Loading ...

Play interactive tourEdit tour

Analysis Report http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH

Overview

General Information

Sample URL:http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH
Analysis ID:347016

Most interesting Screenshot:

Detection

Phisher
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Yara detected Phisher
HTML body contains low number of good links
HTML title does not match URL
None HTTPS page querying sensitive user data (password, username or email)

Classification

Startup

  • System is w10x64
  • iexplore.exe (PID: 6164 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596)
    • iexplore.exe (PID: 6004 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6164 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Dropped Files

SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\rpmlvonsnj[1].htmJoeSecurity_Phisher_1Yara detected PhisherJoe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Antivirus detection for URL or domainShow sources
    Source: http://heygamersnort.at/index/it/disclaimer.htmlSlashNext: Label: Internet Scam type: Phishing & Social Engineering
    Source: http://heygamersnort.at/index/it/abuse_report.htmlSlashNext: Label: Internet Scam type: Phishing & Social Engineering
    Source: http://heygamersnort.at/index/it/privacy.htmlSlashNext: Label: Internet Scam type: Phishing & Social Engineering
    Source: http://heygamersnort.at/index/it/SlashNext: Label: Internet Scam type: Phishing & Social Engineering
    Source: http://heygamersnort.at/index/it/terms.htmlSlashNext: Label: Internet Scam type: Phishing & Social Engineering
    Multi AV Scanner detection for domain / URLShow sources
    Source: heygamersnort.atVirustotal: Detection: 9%Perma Link

    Phishing:

    barindex
    Yara detected PhisherShow sources
    Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\rpmlvonsnj[1].htm, type: DROPPED
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: Number of links: 0
    Source: http://heygamersnort.at/index/it/HTTP Parser: Number of links: 0
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: Number of links: 0
    Source: http://heygamersnort.at/index/it/HTTP Parser: Number of links: 0
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: Title: Report Abuse/Spam does not match URL
    Source: http://heygamersnort.at/index/it/HTTP Parser: Title: 1K Daily Profit - Il Sito Ufficiale does not match URL
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: Title: Report Abuse/Spam does not match URL
    Source: http://heygamersnort.at/index/it/HTTP Parser: Title: 1K Daily Profit - Il Sito Ufficiale does not match URL
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: Has password / email / username input fields
    Source: http://heygamersnort.at/index/it/HTTP Parser: Has password / email / username input fields
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: Has password / email / username input fields
    Source: http://heygamersnort.at/index/it/HTTP Parser: Has password / email / username input fields
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: No <meta name="author".. found
    Source: http://heygamersnort.at/index/it/HTTP Parser: No <meta name="author".. found
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: No <meta name="author".. found
    Source: http://heygamersnort.at/index/it/HTTP Parser: No <meta name="author".. found
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: No <meta name="copyright".. found
    Source: http://heygamersnort.at/index/it/HTTP Parser: No <meta name="copyright".. found
    Source: http://heygamersnort.at/index/it/abuse_report.htmlHTTP Parser: No <meta name="copyright".. found
    Source: http://heygamersnort.at/index/it/HTTP Parser: No <meta name="copyright".. found

    Compliance:

    barindex
    Uses new MSVCR DllsShow sources
    Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dllJump to behavior
    Source: global trafficHTTP traffic detected: GET /rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: drtjsmith.comConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: drtjsmith.comConnection: Keep-AliveCookie: __cfduid=d5982d039f35453521d6f625db3a829831612214902
    Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-Alive
    Source: global trafficHTTP traffic detected: GET /index/it HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/ HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/volume.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/safe.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/facebook-it.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/john.jpg HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/john-sign.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/bootstrap.min.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/font-awesome.min.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/styleCustom.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/reset.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/css_1.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/css.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/style.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/css_2.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/css/cust_video.css HTTP/1.1Accept: text/css, */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/jquery.min.js HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/preloader.gif HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/commonJs.js?v=19 HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/bootstrap.min.js HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/device.min.js HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/getdetector.js HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/scripts.js HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/js/currency.js?v=1 HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/twitter-it.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/safe2.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYNNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoadNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYdNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobtNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYtNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoY9NfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobdNf.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAgM7UvI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLCwM7UvI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAwM7UvI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLDAM7UvI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAAM7UvI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAQM7UvI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLDwM7.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYNNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoadNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYdNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobtNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYtNfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoY9NfQyQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCkYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobdNf.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCAYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCgYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCcYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCsYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCoYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCQYaQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19-7Cxs5.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19a7Cxs5.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1967Cxs5.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19G7Cxs5.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1927Cxs5.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19y7Cxs5.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19K7Cw.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCkYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCAYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCgYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCcYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCsYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCoYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc3CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCQYaQ.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc-CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCsYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCoYactd.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc5CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc2CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc1CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc0CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc6CsI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic3CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic-CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic2CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic5CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic1CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic0CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic6CsI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc3CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc-CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc2CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc5CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc1CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc0CsLKlA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc6CsI.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fCRc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fABc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fCBc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fBxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fCxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fChc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmSU5fBBc-.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu72xMOzY.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu5mxMOzY.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu7mxMOzY.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu4WxMOzY.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu7WxMOzY.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu7GxMOzY.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOmCnqEu92Fr1Mu4mxM.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fCRc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fABc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fCBc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fBxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fCxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fChc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmEU9fBBc-.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfCRc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfABc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfCBc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfBxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfCxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfBxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfBBc-.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmWUlfChc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfCRc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfABc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfCBc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfBxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfBBc-.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/bg-pattern2.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/Digital-7.eot HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfCxc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/fonts/KFOlCnqEu92Fr1MmYUtfChc-EsA.woff HTTP/1.1Accept: */*Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoOrigin: http://heygamersnort.atAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/close-button.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/money-bg.jpg HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/logo.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/check-button-bg.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/check-icon.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/spots-arrow.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/feature1.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/feature2.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/feature3.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/feature4.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/button-left-arrow.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/button-go-arrows.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/top-arrow.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/bg-arrow.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/faq-list-title-bg.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/social-callback-title.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/features-title.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/faq-title.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /geo HTTP/1.1Accept: application/json, text/javascript, */*; q=0.01X-Requested-With: XMLHttpRequestReferer: http://heygamersnort.at/index/it/Accept-Language: en-USAccept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/red-clock-icon.png HTTP/1.1Accept: image/png, image/svg+xml, image/jxr, image/*;q=0.8, */*;q=0.5Referer: http://heygamersnort.at/index/it/Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/images/favicon-32x32.png HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/terms.html HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/favicon.ico HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/privacy.html HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/disclaimer.html HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: global trafficHTTP traffic detected: GET /index/it/abuse_report.html HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: heygamersnort.atConnection: Keep-AliveCookie: userID=87e3d563afd9a38eecbb89364334afbd; guestID=98c7be3646973099b4dd692c201f3975
    Source: unknownDNS traffic detected: queries for: drtjsmith.com
    Source: reset[1].css.2.drString found in binary or memory: http://developer.yahoo.net/yui/license.txt
    Source: imagestore.dat.2.drString found in binary or memory: http://drtjsmith.com/favicon.ico
    Source: ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drString found in binary or memory: http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHRoot
    Source: font-awesome.min[1].css.2.drString found in binary or memory: http://fontawesome.io
    Source: font-awesome.min[1].css.2.drString found in binary or memory: http://fontawesome.io/license
    Source: bootstrap.min[1].js.2.drString found in binary or memory: http://getbootstrap.com)
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drString found in binary or memory: http://heygamersnort.a
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drString found in binary or memory: http://heygamersnort.apmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHt/index/i
    Source: rpmlvonsnj[1].htm.2.drString found in binary or memory: http://heygamersnort.at/
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drString found in binary or memory: http://heygamersnort.at/index/it/
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drString found in binary or memory: http://heygamersnort.at/index/it/F1K
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.dr, ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://heygamersnort.at/index/it/abuse_report.html
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.dr, ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://heygamersnort.at/index/it/disclaimer.html
    Source: imagestore.dat.2.drString found in binary or memory: http://heygamersnort.at/index/it/favicon.ico
    Source: imagestore.dat.2.drString found in binary or memory: http://heygamersnort.at/index/it/favicon.ico~
    Source: imagestore.dat.2.drString found in binary or memory: http://heygamersnort.at/index/it/images/favicon-32x32.png
    Source: ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://heygamersnort.at/index/it/ml?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHd
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drString found in binary or memory: http://heygamersnort.at/index/it/ml?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHt/index/it
    Source: ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://heygamersnort.at/index/it/privacy.html
    Source: {678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.dr, ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://heygamersnort.at/index/it/terms.html
    Source: ~DFF40159CB9872391F.TMP.1.drString found in binary or memory: http://heygamersnort.at/index/it/terms.htmlEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH
    Source: Digital-7[1].eot.2.drString found in binary or memory: http://www.styleseven.com
    Source: Digital-7[1].eot.2.drString found in binary or memory: http://www.styleseven.comCreated
    Source: Digital-7[1].eot.2.drString found in binary or memory: http://www.styleseven.comDigital-7Digital-7RegularRegularDigital-7Digital-7Digital-7Digital-7Version
    Source: Digital-7[1].eot.2.drString found in binary or memory: http://www.styleseven.comhttp://www.styleseven.comFreeware
    Source: bootstrap.min[1].css.2.drString found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE)
    Source: classification engineClassification label: mal64.phis.win@3/160@2/2
    Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{678CFD22-64D4-11EB-90EB-ECF4BBEA1588}.datJump to behavior
    Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Temp\~DFBF515F26F5F62741.TMPJump to behavior
    Source: C:\Program Files\internet explorer\iexplore.exeFile read: C:\Users\desktop.iniJump to behavior
    Source: unknownProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
    Source: unknownProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6164 CREDAT:17410 /prefetch:2
    Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6164 CREDAT:17410 /prefetch:2Jump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dllJump to behavior

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Application Layer Protocol2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol2Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH0%Avira URL Cloudsafe

