5D2
                                                                                                                                              SHA-256:3EA5A7F85B9C1B27AF8106C6442D4BF37D9B9502E4CAF74673A26C9CDE3768F2
                                                                                                                                              SHA-512:0E1961C31B69F7DC302F2BD62F40E9F1EE72C56D4A33269B6D3E4C67E6A9B87B0AC31A806A4CE824E864CC998BCE80C11A99B9B65DB7CD1917BE72C09DCF7A0C
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2403.5d522c23634298da.js
                                                                                                                                              Preview:...........Yms....*./2.....8...dn:.....E|n...I.x..........Nr.....v......$..|...e.>..r...n..9.VE.4g3.gw.t.....i .,59.4%...y+."..1y.EK.....q.L.,.e+c8.....#....c".;.d.2..$)3m*,`..G.$.x.1.\."mI...B..J.....V.l?P..'......u.?.#....r.C..J...:.`..4... g.Ul.=....Z..$.u.n.s.R+4%....M.......=...Z.ao.2..P..}..Bo..q..Ao.R+5.Bc$w.}...g.G=..Q...._e...L.$!t.r.Vd/q...YN_..u..!....&...e..$..$m.i...EV"..|[qk..7.....oV.'.p.`kp.4.7.).....9.. .8R2.1~~nT+..1.E.r......}{^dI....d..&'..BX.O..r...!.,.+.>ljUr.k~...\....[C*..h....J.;.8.L0`..W.$.j.$.......V.(~.Jr..[a,.bH.........;...p.%..{.6.........4.....vi(.R...A...C.....[+/V.LH4..g.$.be.d..A9..C.U.>.W..y......~-.$. ............5.._.a.$.."0 ....4.....5.=.]mv....l..R.g.z...WK?}.{{....t@.83....d.}..e.@....%.S9.BV....`..^p...n.f....H.,y..CX..O..,t...8G.......u[+......a....4..Y...~k.jb.R.r......)....@.K.J.EU..%...P.....@..>.y....?..F./xb.M...#U..].,.9C?.....n.Y..../|?.>w..*.uG.N......;.M..A_.....9..N..A...pv.b..i...t
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 3879
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):1610
                                                                                                                                              Entropy (8bit):7.86917313297099
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:24:X1yC3SeOiyCMeTFHdPELeBgZpuU4uyLaMxQnsNqFchS5iETyqkMz2g2d6e/:X1PyReTF9MnwuyLaVsI7sEfc6e/
                                                                                                                                              MD5:CFB8D980EF554A79319C383A3CDFEEDE
                                                                                                                                              SHA1:B911E62488FC54FC8BC2F50207FF34B9D8374521
                                                                                                                                              SHA-256:6D406373B40ED0BB757D304751E2DB28DE3D2F2916CCC0CC6E5581A35BDCC818
                                                                                                                                              SHA-512:595737E8ED2E054199B47A99C83D469D45FF390508C9436D5D57856C5536A20E65446DEF3D279DFE4B2B258280E5CE99E944C1CA933C082EF9C11DABD54EBE08
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:http://www.car1997.cn/
                                                                                                                                              Preview:...........W]o.V.......DS...6-i.WZ%$...4.]LStl..n....M...M|...Xi.6._.11...(./#......s.8I),L.\.8vr......7..4[%..s:).3..6..T.p...r.O..?<qT.E>[6,.....].v.o.....)...w-..>.r..91B.0A..JX...[B$.a.....E.Ed.`.;:..=.K.0...\.yp..8..\..z....^.......n.^n.n...........'.Z.}.z.x}....~..^Z......G.....7w.....np.>.7..5..._.....`...\s....Jp..h....../~..~[..Z.......6l...8.....>l...[......3..S..v~...t.Z.7.g/5.....y.vn.....l4.4k.........rc{.q..h.(..ZZ.......+..w_/}.s..b....~9...k...G?4.,..m.k.....W...p.Po..q.l...S...n.X.a.....-.Z..E..q..(...8..P.5Hq?...L...m.v..<W..C......R.ve.R...Iv;...G..5.15.....PN.Y.+.V..Yh..H..K".(Z..=......k...Tm.v.....!..v....):.t...D....e......E.8...=.r`...U!..d.../.o..bD.....p...lw...]...).F.e.*..#8.O....L..|.}......g...N....p..-.[.#@u.=.qZ..UA.<.{..j.D..=_).Dt|O...h..!.6=.vH@dfU.Y.]..dh>....f..MT..(K.l..*..!N...zb......c.....Kf1.5N(.(....I..Jp....?Cc.Q..4DP./.pG....3..Gi^.D7...C.X.y.l..\....lx. .....b"k>...1,.'.AC.h..M74....2} .'G.....