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    drtjsmith.com0%VirustotalBrowse
    heygamersnort.at10%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    http://heygamersnort.at/index/it/disclaimer.html100%SlashNextInternet Scam type: Phishing & Social Engineering
    http://heygamersnort.at/index/it/abuse_report.html100%SlashNextInternet Scam type: Phishing & Social Engineering
    http://heygamersnort.at/index/it/privacy.html100%SlashNextInternet Scam type: Phishing & Social Engineering
    http://heygamersnort.at/index/it/100%SlashNextInternet Scam type: Phishing & Social Engineering
    http://heygamersnort.at/index/it/terms.html100%SlashNextInternet Scam type: Phishing & Social Engineering
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoadNfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19y7Cxs5.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/css/style.css0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCAYactd.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/top-arrow.png0%Avira URL Cloudsafe
    http://heygamersnort.a0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc5CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/js/getdetector.js0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYNNfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19G7Cxs5.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCsYactd.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic-CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/ml?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHt/index/it0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfABc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc2CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/safe2.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYdNfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/features-title.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1927Cxs5.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCBc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/safe.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/css/font-awesome.min.css0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAQM7UvI.woff0%Avira URL Cloudsafe
    http://getbootstrap.com)0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfBBc-.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCQYaQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCBc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/ml?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHd0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCAYactd.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc1CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic3CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/red-clock-icon.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fChc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc1CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfBxc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/js/currency.js?v=10%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobtNfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/twitter-it.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCxc-EsA.woff0%Avira URL Cloudsafe
    http://www.styleseven.comhttp://www.styleseven.comFreeware0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1967Cxs5.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu72xMOzY.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc3CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCkYactd.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoY9NfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc6CsI.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/terms.htmlEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCRc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYNNfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu5mxMOzY.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/feature2.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/preloader.gif0%Avira URL Cloudsafe
    http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHRoot0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fChc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/favicon.ico~0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/favicon.ico0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCkYactd.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc3CsLKlA.woff0%Avira URL Cloudsafe
    http://www.styleseven.comDigital-7Digital-7RegularRegularDigital-7Digital-7Digital-7Digital-7Version0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19-7Cxs5.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAgM7UvI.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc5CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/money-bg.jpg0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCsYactd.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7mxMOzY.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfCxc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/social-callback-title.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fBBc-.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfCBc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/css/css_2.css0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu4mxM.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/check-button-bg.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/css/cust_video.css0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/faq-title.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/check-icon.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/js/scripts.js0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/images/bg-pattern2.png0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobdNf.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu4WxMOzY.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic2CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7WxMOzY.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc-CsLKlA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfChc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fABc-EsA.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/css/reset.css0%Avira URL Cloudsafe
    http://heygamersnort.at/geo0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYdNfQyQ.woff0%Avira URL Cloudsafe
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCxc-EsA.woff0%Avira URL Cloudsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    drtjsmith.com
    172.67.165.113
    truefalseunknown
    heygamersnort.at
    78.40.46.135
    truetrueunknown

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoadNfQyQ.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19y7Cxs5.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/css/style.csstrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCAYactd.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/images/top-arrow.pngtrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/disclaimer.htmltrue
    • SlashNext: Internet Scam type: Phishing & Social Engineering
    unknown
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc5CsLKlA.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/js/getdetector.jstrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYNNfQyQ.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19G7Cxs5.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCsYactd.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic-CsLKlA.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfABc-EsA.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc2CsLKlA.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/images/safe2.pngtrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYdNfQyQ.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/images/features-title.pngtrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1927Cxs5.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCBc-EsA.wofftrue
    • Avira URL Cloud: safe
    unknown
    http://heygamersnort.at/index/it/terms.htmltrue
    • SlashNext: Internet Scam type: Phishing & Social Engineering
    unknown
    http://heygamersnort.at/index/it/terms.htmltrue
    • SlashNext: Internet Scam type: Phishing & Social Engineering
    unknown
    http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHfalse
      unknown
      http://heygamersnort.at/index/it/images/safe.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/css/font-awesome.min.csstrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAQM7UvI.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfBBc-.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/abuse_report.htmltrue
      • SlashNext: Internet Scam type: Phishing & Social Engineering
      unknown
      http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCQYaQ.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCBc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/abuse_report.htmltrue
      • SlashNext: Internet Scam type: Phishing & Social Engineering
      unknown
      http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCAYactd.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc1CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic3CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/red-clock-icon.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fChc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc1CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfBxc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/js/currency.js?v=1true
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobtNfQyQ.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/twitter-it.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCxc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1967Cxs5.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu72xMOzY.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc3CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCkYactd.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoY9NfQyQ.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/ittrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc6CsI.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCRc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYNNfQyQ.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu5mxMOzY.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/feature2.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/preloader.giftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fChc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/favicon.icotrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCkYactd.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc3CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19-7Cxs5.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/disclaimer.htmltrue
      • SlashNext: Internet Scam type: Phishing & Social Engineering
      unknown
      http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAgM7UvI.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc5CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/money-bg.jpgtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCsYactd.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7mxMOzY.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfCxc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/social-callback-title.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fBBc-.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfCBc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/css/css_2.csstrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu4mxM.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/check-button-bg.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/css/cust_video.csstrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/faq-title.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/check-icon.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/privacy.htmltrue
      • SlashNext: Internet Scam type: Phishing & Social Engineering
      unknown
      http://heygamersnort.at/index/it/js/scripts.jstrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/images/bg-pattern2.pngtrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobdNf.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu4WxMOzY.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/true
      • SlashNext: Internet Scam type: Phishing & Social Engineering
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic2CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7WxMOzY.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc-CsLKlA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfChc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fABc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/css/reset.csstrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/geotrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYdNfQyQ.wofftrue
      • Avira URL Cloud: safe
      unknown
      http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCxc-EsA.wofftrue
      • Avira URL Cloud: safe
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      http://fontawesome.iofont-awesome.min[1].css.2.drfalse
        high
        http://heygamersnort.a{678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drfalse
        • Avira URL Cloud: safe
        unknown
        http://heygamersnort.at/index/it/ml?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHt/index/it{678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drtrue
        • Avira URL Cloud: safe
        unknown
        http://getbootstrap.com)bootstrap.min[1].js.2.drfalse
        • Avira URL Cloud: safe
        low
        http://heygamersnort.at/index/it/ml?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHd~DFF40159CB9872391F.TMP.1.drtrue
        • Avira URL Cloud: safe
        unknown
        http://www.styleseven.comhttp://www.styleseven.comFreewareDigital-7[1].eot.2.drfalse
        • Avira URL Cloud: safe
        unknown
        http://heygamersnort.at/index/it/terms.htmlEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH~DFF40159CB9872391F.TMP.1.drtrue
        • Avira URL Cloud: safe
        unknown
        http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBHRoot{678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat.1.drfalse
        • Avira URL Cloud: safe
        unknown
        http://heygamersnort.at/index/it/favicon.ico~imagestore.dat.2.drtrue
        • Avira URL Cloud: safe
        unknown
        http://www.styleseven.comDigital-7Digital-7RegularRegularDigital-7Digital-7Digital-7Digital-7VersionDigital-7[1].eot.2.drfalse
        • Avira URL Cloud: safe
        unknown
        https://github.com/twbs/bootstrap/blob/master/LICENSE)bootstrap.min[1].css.2.drfalse
          high

          Contacted IPs

          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs

          Public

          IPDomainCountryFlagASNASN NameMalicious
          78.40.46.135
          unknownSweden
          13189LIDEROLideroNetworkSEtrue
          172.67.165.113
          unknownUnited States
          13335CLOUDFLARENETUSfalse

          General Information

          Joe Sandbox Version:31.0.0 Emerald
          Analysis ID:347016
          Start date:01.02.2021
          Start time:22:27:30
          Joe Sandbox Product:CloudBasic
          Overall analysis duration:0h 4m 36s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH
          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal64.phis.win@3/160@2/2
          Cookbook Comments:
          • Adjust boot time
          • Enable AMSI
          • Browsing link: http://heygamersnort.at/index/it/terms.html
          • Browsing link: http://heygamersnort.at/index/it/privacy.html
          • Browsing link: http://heygamersnort.at/index/it/disclaimer.html
          • Browsing link: http://heygamersnort.at/index/it/abuse_report.html
          Warnings:
          Show All
          • Exclude process from analysis (whitelisted): taskhostw.exe, ielowutil.exe, backgroundTaskHost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 52.255.188.83, 88.221.62.148, 104.43.193.48, 168.61.161.212, 51.11.168.160, 152.199.19.161, 20.54.26.129, 52.155.217.156, 8.248.123.254, 8.248.125.254, 67.27.157.254, 8.241.122.254, 8.241.122.126
          • Excluded domains from analysis (whitelisted): displaycatalog-europeeap.md.mp.microsoft.com.akadns.net, arc.msn.com.nsatc.net, ie9comview.vo.msecnd.net, ris-prod.trafficmanager.net, displaycatalog.md.mp.microsoft.com.akadns.net, skypedataprdcolcus17.cloudapp.net, ctldl.windowsupdate.com, arc.msn.com, skypedataprdcolcus15.cloudapp.net, e11290.dspg.akamaiedge.net, iecvlist.microsoft.com, ris.api.iris.microsoft.com, db5eap.displaycatalog.md.mp.microsoft.com.akadns.net, skypedataprdcoleus17.cloudapp.net, go.microsoft.com, blobcollector.events.data.trafficmanager.net, go.microsoft.com.edgekey.net, audownload.windowsupdate.nsatc.net, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, auto.au.download.windowsupdate.com.c.footprint.net, au-bg-shim.trafficmanager.net, cs9.wpc.v0cdn.net
          • Report size getting too big, too many NtCreateFile calls found.
          • Report size getting too big, too many NtDeviceIoControlFile calls found.