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 260299
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):260056
                                                                                                                                              Entropy (8bit):7.995244741506475
                                                                                                                                              Encrypted:true
                                                                                                                                              SSDEEP:6144:q8/Gsc6qxwasPcyWKQgd95KspiQz5NhCV25OBINUT:q8/GscJP2KsV3Qyg
                                                                                                                                              MD5:DDAD6E6EF3D3254F516A38BA3EF7D5FC
                                                                                                                                              SHA1:F916D45CF1FAEBF62003FFBA0E68741689906FA1
                                                                                                                                              SHA-256:855DA4E2CEF2EE598784E09ABC738F119BB31D6CE0661CFE1EFDEE099F57D1A4
                                                                                                                                              SHA-512:7B97AB45B729B7D605389717FBD1722A0B957CEBABCF49C8966CEEE66A0F315941BBB2456E56F557862231A20E5F4932F9E8AFF50BF6F6E072F263A65E52D18E
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/images/fangwen-9db6e4fa648a77dfca2d3b5abb1063f9.png
                                                                                                                                              Preview:...........O@...PNG........IHDR.............`B[<....PLTE...................;h....&]./i...................(X{9v..D.......P..s..t..D...........Sz..........B..3q................?..B}.........P..Fy.3o.............]..;q....`.....t.....N....[...............1e....>o....Ly.]..m...D....l..#Z.{..y...P.U...>~...(f....RSSp...I..W......R..w.....~.............z.....T..\..b........e.....................F........C..........................:{.K..8u.@..6p.B.....>...........F..L........N.....>z...*k..X..F.&g..R......)h..B..Q.^...S.F.....|.....$d.....T....0n....S{....$b.I...Z..H.1t..F....Q.. \.)e./Q.M.....I.%`.H...S."Y.;..-p...$J.D...*O.0k.8y.*`.=..I..7z.C..Lx....-i....#^.......2f..]....C..:X.;z....<..<s.V../r.H..4t....>..4x..O.qw.w}.'i.By....Ca.1l..a.Ik.Ov.5Y.:n..Z.0W.k..gm.CHZM..5{...#i.[..(q.PUg=b.\bt........27H.?.....otRNS.......9eQb&. ...Bq.47.')|eJd1d.A.WU.Y@Pi.B:.t.G+ce.....JNS.Wa.Q.......................Z.................vN......IDATx..;..0..#@Pn.a.&...`.",./.."...X..t.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 21486
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):6228
                                                                                                                                              Entropy (8bit):7.958546621279086
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:BtdtdlsNMhLjKQUKjQzc7crf1yKBWE8DXjwl1iugknjqCBguqV21YqMLo+:BzflsNMh8Fc74/B38zjo1Skh+01r+
                                                                                                                                              MD5:6E465E66D407E841BDFF8DF225FD02B4
                                                                                                                                              SHA1:C535913DDBDF5405790E7044719BE7DB2E60DE26
                                                                                                                                              SHA-256:790E14DBD93F8EA4FA7DC0E35AA4AAD4FEB23737BB074C082F1136E8C7037EA4