          Simulations

          Behavior and APIs

          No simulations

          Joe Sandbox View / Context

          IPs

          No context

          Domains

          No context

          ASN

          No context

          JA3 Fingerprints

          No context

          Dropped Files

          No context

          Created / dropped Files

          C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{678CFD22-64D4-11EB-90EB-ECF4BBEA1588}.dat
          Process:C:\Program Files\internet explorer\iexplore.exe
          File Type:Microsoft Word Document
          Category:dropped
          Size (bytes):30296
          Entropy (8bit):1.855231976142374
          Encrypted:false
          SSDEEP:192:rMZ3ZF2w9WLtlifw35zMFxB2wrD2vsf2r3EjX:rMJcwUpKVZ2S262U
          MD5:FF2E5089D6793A3ECEBAB8CC8311F640
          SHA1:82A7D79592F54E6C01F1E873BBA1C2C66286A18F
          SHA-256:BEFFCA8ADA5EACE46C87B6628B2E9627973DA2390709129023E3955FC66C9ED8
          SHA-512:A6E61B2AF125CFF9225E4477AC0D3814027554DB74E884605289E0679B4B694AC2DAA196315AC0570F93195815119C7A5BE83AA5DAC11FD6760FC300E03C4929
          Malicious:false
          Reputation:low
          Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{678CFD24-64D4-11EB-90EB-ECF4BBEA1588}.dat
          Process:C:\Program Files\internet explorer\iexplore.exe
          File Type:Microsoft Word Document
          Category:dropped
          Size (bytes):78252
          Entropy (8bit):2.2572027503757908
          Encrypted:false
          SSDEEP:384:ryGw0BhUwGwayxLAOnvfp94UBCH3Mp1YbkIEc9HoZgxdfTWnlTLTGjo+c:lZT
          MD5:DA2D49CDE7AACB5A94307359855A7B12
          SHA1:F220E8858C4C8B16D15368BEB07BE87EEFE294D5
          SHA-256:F4D0FA52B4B7A6545F7472944CA6755FF97AF04C854BF0D63B874D83F537E3D3
          SHA-512:A24F61666FE65D93B4EA84B6698C9A4A89EFADB2D40AE4A5D2883FECF741110D13845C5D630710C8CE4B0B322A4BB0BA702BBD2F3EE50B54CC0D53B0ED7835A4
          Malicious:false
          Reputation:low
          Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{716510CA-64D4-11EB-90EB-ECF4BBEA1588}.dat
          Process:C:\Program Files\internet explorer\iexplore.exe
          File Type:Microsoft Word Document
          Category:dropped
          Size (bytes):16984
          Entropy (8bit):1.5648485763807114
          Encrypted:false
          SSDEEP:48:IwOGcprPGwpaGG4pQSGrapbScrGQpKKG7HpRTsTGIpG:rSZ5Q26UBScFAlTT4A
          MD5:47227D6D6A5E7B1D3596C7CFAD25E779
          SHA1:99E53890DAFD5C1F55952C635658B413112EFFCA
          SHA-256:AF9BEA89C1BA09F4650A0EC4B38352618C624E750B14EB0C23F04B0BDDC46CB7
          SHA-512:F60E8D772AC2919BF6A2AE756E225FC1F3236AFFF52C7067D3F293225E3C3FE88B6D216C7308B44E3D478A7C06E9CF30865075F5F7F8F14AA017A05F283CFAD6
          Malicious:false
          Reputation:low
          Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:data
          Category:dropped
          Size (bytes):20692
          Entropy (8bit):3.368614077307635
          Encrypted:false
          SSDEEP:384:CM57ul43UnqgvhMMMMMMMMMMMMMMMMMMMMMMMbAAAAAAAAAQ:/5kTvhMMMMMMMMMMMMMMMMMMMMMMMT
          MD5:30227C3265DA0EAD3010DC59A6C5ADB9
          SHA1:9A4179164DA0A0CBDB0D609DB84CC77B03BB5721
          SHA-256:00FC6C2B550E57B7587321A198A9C7166A7395635DD246605095E861846BB988
          SHA-512:856E7B37FABC3B33EC788CE07A400D03CD6136EBB0431FF05278D05D25FA6310E296D420DA7C2BF883F7DB3D48DAD0C3BD56E0F979E69EFEACE9F314B7F8CCCC
          Malicious:false
          Reputation:low
          Preview: .h.t.t.p.:././.d.r.t.j.s.m.i.t.h...c.o.m./.f.a.v.i.c.o.n...i.c.o........... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TLBCc-CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 13768, version 1.1
          Category:downloaded
          Size (bytes):13768
          Entropy (8bit):7.9463018245853565
          Encrypted:false
          SSDEEP:384:RLMgDyq1Utb27E3ZmcH74g9pF0KtUirLqkP:RLMgWq1Ucw3agbF0CUhkP
          MD5:C18D624BF38FB7DCB9977839F5E4B008
          SHA1:8203739749B2A07B09A5A08D21CC9B2E2B389FA6
          SHA-256:EFCFDB4FACB2447F46D9D1AECCECAC0795001EEF31767EA52514EF24964F7496
          SHA-512:02BDD5555FC698698DFCC41BD8978CAAD29B90E10B1EA45503D239ACC6ED35141D9ADA3AA1F4E2D86FA81B357ADB1A1EBA62747BC902B9361ED59F3D37EB52D6
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc-CsLKlA.woff
          Preview: wOFF......5......._.........................GDEF.......J...j...tGPOS...........z...CGSUB...h...5...6....OS/2.......M...`|...cmap............d..1cvt .......Z...Z...=fpgm.......3......#.gasp...(............glyf...4..$`..B..%.xhdmx..0....N.......Fhead..0....6...6.G.Whhea..1...."...$.H.Phmtx..1@............loca..2.........1.B.maxp..3.... ... ....name..3...........>.post..4........ .a.dprep..4........8...Cx......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x.,.CB.Q..._.d.m.m{........Fm#..7..?./P....@.kh.#d.xg....UB..6.A....i...........*.......B.J.../.E..e....m~iO.......K...o.f`..{r.0.o..."BT..a.k.d..YrG<;.o.#UY&[...r.......%.x.H$.dRH%.t2."..r.#...)...J)..z.h..V..^..d.1&.d..f.c.eVXe.M..f.=.9......s.e..V...?....'...n..s89..S.6T.K'8fffff...Q..}Z=YN..X.........|......b.1..&.>..;..7M........U...C..?t:..R.......:.....L[...&.Y..P.5P.!.I..Fh.0.B.L!>B.^..a<............|...T...s*..._...j..Z...G7B.....`.9"..%....j1z...J{V.T.X>...M.j.TB5.@-.l.....ah
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TLBCc2CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2196, version 1.1
          Category:downloaded
          Size (bytes):2196
          Entropy (8bit):7.2343616301215175
          Encrypted:false
          SSDEEP:48:3++9Z1xakaPNTQzFMNjMFPjplVoQaHOsMRx/h:3h9Z+hlqvjHV6HGrZ
          MD5:4C40EEF1AB3A9287607DEDFFD716D202
          SHA1:9C2C4588ED5FD70B8224D8D4C36F030C4D3380DB
          SHA-256:8F47F3ACC4253D83837884260C85ED80C2A2CB97C2D16D90C3852EF7CB2E1CDF
          SHA-512:DB06CEC9DBFFD3CC336332DCB20E50DE271D1B1BEA7C490216EC2EAE352A95E0FA92E99CCEC23D95C24F8E8D1A0F6CC227D64F56DDF14C00DAABAE601CECC3FC
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc2CsLKlA.woff
          Preview: wOFF...............|........................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...L...`.G..cmap.......7...X. ^.cvt .......Z...Z...=fpgm...$...3......#.gasp...X............glyf...d.........Tphdmx................head.......6...6.G.Whhea...P..."...$.H..hmtx...t...........*loca...............Dmaxp....... ... .7..name..............>.post........... .a.dprep...........8...Cx.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f........:....Q.B3_dHcb``.b(p`@.....@..l......g11(00...X.n`P.Bf.....x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......N.`.J.......}.............`.......9.......!...:.......................[............x.]..G.A..g.."@......q....G...0_...].?......w.=.~........y.}>./.......O.....y......2]Z.G.=.>T....D...Iz..^N.....A...4.`.[.w.....wAte..j:..S..6.&.4.2..S.."s7...H,..d.u.B..t.!.g.....Aog..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TLBCc3CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21644, version 1.1
          Category:downloaded
          Size (bytes):21644
          Entropy (8bit):7.972941384236188
          Encrypted:false
          SSDEEP:384:eBkuqaCbnzbZGdMl2O/WSQivVXlP57vwZrl+/WeAJTCMsK9qjxv0:KqamzbZGdMlL/HQsXlP5Twm+B1sIq9M
          MD5:A773D99556538C22F69F45D4551725CA
          SHA1:429B15EFDDE99644D462D71552CAFF9D4CAB65C0
          SHA-256:DE2D7E764D7080DCAFA4A0AF415187CEAD11282941AA991C5B3250BD72C03731
          SHA-512:572EA0AAD9EF8221BC2CEAFB865B5E193D038C8C16E72F76F7F008A4AA5579EB5839D74CD8F52490741F2753978BC8B82018989A69EA9E0A1FD99508A7EF594B
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc3CsLKlA.woff
          Preview: wOFF......T.................................GDEF.............~..GPOS.......1...BqmeEGSUB...P...5...6....OS/2.......L...`|Z..cmap............S.(Ncvt .......Z...Z...=fpgm... ...3......#.gasp...T............glyf...`..C...wz`(U.hdmx..Mh...o....UJaGhead..M....6...6.G.Whhea..N...."...$.H..hmtx..N4............loca..P...........a.maxp..R.... ... ....name..R...........>.post..S........ .a.dprep..S........8...Cx............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x.....I..O...?/ccm.f.l.m.m.c.H6...tFk..R...9....I>=.7.......G[...Y........wW=*...\.S..].,".s%...-G.E.nW.0g.s..|.t.W...X%<...*c...U.Q........^L\../...&...P.5...>S3.T+.V[..~O..(..8M.dM.:m.6m..........>..q..y].U].u..M..m.(A.JS.2..W..Xu.'5..5.4.J..~...|.T.Kc.].x.T..-"....l.f.0..x.C=.v.u...8.W u..S..X3y./&...=....E..}.f(\....|[...S..p)..M......U.F"....j....>....T;....E..CV...5..-~1hF.....t...f=..vf=..;Qo&... |".8C..p)P...E&.D.....i.^...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TjASc-CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 13444, version 1.1
          Category:downloaded
          Size (bytes):13444
          Entropy (8bit):7.938577323980127
          Encrypted:false
          SSDEEP:384:eFO/PFd/a3d0Sy7mbVXFsHMZ5PNMcd6q3xWW8Y:e2XadBR1tZscQqBWlY
          MD5:5FFC7C80DB40BAD0A3E39BA3668CC517
          SHA1:EF5405F009CBB5795B6076F07594F582DB02F9FE
          SHA-256:CB202914E559013B11B0FE8AFEE7D5CA49851A8FFCE164E5E2F801F60FD666F2
          SHA-512:328F7C71205B928664D13FE1E3F1505846B9C1896F9A060C7EDBABF655FA52416B91575776A17FDD6AE6A49F787400178A1C52383D0A93C167ED31E2B32D2FDF
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc-CsLKlA.woff
          Preview: wOFF......4.......^.........................GDEF.......J...j...tGPOS.......s...V.y}.GSUB...T...5...6....OS/2.......M...`y..Ucmap............d..1cvt .......X...X/...fpgm.......4......".gasp................glyf......$(..C...x.hdmx../D...N.......:head../....6...6...mhhea../...."...$....hmtx../.........j...loca..1|........9.KCmaxp..2.... ... ....name..2...........>.post..3........ .a.dprep..3........?.1 .x......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x....d.....>=6.......g.5g.x.z.m.6.m.Vp.~.q..;.._.......(2@..B2k.U\.z..-\.~...\..m..q.."B_.l^.c.e.!....qt.1L.d...f...5..f.....O..m....7..q...E..\1?/....s..O...$.O^.....e........j.|<..<.<...._....._....'...1....J..t.. .3.a.t.#..h.0.q.g...D.i.f.sY.B.....d....7.....Y....Mlf+]t....b7{....../..:ZdG...x..q/c..&.L.....&g.r....2W9_....R.J.6G......n.7.b.....G...V...)...."..f.....z.e5..m....=e}.....=..5......}.....u....@.-..41X.....hd..y.+.k.f....mG...~.../..|..>$.g...........[....l7...`9.J.}..f...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TjASc2CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2228, version 1.1
          Category:downloaded
          Size (bytes):2228
          Entropy (8bit):7.215136128169384
          Encrypted:false
          SSDEEP:48:fyBb0niivYusWFCRixvDZ6gg3lgGBxDU8Mq0hbxc9Kj:fyBgniivzCRixvoLlZBxDU8W8oj
          MD5:4ACC4BEE131A847BB733EB5C4220BE1A
          SHA1:978102C4626532ADB19AD068EE6C2532BCF48D76
          SHA-256:D2154D2B2E68BAA2377D26C3041906348F5932F6786D2D37BA7B31E6B85EDF29
          SHA-512:BBEFF134655D349E375E036150B1C617640B3A356E7E5F5C86D9EB572B4A4B149D9771C8D9DAAF1CC65C58152C7C244C287B178FDCAABB1304A57699CB79D0B7
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc2CsLKlA.woff
          Preview: wOFF........................................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...L...`....cmap.......7...X. ^.cvt .......X...X/...fpgm... ...4......".gasp...T............glyf...`........+*n9hdmx... ............head...4...6...6...mhhea...l..."...$...}hmtx................loca................maxp....... ... .7..name..............>.post........... .a.dprep...........?.1 .x.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.d.a`e``..j...(.../2.1100.1.80..w..w.r_y_6....i.......X.X70(.!3..S..x.%................I....X.L"~.MnE.......<$..#..X..6.....*.h.Z.`.V...N.n.....N.`.F.......`.......9.......!...:...................[..............x.]..G.A..g.."@.....q....G...0_...].?......w.=.~........y.}>./..b...Oj.....z.<..p-e.L....4x...-'...[..t.]....9.a...p4.`.].wf....wAte.n5a.q............T"...E..$)..d.un.N."2.u.}./.vk.4z.A.g(,..F.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TjASc5CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9948, version 1.1
          Category:downloaded
          Size (bytes):9948
          Entropy (8bit):7.90746962093554
          Encrypted:false
          SSDEEP:192:RJtuos3uGeyx6DveyGSH0v8fV3jcru9ALjWCKSxON+HeY7GJUpW6W8Y:AorGeyxCooxOLjWCdOKerJUpW6W8Y
          MD5:A3FF54598CA82B1CD18240787411F89C
          SHA1:C9FCD541AD97F22F0FC6C31045520374B27B806E
          SHA-256:BCEFB48D2F0FCDDA99C0AD731D1DCF73FCE19346657CBBAC775907F3027E1475
          SHA-512:5027DA2A2107A31F43661D6EE5F7C4402388E3937A42FCEB3AA1515DDE7335B381E5DE3F64EBAE173B27E2E285CF73CBFFD0D0E639EC79ABD1EE85C883FF329D
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc5CsLKlA.woff
          Preview: wOFF......&.......=.........................GDEF.......E...d...sGPOS.......g...J5...GSUB...D...5...6....OS/2...|...L...`w...cmap.......Q....$V".cvt .......X...X/...fpgm...t...4......".gasp................glyf..........*|...hdmx.."X...@...p.|..head.."....6...6...mhhea.."...."...$....hmtx.."....&.......vloca..$.........t.~.maxp..$.... ... ....name..%...........>.post..%........ .a.dprep..%........?.1 .x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.|...eW.E.....m..6c.S..R\Fl.....Y.....>.{r..T...5k.U.<..NQ..g.{.2O9...(AfA.;..NS....y.$....`K.../...%zY.....P..t......'T....~V..=.....U.&.g..!.C.r..R.r..<.`..De*W.jT.:5.I.j.>:@.j..j....R-.r.....#..B;R.v.*,U5.n.[....j.9j...-.....{...9Y. ..h<...7.o...xe........A.h.i.r.r.}...h.>P.h.Q....R.=..Ub..~a.A..T.3..O5.:.f..5.....7...j...f....*.k.Y...}.C.u8...G"S.0......T:..._.h...8.V...^.~...#...T.A...~*...:p...G.h.t....M`..J%*.X....\.l.n..J.*..v:...H..q...Th.*.O............WHy._...T..1.....M .A<..m/
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TzBic0CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 16384, version 1.1
          Category:downloaded
          Size (bytes):16384
          Entropy (8bit):7.959755698918598
          Encrypted:false
          SSDEEP:384:nCqWU6+vp84XqUOWMBat39J63gMsRJmwe4UVwvaVf5XLwYmISJCo:nCB+vp5XqCMByJgsRJI4UWva7LwYmISr
          MD5:68AE86B901207C2517599F26436405AA
          SHA1:D5BCCA7A39154647D6A992942D6285139AC3519D
          SHA-256:3E406A20F0A1A94CFC66DAC8EBF6FD3B3CA54C7F34BF5DA5A4E577B72A7B8FEE
          SHA-512:8DF58B979F8650D8D876C4709C95CF36277AC72F338EC200BFCF596EB97818854D1E46B237B4A5660F6C6F4A682C02E753AD6AE504F76884C2FAE154C086B698
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic0CsLKlA.woff
          Preview: wOFF......@.......v4........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......Q...`vYB.cmap............%...cvt .......J...J..,ofpgm...<...3....c...gasp...p............glyf...|..0...\f....hdmx..9D...i....5;E2head..9....6...6...`hhea..9...."...$....hmtx..:.........E...loca..<$..........nmaxp..>.... ... .,..name..>4........ .=$post..?........ .a.dprep..?,........9..Bx......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TzBic1CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7684, version 1.1
          Category:downloaded
          Size (bytes):7684
          Entropy (8bit):7.8825755448100105
          Encrypted:false
          SSDEEP:192:X1YaL2GYZxgO9lzcpST87ziALjsOzPxSJCo:FcbZxgO9lgAMN9zJSJCo
          MD5:E3E32C0CE098A952D0B3E2BCA1B33676
          SHA1:712CA4078C0EA51006E59481A6AD407C5C5C92EF
          SHA-256:63A9E243500A16BC14BF7DC7275D3ACF9F173DEF967CD44EF021D9914500E5F2
          SHA-512:C3B31D850FEB8D027FF21AAF7C189105EBC447CE9303FD88B1A07F372F5A2BD371024B1055D74ED240E1FC71DC9AD4CC729FFD4EC2A360045B190846C0C12ACA
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic1CsLKlA.woff
          Preview: wOFF..............6$........................GDEF.......'........GPOS...............0GSUB.......5...6....OS/2.......O...`v:.@cmap...8........C.B.cvt .......J...J..,ofpgm.......3....c...gasp...<............glyf...H...Q..'T....hdmx.......6.......3head.......6...6...`hhea......."...$...<hmtx...0........A#..loca............Q.H.maxp....... ... ....name...8........ .=$post........... .a.dprep...0........9..Bx..... ..0..Q*jj.eoN......8......x.'.x..5R.@.D.....p9.n........$8.Dh......]..UO......a......4=.k`.o..h..8.L."(@..M.c.O...6...@Y.1....[...o.y........."........{..}...@.W.]..4........N.XI..h...~....dJ....bV..E:m(...cEgJ....'.1&..t.........3.w.......c.T..n..H.....J.x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.g......:....Q.B3_dHcb``.b(P```A.p..wgPddRX.....!.}..P..|........ d.......x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.......N.`.1.......|.........`..... .!...:
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOjCnqEu92Fr1Mu51TzBic6CsI[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21588, version 1.1
          Category:downloaded
          Size (bytes):21588
          Entropy (8bit):7.973550860004932
          Encrypted:false
          SSDEEP:384:9do1erd5msN48bPbceGykR88v9yGLRkcl46tW6amtMQSJCo:9+1erd5vCfRzluCSJV
          MD5:81F57861ED4AC74741F5671E1DFF2FD9
          SHA1:AC3993E9EDC4C30C97FE670AA1E8A7088AA69E31
          SHA-256:EEC142608E8B417E2ACB6E5301A750047A04E2C5A6563223CAAE499E19EA08EE