                                                                                                                                              SHA-512:0C969F1273E1A24182C24BCFF1C9219403EE171A6546476BA6EE24F864052161FD45D3073AAA293590D9B44E16C02455FCCD5F67C7BE28463A70B7323D28C5FA
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........\i..../.........~.EI.Z..2}.V..#........B.}_a...4 mH1..it....|/+kzZ..~..//.z..............M..._.].b..[u..t...]...uw..vo.7.......w.u/.......y...........W.y.........v..~....K..........G.?.u=..].}.Q..n.w..R....].m...n...........}...........^...{.w...7}...^...qG......w.~..S....vG_......X..{...~{.....w.B.O...\}r..........vu..m|C....~.......c...'V.7..g?........_...~C._.....M'.O.y...Xmb[]<r....s.~...q.N1.`B~.]=...4r....._c..a....t..1.c.......=,.|}...n1I=.Y._..#.I..!9....g.....F.M.....|I._e/..Y9.......>.7..1)H.(M(..h.....n.[.....eT..bZ.s...-...>P..&?...H.V..O..*n..........9l...3z...*r1..T.K..l.. .2..X.45N.............{g....1...d*j...V.-....`T>S.%)k....F5..Jv.%..)..0].D{.../Wuq@...j...2.*.)......$+UEa....N@.M..%.S. ..6.L.Wk/.6..l.6...!';......n.?9k..pQ?...U..;b.E.s..G[L.NE...E..v.....~.P.!......yk.cFH.rHFU.%..n......x\5..J....[...h...N....W.....n....97..h....._. ...q..,&S.<z_.F...c..&......).z...X.'..."H...0..;.._mo....F.t..S
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 12208
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):6000
                                                                                                                                              Entropy (8bit):7.96030233272535
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:RIVQPImjzL/1DhENmdzGZSTG1C7wOapnFWIahrLkdoS+hwghTXTqn9XQm:CmfTj9onIwNpnFWIahLkCS+hjRqn
                                                                                                                                              MD5:F0D12A5DF82DF20E13BBBB46C50A5D18
                                                                                                                                              SHA1:FCCF4DF54841B6CF59B9579CCD813AB0F7D67A52
                                                                                                                                              SHA-256:BAB5FFC44F3323A4C9307B72D6CB18411270CA98F28E0461D3F855871AA0529F
                                                                                                                                              SHA-512:F26D9684B430D6DDA542E9DB1A237E44A35B930A83099B69FBE870D933F23895C2195A447248FEEA4BF424AB5F01BEDA06300833F95AA7D1B8C9F0A3D7C30FD8
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/webpack-c1a65d9dfffc0df5.js
                                                                                                                                              Preview:...........Zko#Wr.+.F .3-....{...E..z.x...(.}..+....x 1.=..I.3......x.u.q.T.~S.WiX.W...y..v.,..\..6..?.?..Q.4....6..^_.....2.....M..7..(.>.7.v\%.#..e....:./..n?..i..V..v9l>>..\.pw7.5..~N-..\a....Y.we(3.c..?/.m....]Z...K...............lU>.~.l.y..6)..V..0.e....r.......i.wd..u&.]]_....CW.......fo.U.a..{-{v...,....p{.|..}.}.Z^_..n.>...O...8..t...o.....L...g..y..>.gg........v...E..l>../..io:.|U...js.......>.-S.o..;.^.#..0.|..[...>...8nt.....t..5..~...n...CI.r.e.j.?..3....y../.nK..'....j...n7o.U.| Z0...,nn../..xW.;..^........8.....0.^|..a.v.K.#O.f~_.........0....H.r.........!...C..c@.....p.."=....b%.4.q.G.b.u...:.U4..Y.....a.....mY...M..?X.0......y..bEPR...|E.ua.D._]........|U}.q<;{.e.<,.....}.?.Q.}X...e3|.).-~]`..C..4.W...K.W.w....W..95.` .s.j....|..]@*..U.......y..>...^..t...o.SY=.M.w....].X7.P%.I.....r......P...Gd.....@.b.Q......w{<....#..w.v..2}.n.W..~C.s.t....N.......A.s.T.(...!.q.c..A...F[..S..q.......s...UIS.*U.q.7.......Y
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 16437
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):6192
                                                                                                                                              Entropy (8bit):7.965968203050715