          SHA-512:F23A7D58BE44E474CB65C368B048EB68AA1B6FEF4A12797A4A19C8D9E2F1BB7AB6FCEAE2AD17C59283616503107C332EA6245BF9F721BC49A676E8C92F46EC74
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic6CsI.woff
          Preview: wOFF......TT................................GDEF.......G...d....GPOS.............~..GSUB.......'......r.OS/2.......O...`u...cmap...X..........W.cvt ...P...J...J..,ofpgm.......3....c...gasp................glyf......@W..n.S...hdmx..M4...n........head..M....6...6...`hhea..M...."...$....hmtx..N..........=-.loca..P...........maxp..Rh... ... .(..name..R......... .=$post..Sh....... .a.dprep..S.........9..Bx...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x....dK...{....?..F?.|.~.m...ms.{.Z..;......U.]7s......\.=D.=.7...>....x...D..O|.U:...|o..3.x.j.r"B.............../.)x$.'"j.....1LGmaGxQxG....~.:'.A..hd.z,.k..KO.....^.}H|#z_.O......R..A...9..A..!.(./..."..:.Iq1.r..s..r.7r.7s..q.wr....nz..]...2..d4c..c....d....T.1...d....\....,c9k.g..Yv.#O."%...... ...t"uM..%.......j.#^.....}\c.q.i...<jy.D...C.01.2.r.....V..z.W.7b..L.S.41]..kUs.X/6..b.........(..(...K..{.^..'........`#./..B......N+p.m`...].lQ....Drg.M..Kx.^.S.*..........h ..$.k.'Hy.I.ze..4z.-T.....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOlCnqEu92Fr1MmWUlfABc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 12568, version 1.1
          Category:downloaded
          Size (bytes):12568
          Entropy (8bit):7.941312710798985
          Encrypted:false
          SSDEEP:192:KHZbYmfe+aogLelbrfox39WsWoJaRV7xUaSEKt4jZQctM5NqyoIA2Azibi+Rj1rB:KHuMgexAUoJJmZWbj2+RjRHUEgm
          MD5:BB1AEDF67706185A6DFB4BE87B055451
          SHA1:39336EF017D893E044A30C6C4CA09930938E27E3
          SHA-256:0CE211907F36FCE8189A00EB5CA938A7E35ECE1AD806D6310FDC9DF22E80E2D6
          SHA-512:779C87522353DD703E6337EA1E56F09F9D9C1866E8E6C25ED2BE8CD344EADFBEC335CE8A9DD1BECED19AF1854099A3764D9E3B2C76B260E83CFC387470D69354
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfABc-EsA.woff
          Preview: wOFF......1.......[l........................GDEF.......J...j...tGPOS...........z...CGSUB...h...5...6....OS/2.......N...`{:..cmap............d..1cvt .......H...H+~..fpgm.......3...._...gasp................glyf... ......?...,hdmx..,....N.......Fhead..,T...6...6...\hhea..,........$.&.Shmtx..,...........(.loca...0...........maxp../@... ... ....name../`.......~..9.post..00....... .m.dprep..0D.......)*v60x......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x.,.CB.Q..._.d.m.m{........Fm#..7..?./P....@.kh.#d.xg....UB..6.A....i...........*.......B.J.../.E..e....m~iO.......K...o.f`..{r.0.o..."BT..a.k.d..YrG<;.o.#UY&[...r.......%.x.H$.dRH%.t2."..r.#...)...J)..z.h..V..^..d.1&.d..f.c.eVXe.M..f.=.9......s.e..V...?....'...n..s89..S.6T.K'8fffff...Q..}Z=YN..X.........|......b.1..&.>..;..7M........U...C..?t:..R.......:.....L[...&.Y..P.5P.!.I..Fh.0.B.L!>B.^..a<............|...T...s*..._...j..Z...G7B.....`.9"..%....j1z...J{V.T.X>...M.j.TB5.@-.l.....ah
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOlCnqEu92Fr1MmWUlfCBc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2132, version 1.1
          Category:downloaded
          Size (bytes):2132
          Entropy (8bit):7.201807107591226
          Encrypted:false
          SSDEEP:48:fqR7YniPXo2WgrkGQfJcsSVCqnhjwrjqVc9:fStrWqkGQfbSEqnxjm
          MD5:CC8EEE47ABC6A34AF6BC5F7FE93752DA
          SHA1:D8A66E0929BFB008B10A920D97C5C61300056838
          SHA-256:C4D0224AFF496B5E05457346E1DDFE218212AF341E23310B9C0DDC8813365E12
          SHA-512:91CB2AE11B151F76C0BD393906BF4934EE569710B25C562244B3F026EC68F8FD1EFB1C9066ED2B48210F86B8B7EA44CE2CBAF53E6C6434096577D18A8D919BBD
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCBc-EsA.woff
          Preview: wOFF.......T................................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...M...`....cmap.......7...X. ^.cvt .......H...H+~..fpgm.......3...._...gasp...H............glyf...T........F.%.hdmx................head.......6...6...\hhea...0.......$.&..hmtx...P...........,loca...l.........y.0maxp...|... ... .7..name...........~..9.post...l....... .m.dprep...........)*v60x.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`fY......u..1...<.f........P...........}.}...10...bbP``...c.b........C.....x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......N.`.1.......|.-.....`..... .!...:..............................x.]..G.A..g.."@...q.q....G...0_...].?......w.=.~........y.}>./.......O.......=.[p#e.L..-...HYDFN..'.N..._....9:.&.a.i,.r....).$......t... xm.M6h.e.o...E.n..D NH(%S.3.u"..E....}y.[{`..Y.v..!.`...i..{.5.}..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOlCnqEu92Fr1MmWUlfCRc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 19340, version 1.1
          Category:downloaded
          Size (bytes):19340
          Entropy (8bit):7.969405009499026
          Encrypted:false
          SSDEEP:384:eBcxw4boLuwJSxUmA87VFNVyIodXbyr0+coi4cGFagkZxMVesDEEgm:I4bozJF87VlyIod+r0Loi3yi2VeS1/
          MD5:28A800F698DC41B8DABD77EE8DCDE2DA
          SHA1:B9F89D6AEDBB657EC7C8E00267D423C1866FC1A5
          SHA-256:519F4716B61571279A7C09EDE000AA2D6ADFBC68E769EF03FFCEA568551D7716
          SHA-512:325AB2D91C7DEFF76B085E6C087057D3FAC05F286BDDF95B1BE7012D1BF6A9B112599090B458B620644E8BFEC08F2DE233E0496460626EE481717E13638DE2E8
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCRc-EsA.woff
          Preview: wOFF......K.................................GDEF.............~..GPOS.......1...BqmeEGSUB...P...5...6....OS/2.......M...`{...cmap............S.(Ncvt .......H...H+~..fpgm.......3...._...gasp...D............glyf...P..:5..npPD4.hdmx..D....p....XLdIhead..D....6...6...\hhea..E0.......$.&..hmtx..EP.........v#.loca..G.........P'4jmaxp..I.... ... ....name..I........~..9.post..J........ .m.dprep..J........)*v60x............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x.....I..O...?/ccm.f.l.m.m.c.H6...tFk..R...9....I>=.7.......G[...Y........wW=*...\.S..].,".s%...-G.E.nW.0g.s..|.t.W...X%<...*c...U.Q........^L\../...&...P.5...>S3.T+.V[..~O..(..8M.dM.:m.6m..........>..q..y].U].u..M..m.(A.JS.2..W..Xu.'5..5.4.J..~...|.T.Kc.].x.T..-"....l.f.0..x.C=.v.u...8.W u..S..X3y./&...=....E..}.f(\....|[...S..p)..M......U.F"....j....>....T;....E..CV...5..-~1hF.....t...f=..vf=..;Qo&... |".8C..p)P...E&.D.....i.^...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOlCnqEu92Fr1MmYUtfBBc-[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20392, version 1.1
          Category:downloaded
          Size (bytes):20392
          Entropy (8bit):7.969803364230641
          Encrypted:false
          SSDEEP:384:Ld21eNqGoVwVsb0PULg3ZaTn09dltEGKMmZvBxvSJ66JQ3GoT4G54:LY1eNqGM8jULg3Z609taBx6J6fT54
          MD5:BB1E4DC6333675D11ADA2E857E7F95D7
          SHA1:3E2625FE48669F4AD48823E8C18E6FB14B74C5A0
          SHA-256:E8586F9DB7C0503A984C944AD2F1F783BF6051AEA2A066BC21FDEDC8FE7FA68A
          SHA-512:7EBCB4E20E323880245FD9900D58FC54086132711A695825134A8F34D9C63A48610454C9F10210CBB1926A65D1FEBEA96176F865910E1A6A9487FF9BDD83D87B
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfBBc-.woff
          Preview: wOFF......O.................................GDEF.......G...d....GPOS.............~..GSUB.......'......r.OS/2.......O...`v...cmap...X..........W.cvt ...P...Z...Z...=fpgm.......3......#.gasp................glyf......;...k@...hdmx..H....l....%(. head..I....6...6...Rhhea..I@.......$.]..hmtx..I`...y......=.loca..K.........Mc1.maxp..M.... ... .(..name..M........|..9.post..N........ .m.dprep..N........8...Cx...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x....dK...{....?..F?.|.~.m...ms.{.Z..;......U.]7s......\.=D.=.7...>....x...D..O|.U:...|o..3.x.j.r"B.............../.)x$.'"j.....1LGmaGxQxG....~.:'.A..hd.z,.k..KO.....^.}H|#z_.O......R..A...9..A..!.(./..."..:.Iq1.r..s..r.7r.7s..q.wr....nz..]...2..d4c..c....d....T.1...d....\....,c9k.g..Yv.#O."%...... ...t"uM..%.......j.#^.....}\c.q.i...<jy.D...C.01.2.r.....V..z.W.7b..L.S.41]..kUs.X/6..b.........(..(...K..{.^..'........`#./..B......N+p.m`...].lQ....Drg.M..Kx.^.S.*..........h ..$.k.'Hy.I.ze..4z.-T.....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOlCnqEu92Fr1MmYUtfChc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15500, version 1.1
          Category:downloaded
          Size (bytes):15500
          Entropy (8bit):7.962617450959354
          Encrypted:false
          SSDEEP:384:ENqprqF+M9utlHp0mkFHuIfStvWCe86FV99Hmk:ENIqFwly8IfStuCeNXZ
          MD5:FD64CF9F97AF460DDFD180BEFEC0464B
          SHA1:83F23E1BA0216AC9D31FFD381422B83B55E08D95
          SHA-256:B8F528EFD391B8FAE45912AC51DAA9D2BD0340150FA5F94047CAC13E03DDEE37
          SHA-512:7343459F2929EBA8A5B730D57CB2DBBCD0F4D5225F0F80C26A30BD3CBCD0794A7F673FDC34378947B31A02762E581693C6E4A2FD7977169D7BDED3AA3C870A3E
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfChc-EsA.woff
          Preview: wOFF......<.......s.........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......R...`w!B.cmap............%...cvt .......Z...Z...=fpgm...L...3......#.gasp................glyf......-O..Y\..U.hdmx..5....g....CBV:head..6D...6...6...Rhhea..6|.......$.]..hmtx..6.........f.0.loca..8........., ..maxp..:.... ... .,..name..:........|..9.post..;........ .m.dprep..;........8...Cx......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOmCnqEu92Fr1Mu7GxMOzY[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15616, version 1.1
          Category:downloaded
          Size (bytes):15616
          Entropy (8bit):7.954432936496767
          Encrypted:false
          SSDEEP:384:oQ9hdlnyTvaXisZt/xyKqZwcGV0Scyu8KD:oQPcvaSstoKgH+Gyu8C
          MD5:253F16A2EAE3D76A318E33B11F5B7614
          SHA1:8B370CF5F5D44A1A8EE4C33724AAF7209263FE00
          SHA-256:AB01F93DCE70D817327D4770FACE44C04B4DB7B23C9599AAE03ACAFCA4B455D4
          SHA-512:DD2F302A5A952F6CD15A7CEAD4CCD1FFA47831161F9200208FEEF789D43110023759586BB59F9AD47C82A47FBCE034E009113A2BFED1E1C43F042E4D05CD5B5C
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7GxMOzY.woff
          Preview: wOFF......=.......t@........................GDEF.......5...@.`..GPOS.......6..../..FGSUB............N.K.OS/2.......Q...`u-B.cmap............%...cvt .......T...T+...fpgm...@...5....w.`.gasp...x............glyf......-...Z.;.j.hdmx..68...h....06E3head..6....6...6.j.zhhea..6........$....hmtx..6.........H.SHloca..9.........?.)Kmaxp..;.... ... .,..name..;$.......t.U9.post..;........ .m.dprep..<........I.f..x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..3. W.........c.L..k.el....}...6...U..].R.W_{.-.g....`.}.8..]#.9_9$JP..}..9.m%.J)..nV.l.t..w~%*].A..`...V.WK....[.."..:.JK..S.F..t..m+Im..@Z..g9.f...."F..3...N..j...H.#..mq:!.8.A..!.....>.Y.....4.>.U.#..6..xu..i.[Nszf.&]8.(...E.v.....:5..t.J..}.iM.E..$R...o..Y.tG-.B.9...M.9. C!...gy6....m.w..=.!.{....2..C.3..#.2...7.D.L6.T.L...=.).x..^....m.z..>...}.S........}.{?...f.e.y.Xd.eVXi...Xk..6.U.Q..m.u..[.^}......[...........F....k9$.K.F+,S..Jm..)..F..[c...u....)..K.3..Z.....[..j.....7w.o.K..2."c.....B.T...n
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOmCnqEu92Fr1Mu7WxMOzY[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7236, version 1.1
          Category:downloaded
          Size (bytes):7236
          Entropy (8bit):7.860853457065225
          Encrypted:false
          SSDEEP:192:E9g9tBfVHpIRH0KXMvJ0zJCQqIjHBpmMbylAOi7:E9g9f3AMJcqCHi0P
          MD5:673F872562256B786632911857030AC3
          SHA1:A75EF987A50A50463A9565F6B7DCBCEA3160742D
          SHA-256:AA201A63F4E31F2CA567B665905B33EDC198020B385302CB5D5CD1AAF2FC148B
          SHA-512:486663978C3ACE26FE2EBFDB753261801006BF465737A7D1CD1B83F457F14E6719C4221AD3A264B96ED66E4D1DB9DC44182571537387DECB79124C6880218D14
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7WxMOzY.woff
          Preview: wOFF.......D......40........................GDEF.......'........GPOS.............P.0GSUB.......5...6....OS/2.......O...`u..Vcmap...<........C.B.cvt .......T...T+...fpgm.......5....w.`.gasp...L............glyf...X...^..%p..{.hdmx.......<.......3head.......6...6.j.zhhea...,.......$...&hmtx...L........Ez)kloca...8.........W..maxp...H... ... ....name...h.......t.U9.post...8....... .m.dprep...L.......I.f..x..... ..0..Q*jj.eoN......8......x.'.x..%PEQ.E.}......\...h...C.{oH.D...V.|.sp..g.yz1@.d.......6..w..7u.v..v........... `T/....[x....a.W"(...r.......*...;....c.K...>=...}.r..Sr.f^.].,...<...DS...$RF3It..g..M:...!.*..>B...G/..}......NP..=..*...........<?h.;A.*.}{...yKI...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`fic......:....Q.B3_dHcb``.b(P```A.p..wgp`dRX.....!.}..P..|........ d......x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.......x...d.N.Z...`.V.4.<............
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\abuse_report[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):12704
          Entropy (8bit):4.436452059968922
          Encrypted:false
          SSDEEP:192:T6irVzjIPcu2x7CkFNftxoO7wWCkMjTiyAIzGxUuATC:DXLfCJyUuATC
          MD5:ED1F0C782FFC3175C67181FD19418911
          SHA1:C6796981312410258754BE9808566E4C777AE733
          SHA-256:98695447ABF6DDE0EAFA5F6C0E8C93CCAB1802CAA7A059248A71557528E8A3F8
          SHA-512:5900E9D531014CD17E91AAB99CEA55D4F205DAA110A3E2EF2D830F4419C239FF406EF513EEE0D9FA8089E65B2EBD72807CC423F89FC36C1477180507C4C6EC98
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/abuse_report.html
          Preview: <!doctype html>..<html lang="en">..<head>.. <meta charset="UTF-8">.. <meta name="viewport".. content="width=device-width, user-scalable=no, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0">.. <meta http-equiv="X-UA-Compatible" content="ie=edge">.. <title>Report Abuse/Spam</title>.. <link rel="shortcut icon" href="favicon.ico">.. <style>.. body {.. background: rgba(0, 0, 0, 0.7);.. margin: 0;.. height: 100vh;.. }.... .form-contact-us,.. .form-contact-us * {.. margin: 0;.. padding: 0;.. outline: 0;.. box-sizing: border-box;.. text-indent: 0;.. text-align: left;.. font-family: sans-serif;.. }.... .form-contact-us .input-holder {.. margin-bottom: 10px;.. }.... .form-contact-us .input {.. -webkit-appearance: none;.. border: 1px solid #ccc;.. border-r
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\bg-arrow[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 170 x 114, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):4070
          Entropy (8bit):7.743228173607098
          Encrypted:false
          SSDEEP:96:hGj7Uh1eJhdJImTmejiZTrHTCwwbkmhnhPdmPCYLdI6VV6eNuMU:Vh1WJ5Tmq0TrTC39ph1mPCYW6VV5U
          MD5:4830CDD0299B5CBF5AED8973B8BAB51D
          SHA1:DFBE93091D00A6DE288FBBD0373CF653D18F1EF2
          SHA-256:FC7F6EEE29D88AF43AAE090E1141AA1BE427A7F0ACE77D120D1DE5F54A9A0067
          SHA-512:3E81C82648E0D1D4B0DF254326E71029312DECF3CDF124BB2220D2ED58E0B6244D5254D372F804C0D54C7EF4AD914B9A811C1730DE3CCCC70D266D14D0C20001
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/bg-arrow.png
          Preview: .PNG........IHDR.......r............PLTEGpL............................................................................................................................................................................................................................................................................................................................................................................................vxy.............)....tRNS.*41(......$.5.......<&,.0..".9...9.!x.>.JUp>.tM@^J|VG]AjCbPjlRgW.CZiMXlE^TePalsNab.g[hr[nveRxIebX.odq.DFa.F.1<#E.'jw..Y<O8Ha. kv|.zzk,!n.t...yIDATx..{[S....p.B.U@@)- .B...Q.........@.w..bD..?.............i......s..Z..~..y..o..s;...WG..]n...;.G..hs..^_>X?...ur9.y.Q_pT...7.:..=.U.....u2u.K...... .S.....G.zu.%QS...zX6..z..._....3[_....I...X...|...X.>~P..~..j*di..g.9SY[.._..S_.............\..Z'N.(-=..|Y..o.)9w.............d.b55..xu.{wuzui..+....M....y.../........{....?j1A...%....VE0i.^.5......4D.....e"......v7
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\bg-pattern2[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 246 x 246, 4-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):700
          Entropy (8bit):7.215728868717868
          Encrypted:false
          SSDEEP:12:6v/7g/YWKzzCerlHf7osmCD28zIGQJxMCZj70/8kOi52c:H9Kz2erl/7ICyGQ/l7JBc
          MD5:76C81425084E6D65D19989F1FE3F2AF2
          SHA1:025884C382B8E903831A9A692A612759909FA32A
          SHA-256:2B6D7F9A9779035BB2F1C8E17738BE760D64F269E68673F93B746C17027399ED
          SHA-512:6E7C4AE675D72D9A5DD5DACA1704437A34963F18ACF91853CB4C4D7C9CEFB65E294127AE1C6FC81A5158287EC56144E0228212081A85ED133C3F0B792227A095
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/bg-pattern2.png
          Preview: .PNG........IHDR..............<g....'PLTE.e.-a.(X.+^.*Z.'U|-c.*\.(W.&Sz%Qw#Nq,`......PIDATx...1OSa......[4.o..P.V.6.p.DRq)....Z1..pSkXoL0..h.V'.Idp../.&......ZM....<.3...Fx......-].........i.....W....dWK%.jwt.H.o\9......Z.....5......C=X......ii.u.\.n.zWu...T-..t...iZ.S.o.\.....z1..e...l..MK.(W..=U....5.....~.^....LK>..g..Q......[..I..d..9.Rz(...4..[.LK.E.....^&>.6}.....{..{1-.r.$(....].4-.....K...~|/..V.7....^,K{...\..gZ......K........,..bYR.p|/.8.3-...{...A....?.........^n&.i...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx...1<......cx.?../&.B}.3.t....IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\button-left-arrow[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 173 x 114, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):1081