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:wXWEs2ElclIbJAA4nDOn5zMxZCzUeYUmOwe+DMLA0WLEwkLAixUomV0I7JYqPwNh:wm2DK/4C5zKom5e+DVL4VcNdI00D
                                                                                                                                              MD5:6F74666FC7BD9F0A0C8DDDBC1ED23EEE
                                                                                                                                              SHA1:F3A11F86B028D7F1F72B03FC82232D1FCDB95F1D
                                                                                                                                              SHA-256:D2A095DE97A38683498F5FCE5F4003A7DD54E3342404C149A77AFC4D2F35418D
                                                                                                                                              SHA-512:AC8DC841E37060AFF6C724120E4C536B665FB37C27FC4178903792EBF2541AC66F882197126D6B24456FBDC5BD8C110700E5D812E34546DCE7171492F626AE75
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2097-6fdf153c7f7de5a7.js
                                                                                                                                              Preview:...........[.s...W...Ia..N.FXer!..7u.+.u.J32Z.Z!q...5.....C.....X.......9.....]...,...O.?..[[....q.E.......3.......H."J.[0....*r..E..5...N.'...;,..7.3..h.xyFm9......Pzu..e....$.........>.N.E.%....~d;.p.. ....vz.@p7I.lg...........}[..;.....c..7.{.. ..{....3,.e....4y..^...v..cs.....W|.:.mcE.eEIG.0"p..96wNN...Qu.....(....aS.k...r..`.na...aK.....9C3..b..B..(.....b.X.m..F..e.O.<=...u...hL.....'''.<.AV...K.8F....;/..'..n.Ph..-w.A..K..9,3.....C.t..9`..G.....1.6.w......4.........(-.....t|w......|...?w...^9...:Ax...8j..|.!;...X....f8....//.,....=~.F9..t.sJ.Qb2..A.w".Y1.8..(.Q...m>.5-.i.....Lv.U$..-0\KN']t..9.(.f......F.@.......$.....3]M.4.u.6x,.C4L.66T>8...!1.\..;.1...D..>.r...2..wn..9.vk.e...ae..).X..@..?..L.~....OH-.}..K|.I..V..,(E..S."n...-bj.Z...[.........U......._E.A.,.....eA]`<....O.$..9..k..O.......Ng#*.......>U...{.f.no.^.....uF.l..1....1.u...w.z..^..XN...N...l_oW....G..L&.w...L.(j.'.#.H-`M...OW....<..o<LT.f..@....>...'L..:..m}..&.....$@$...L...l...z.
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 62
                                                                                                                                              Category:dropped
                                                                                                                                              Size (bytes):73
                                                                                                                                              Entropy (8bit):5.309840573160466
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:3:FttXz2nXoqJLoWPxpiBlzfyol:XtjQX3JcIvozfv
                                                                                                                                              MD5:CEEF627246D219343480EED9FD7847F8
                                                                                                                                              SHA1:FCA9F6E3299052A0A0EFBD4CF7BE14ABA82F3D9E
                                                                                                                                              SHA-256:796F6DAB94C4BDC13014272796103C4753A30CD6A952C58DE5E9B9728A68630C
                                                                                                                                              SHA-512:8BDE7E6BB3F9D4F15794A66E4E32B65BD58253D046E77567F15186FC09A994C2A96F9A4348355E9848E26D02C4208B76C21B41EE7ABF344D43EA506BF8E23703
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              Preview:...........V.K.MU.R...IM..I-r-*./R.Q.M-.NL.I.......(.Be..S.........w>...