          Entropy (8bit):7.623915310696776
          Encrypted:false
          SSDEEP:24:sFJG2/p/1iKPIHXIe3hSbAe8TV/glzfHQBX4V3:sFJfp/103Ie8c7hIlfQBoV3
          MD5:AE442CE668E759A083B972B253983A9D
          SHA1:BF9A305DF9E1A68181B07FCA46186E922BB1E50B
          SHA-256:678C399D2901F8A1E07A26985549CA728F4189D20A584907556C565BCD52E658
          SHA-512:F91D9831804C3E3E89E9D94F9CD51E9E07F04D3F5A35F557ACA182826E44EAC4510129CE8B6A82752204347BB23361F541A9E9BDDEBC7123C35CBC941A2F2817
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/button-left-arrow.png
          Preview: .PNG........IHDR.......r............]PLTE......GpL.............................................}..............................[\]...j..g....tRNS...............y.....L...1C.U#aN%.i...lIDATx...aw.0...4Y).U.....g.!...H..<ywN[..k9.Rg.dqF<...e...{.8.K..}7..>.........)..G{i...E.7....#7.-....%........n..5Wm.'.M7...6i.w.[..J#z.2T....+...K..._..D.b.wi${........O#.......3.V.....s...+.F.U..v..ih=J..z.....Mj.....s....F.J.....+.-..EZ[..,-[/-..N..^/._...I..W....M.L+g.4<-Y).P.R...]....giRK#.Y..UZ4..-.K....q..0..Q......`....j.Bi.Z.P...~.&..R>...g....'...+.G..x..}..`.d.6..R..w0....E>?.4..|...*-...Ak9}+.[K....r.Z....7.4x-.K..R.J..*Mjs.y...6..zLBK+.fe...........Y!.m.Hh.e.h..n.Z.]..3K@...V....O..~CO?...'Fh,..........b~a.......Xl.Ka...>.....}-.\.V......j?.C.~.......ca...%R..v.0..B...@.?..j..aj].Aj..!j..j.>.(.~30...k..iW.3.(c.[.Ml...zaX...[.Ai..i6..!....A4.G....|.0.=.4...G.FaZ+....<...:Bv..>....Gq...=.;O.^....S..\l.ga.X.<.<...-l>j..{,.wa1.H.GO@a.....;.sS....._....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\css[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):18958
          Entropy (8bit):5.4391691796628185
          Encrypted:false
          SSDEEP:384:VfFzNVKJr8irF067KGulXYFXQXuXwKXgLXSXD3XlTvAWcEr:6Am6sxg7gD
          MD5:82D81397CA8C4B984A7013D883C0DEF8
          SHA1:8EC5B0DD42F12D2BA27AAC52B3FC014AC52234E0
          SHA-256:BE763A554895E2120B2736E310112A83C13C14910D361E1BD885F6F2C850B658
          SHA-512:6C2179B9A06782A263BD708BEEBD6D3114EF52C43E8EB5FCBA4F198E6D0F73AC30B808AC1B73B0AC2A66C88687103DF56B1E08039EC5F68FCB45BFFFB25953D6
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/css.css
          Preview: /* cyrillic-ext */..@font-face {.. font-family: 'Roboto';.. font-style: italic;.. font-weight: 300;.. src: local('Roboto Light Italic'), local('Roboto-LightItalic'), url(../fonts/KFOjCnqEu92Fr1Mu51TjASc3CsLKlA.woff) format('woff');.. unicode-range: U+0460-052F, U+1C80-1C88, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.. font-display: block;..}../* cyrillic */..@font-face {.. font-family: 'Roboto';.. font-style: italic;.. font-weight: 300;.. src: local('Roboto Light Italic'), local('Roboto-LightItalic'), url(../fonts/KFOjCnqEu92Fr1Mu51TjASc-CsLKlA.woff) format('woff');.. unicode-range: U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.. font-display: block;..}../* greek-ext */..@font-face {.. font-family: 'Roboto';.. font-style: italic;.. font-weight: 300;.. src: local('Roboto Light Italic'), local('Roboto-LightItalic'), url(../fonts/KFOjCnqEu92Fr1Mu51TjASc2CsLKlA.woff) format('woff');.. unicode-range: U+1F00-1FFF;.. font-display: block;..}../* greek */..@font-face {..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\css_2[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):15930
          Entropy (8bit):5.496076830182844
          Encrypted:false
          SSDEEP:384:2aGJadpT1WdGmjGpsD6UGLsbpVTNc9Is9pDMzGcSiM:BZ
          MD5:91F1F6DE6BF53B1DD0DECA8DDA592DD5
          SHA1:BD3839ECE3A3205F7267D3C7313849F0A4D9C01E
          SHA-256:F0D58C0A6673D8001D084CFD2192F2256092C639A9D50414435715B934D05149
          SHA-512:DDA599729C7AD22775057FA2A3A19DF0DEE98EF7798A75C434DCEF37BFDCE1F50E423DD5EA518889FD29C26A968480ABB14575A6B7E252C581325BD7A5CE7F03
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/css_2.css
          Preview: /* cyrillic-ext */..@font-face {.. font-family: 'Roboto Condensed';.. font-style: italic;.. font-weight: 300;.. src: local('Roboto Condensed Light Italic'), local('RobotoCondensed-LightItalic'), url(../fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYNNfQyQ.woff) format('woff');.. unicode-range: U+0460-052F, U+1C80-1C88, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.. font-display: block;..}../* cyrillic */..@font-face {.. font-family: 'Roboto Condensed';.. font-style: italic;.. font-weight: 300;.. src: local('Roboto Condensed Light Italic'), local('RobotoCondensed-LightItalic'), url(../fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoadNfQyQ.woff) format('woff');.. unicode-range: U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.. font-display: block;..}../* greek-ext */..@font-face {.. font-family: 'Roboto Condensed';.. font-style: italic;.. font-weight: 300;.. src: local('Roboto Condensed Light Italic'), local('RobotoCondensed-LightItalic'), url(../fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\cust_video[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):941
          Entropy (8bit):4.596976690831124
          Encrypted:false
          SSDEEP:12:7RE/CdXIivYX+BT0oqAGVstdBfm8lLbBdenvtO2wt6dPrEvo5Tb78h1jfoE/:VJdXWSTpAUdBptIvtOBt6dzh5TyEm
          MD5:D4F3A8802314824E332B1D6E1693A65E
          SHA1:24DE1FC6A9D6F45AF3448B003476D5ACAFADD691
          SHA-256:6378910C4C025CA9D7F5B92086FC3E9EC068200156F3AADF6A8DF3CB9F1B9B4E
          SHA-512:847B6801EE9DC5178D950D53F985B950A6D41D0569E37B95159CF97C163BA26A47E079FF9BBA79A2D9EAB52D6DBC01E363395E175A0C025A0B31B5FA7A21C16A
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/cust_video.css
          Preview: .video{.. max-width: 100%;.. }.. .. .. .video{.. border: 10px solid white;.. box-shadow: 0px 4px 20.9px 3.1px rgba(13, 13, 13, 0.43);.. }.. .up_sound {.. text-align: center;.. display: none;.. width: 166px;.. height: 38px;.. cursor: pointer;.. position: absolute;.. top: 18%;.. right: 38%;.. bottom: 0;.. z-index: 5;.. color: #fff;.. background-color: #000;.. padding-top: 8px;.. font-size: 16px;.. }.. .. .anticlicker {.. position: absolute;.. left: 0;.. top: 0;.. right: 0;.. bottom: 0;.. z-index: 4;.. }.. .. .. .. #volume_up {.. position: absolute;.. z-index: 5;.. top: 25%;.. right: 37%;.. width: 24%;.. display: none;.. cursor: pointer;.. }.. .algo-video-container {.. position: relative;.. background-color: #e8ebf6;..}.....algo-video-container video {.. display: block;.. width: 100%;.. object-fit: cover;..}....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYNNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21056, version 1.1
          Category:downloaded
          Size (bytes):21056
          Entropy (8bit):7.969225333854826
          Encrypted:false
          SSDEEP:384:w1lR0DgJAY9avGqGPxo9Fv7HS2ddodNA3P3OJvqxCmiARmcN:JWAY9RqG6HS2k03PovTmJRbN
          MD5:82FE0DAA86274AB522B6F753075D03E7
          SHA1:F908468A4043E3E9B235E5FB48EEE8DFAECC98F7
          SHA-256:1DDCD64E282953A8582A0ED66B07D874CAC765C57329A3889AC8BBC3AC9DDE69
          SHA-512:DA8F2DB4F412F69DB23981711F29F2707D554C28F30C5003267758DD93A6537D2DB68021668DD92838D667A74B548A5A8F26426AF842D43419C26E46E0DEB6E9
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYNNfQyQ.woff
          Preview: wOFF......R@................................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......M...`z...cmap............S.(Ncvt .......X...X/...fpgm... ...4......".gasp...T............glyf...`..@...t.2..hdmx..K....j......!.head..K....6...6...hhea..K...."...$....hmtx..K...........!.loca..Nl........G.*.maxp..PH... ... ....name..Ph........&.D'post..QL....... .a.dprep..Qd.......?.1$.x............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobtNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9864, version 1.1
          Category:downloaded
          Size (bytes):9864
          Entropy (8bit):7.916112856261582
          Encrypted:false
          SSDEEP:192:8Otuos3uGesXxAmHR+GYcig7vALfq4DVZ0oPKho0nsnVvXh2YhW2N:eorGesXxAYR+Gn7vALfqQB+onVp2cW2N
          MD5:E6A69730BC5F90197682A6BFE9677FAA
          SHA1:6D47C71114EAF466A6B93230A4D591E36C2D0E41
          SHA-256:6CA500F267D616F917672F86A2F977C9D907612AF7C5045275CA48D1DEB41A16