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:PNG image data, 94 x 460, 8-bit/color RGBA, interlaced
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):3739
                                                                                                                                              Entropy (8bit):7.867573472184825
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:96:A2DtQv1cWr0WqZkbDa2DrPJ7bLGXSsM79:ZQyxybO6FbL1b5
                                                                                                                                              MD5:675956B127CBF832C7F6D5FC3E56F582
                                                                                                                                              SHA1:D15660DD65EF51DB67261274A648C85CD7310587
                                                                                                                                              SHA-256:C36A9A069A110422A422B99252F6081223665128438EB597D6E0EFBC8E6A6D96
                                                                                                                                              SHA-512:6BA7B93D4AD20C69D69687E853E0AF03FFC00E322249B7AC2DC7F0B290949084F4DB24E18AC894C0E5A804683064C61DA69E116852BE76FBD67C42DC75A257DC
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.tvwxbvay.com/chat/chatClient/refactor/v6.0.1/dist/images/6_icon_common@2x-675956b127.png
                                                                                                                                              Preview:.PNG........IHDR...^.........+./....bIDATx..}..e....*H.J..Fj0b.h.S......m)..5-..D.?..k..!.&.c....E.."...*-...D..&..)...r...w....f....u......L.......w?3..3...D.V.Z.....aQN>.-0[..%t.z0[`....=.- ~![...K/......8......('....-d.z.......yWZ....m..|...[`v..M7v.J@....% w......@...G-.4...[.,0....=f.x.j..q{j...F..#s.Sw^.!..>>.y...U..\....y...zhs....m..K....W.1+.-=.Z.Nns.:.......T.gl...g......z.........;..^..w..,.-...X@...(...V. ~..oe..KY@,lE,.......r...c E...d3.....".f...-z.{?h..>h5>h....94F[dv.em..[... .9(m.."...{.|..Z@.}T......q.R.....g."a..`{..an.[5u............,`z|Q....[_.#K.....[^...._V$B_...{u.%.(..G..W2.S9....xO...AS.O(...*.....v..LV.$.7.'=.@C...U...H'.`Z.=...........e.f....K..........+..Yy...n+2..M.o".mz.R..F..Mfk......f.W......?..-.'+/].[..<...*......m..........?....SSS..p..7.O..X..Rycg....mF*o..=.>.3.Y..*/s Y..."...|k..Pkl.]......bc..,...Q.....?..Ry.....".G..b(....O.~...L.]..-~....k'I.3......Z....E.^......F[.#,G..VG[...9r...9....N
                                                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                              File Type:gzip compressed data, from Unix, original size modulo 2^32 23316
                                                                                                                                              Category:downloaded
                                                                                                                                              Size (bytes):7909
                                                                                                                                              Entropy (8bit):7.971188089220646
                                                                                                                                              Encrypted:false
                                                                                                                                              SSDEEP:192:5hmzeOzyonqV3xd/vdeb33V2iWbIsUzdbBTH3DtyXrcSVtt6MtNDKasDEBAE:jwed3nHxxbIskXb3gXtXoaDKDs/
                                                                                                                                              MD5:0A7316833EDFB1C50F543A68E59FE14C
                                                                                                                                              SHA1:FD798D111E166E6A6E196122F5D66F267C6EF0CB
                                                                                                                                              SHA-256:91C56B1C07DA500E620397F03ECDC70FD0C3B121C1DF835D142B803202C712DB
                                                                                                                                              SHA-512:A9B25C0EA94DE670B3A0E2493370CD361820AF6DBC6DAB039483379468FA65BAF2F57DD9053AC2F4DAA760263F480559DEFF7C783C3E4781989A75614D4AD46F
                                                                                                                                              Malicious:false
                                                                                                                                              Reputation:low
                                                                                                                                              URL:https://www.zl5de9.vip:8443/_next/static/chunks/2963-f5c3a7c6ce32f6f0.js
                                                                                                                                              Preview:...........<.r.F..B..-..a..(.4.sd..Z.rYre+.O..C.1.a...!...=/.HPR|[Wu[q..<.{z.5...M..=......".z..."..].n..?_.S..s.=$....,..'..`..F<a...%..t..m.<OF..e~.R.....-s..y.H.k.w..<...I...#..'................70.g.IJ......z..-...<.{=97...H>...\......H....{{...|A...U-Q.s.....=.....59=...;...(.Lb./F..0.O../..b.'s...3z....&:Kx.H,..].m...7..y.H.....+.ML....f...s...G.<...b.y1...W.].=......7E\Xa.....1t b...................^O.Z..,H.<b*`?..=....F...?p'..?3....+.qj.eV...,.cI.h.aH.{<.j..Z..\..?R...Y.=Os2s%...c.z...d.k2MH..v...2.OO...y8....@.}.=i{$..........j.v=2.b.....#..t.P<;j.Bq.f~...c..Q..#1.:.yd&a