          SHA-512:517E90F347CDDF0855B021A9D66C8DC331A69592C161FA92A5EF7CA7B167A5D05772FD1103E0E6E7620B27565E4F74B9F9437A20C7EC235126B6210CCD4E5C2B
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobtNfQyQ.woff
          Preview: wOFF......&.......=0........................GDEF.......E...d...sGPOS.......g...J5...GSUB...D...5...6....OS/2...|...M...`w...cmap.......Q....$V".cvt ... ...X...X/...fpgm...x...4......".gasp................glyf.......T..)..Z..hdmx.."....<...polo.head.."H...6...6...hhea.."...."...$....hmtx.."....!....x...loca..#.........i.r.maxp..$.... ... ....name..$.........&.D'post..%........ .a.dprep..%........?.1$.x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.|...eW.E.....m..6c.S..R\Fl.....Y.....>.{r..T...5k.U.<..NQ..g.{.2O9...(AfA.;..NS....y.$....`K.../...%zY.....P..t......'T....~V..=.....U.&.g..!.C.r..R.r..<.`..De*W.jT.:5.I.j.>:@.j..j....R-.r.....#..B;R.v.*,U5.n.[....j.9j...-.....{...9Y. ..h<...7.o...xe........A.h.i.r.r.}...h.>P.h.Q....R.=..Ub..~a.A..T.3..O5.:.f..5.....7...j...f....*.k.Y...}.C.u8...G"S.0......T:..._.h...8.V...^.~...#...T.A...~*...:p...G.h.t....M`..J%*.X....\.l.n..J.*..v:...H..q...Th.*.O............WHy._...T..1.....M .A<..m/
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYtNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7528, version 1.1
          Category:downloaded
          Size (bytes):7528
          Entropy (8bit):7.87319389854196
          Encrypted:false
          SSDEEP:96:jK+bq1YndYva0vez2AeUqaJfDvexZ7WFKasbk/nioFkImSnhzY0e/rpu:eMq1YaC0veaARqa47kKaPIS1Y0e/Vu
          MD5:AA34CFCBCA12BBAC03E04FD6E8961D92
          SHA1:6AC211BC71BDCC25F1C6A2D0B4B4247062DA9746
          SHA-256:1A9EC11014F7285C6E61AB78D86F7366EF4977E066C6183A6DC5B33C67570243
          SHA-512:FB5E04BD97A151978DC0499318BAC2B4B761A877EC22C3C3B441B6FAA7C98388AA20377E160EF54DB70CE3EEED4402BC5009F7F4A3112537FA4645EFEC4A70DF
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYtNfQyQ.woff
          Preview: wOFF.......h......3.........................GDEF.......'........GPOS...............0GSUB.......5...6....OS/2.......O...`v:..cmap...8........C.B.cvt .......L...L0..Gfpgm.......3....g...gasp...<............glyf...H......$.IZV.hdmx.......7........head...,...6...6...hhea...d..."...$...!hmtx.............t..loca...h........!N..maxp...x... ... ....name............%.Czpost........... .a.dprep............=...x..... ..0..Q*jj.eoN......8......x.'.x..5R.@.D.....p9.n........$8.Dh......]..UO......a......4=.k`.o..h..8.L."(@..M.c.O...6...@Y.1....[...o.y........."........{..}...@.W.]..4........N.XI..h...~....dJ....bV..E:m(...cEgJ....'.1&..t.........3.w.......c.T..n..H.....J.x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.b......:....Q.B3_dHcb``.b(P```A.p..wgPddRX.....!.}..P..|........ d....%.x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.......N.`.1.......|.......`..... .!...:..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobdNf[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21724, version 1.1
          Category:downloaded
          Size (bytes):21724
          Entropy (8bit):7.974605519713776
          Encrypted:false
          SSDEEP:384:/pduI1eJWziNWE5jE2UvQIqLM5rb9TIvVVngnxOCM3R1x9n70vhH3d9Y:/pB1eJoLEO2C9R9c3gnxEHxN6Xd9Y
          MD5:A8C91ECA220E5E01B288AF0F4D812A47
          SHA1:7CC2DB4BA489DEC324AEA057CF4A73B110EFA8F4
          SHA-256:AABF6E207B0C50FDE5479BFA331BD760ABEA99A00A546FAA0C7CB863D8218B3D
          SHA-512:AD97ABF93F03C649BF198A0432705243615E8F7A0C74D40388A4CA58A1C1D03087BC4BD26692F1479FFB4593A82A4055BBB52445F09618C07B4B3912ABFBE93C
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobdNf.woff
          Preview: wOFF......T.................................GDEF.......G...d....GPOS.............~..GSUB.......'......r.OS/2.......P...`u...cmap...X..........W.cvt ...P...L...L0..Gfpgm.......3....g...gasp................glyf......@...p..q..hdmx..M....f........head..N0...6...6...hhea..Nh..."...$....hmtx..N....x....q.-8loca..Q.............maxp..R.... ... .(..name..S.........%.Czpost..S........ .a.dprep..T.........=...x...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x....dK...{....?..F?.|.~.m...ms.{.Z..;......U.]7s......\.=D.=.7...>....x...D..O|.U:...|o..3.x.j.r"B.............../.)x$.'"j.....1LGmaGxQxG....~.:'.A..hd.z,.k..KO.....^.}H|#z_.O......R..A...9..A..!.(./..."..:.Iq1.r..s..r.7r.7s..q.wr....nz..]...2..d4c..c....d....T.1...d....\....,c9k.g..Yv.#O."%...... ...t"uM..%.......j.#^.....}\c.q.i...<jy.D...C.01.2.r.....V..z.W.7b..L.S.41]..kUs.X/6..b.........(..(...K..{.^..'........`#./..B......N+p.m`...].lQ....Drg.M..Kx.^.S.*..........h ..$.k.'Hy.I.ze..4z.-T.....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobtNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9672, version 1.1
          Category:downloaded
          Size (bytes):9672
          Entropy (8bit):7.9074919829878505
          Encrypted:false
          SSDEEP:192:J8BlEdDJvevqPesJlz3XsaK25N7X5fSJLzJJ1s6YVK7LqOjjVe/Vu:JmlkJWyPeYz3jK25LfSJ/JJ1s9Q7FiY
          MD5:A0885A3E23727836CDBB098CADB66871
          SHA1:EFC1D7CC9DB08EC56C105445F9A4984686EF3A3A
          SHA-256:9D4DDDF7E1DF9460B63F37C53ADE87AA32F1233935B5034C6ED14E3231B51C0F
          SHA-512:1AB05B1F33C58FA450CF350233A0E30A59406CB71AAAAF719551D211E3AA2F6969DED9949851BBC97D524A57EC518A1F5BEDFFACD3E8B9AC6A27F2717CE805B5
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYobtNfQyQ.woff
          Preview: wOFF......%.......<(........................GDEF.......E...d...sGPOS.......,....4...GSUB.......5...6....OS/2...@...M...`y6..cmap.......Q....$V".cvt .......L...L0..Gfpgm...0...3....g...gasp...d............glyf...p......).....hdmx..!P...?...purr.head..!....6...6...hhea..!...."...$....hmtx..!....#.......-loca..#.........^.h.maxp..#.... ... ....name..#.........%.Czpost..$........ .a.dprep..$.........=...x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.}.C..Y.....{e..m....`7....ms.}......<.&..J5....6f...wnZC..MKW..f.u..Cb..x..nZG0....@...+....y.E..../.....o^........{'..U.-.lW.h...l........F..d.I.9.G.E.RA.5....a....p.e...D&3.9, .\.D.EQa...RcAt..tS..E....a.$...c.~Unj.7U...x.4.t.N....G~..c.....v...~M. SZcO.#?D..).$..<Ev......=*..U..j.E..u..v..vA.<......c...3C.Yv.9..x...QB.,..B./.(!...c.]......S..P<G....J....-m.....].&L....W.[T..*..v!.)..4G..."{....\.A...n.]...*...(.?U......9.X..}.....M|C...v..U...t.>a..!HS.u.z...Buo...pu.S(....R"4yGx
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCQYaQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20216, version 1.1
          Category:downloaded
          Size (bytes):20216
          Entropy (8bit):7.9731523480827216
          Encrypted:false
          SSDEEP:384:x5dof1ePzctBTXSQZqP5Lrypoau4bxpepCYgjL9CRLu6E8wwvVUig7J:x5O1ePzQBTidP5Cpoj4bbep3gnh8wwvO
          MD5:2B92236BBDE5370469497D38AB63938D
          SHA1:C597E284BCD5AB132ED99F215874EFEB5E50A3B0
          SHA-256:3C1E53960417886AB9C55495A8046B10EBF315FD62DDB2BDC80BAED953957D68
          SHA-512:89B3790006B199F643130FFF5BDF4D8FD22689217929B4B2B27CC90560666013974F31E60CDD7600587516DB68B1DD04975B09B0E5771A46DBFF224057DF9A2E
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCQYaQ.woff
          Preview: wOFF......N........(........................GDEF.......G...d....GPOS.............~..GSUB.......'......r.OS/2.......Q...`u.. cmap...\..........W.cvt ...T...J...J.V0Xfpgm.......3....c...gasp................glyf......; ..k...''hdmx..H....j........head..Hl...6...6...hhea..H........$....hmtx..H....p......H3loca..K4........H.,.maxp..M.... ... .(..name..M<........!^?.post..N........ .m.dprep..N0...........x...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x....dK...{....?..F?.|.~.m...ms.{.Z..;......U.]7s......\.=D.=.7...>....x...D..O|.U:...|o..3.x.j.r"B.............../.)x$.'"j.....1LGmaGxQxG....~.:'.A..hd.z,.k..KO.....^.}H|#z_.O......R..A...9..A..!.(./..."..:.Iq1.r..s..r.7r.7s..q.wr....nz..]...2..d4c..c....d....T.1...d....\....,c9k.g..Yv.#O."%...... ...t"uM..%.......j.#^.....}\c.q.i...<jy.D...C.01.2.r.....V..z.W.7b..L.S.41]..kUs.X/6..b.........(..(...K..{.^..'........`#./..B......N+p.m`...].lQ....Drg.M..Kx.^.S.*..........h ..$.k.'Hy.I.ze..4z.-T.....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCAYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 12140, version 1.1
          Category:downloaded
          Size (bytes):12140
          Entropy (8bit):7.937441767251203
          Encrypted:false
          SSDEEP:192:VMv6KFO/PCK0lb2x7+1eUdjU5VCp0EX65snC6GDZBy6Wm7XRvvSKjQRAs:mFO/PUAxgesjuU0EXYMfGBBRvSH
          MD5:C1DAF0994F4A77F6FBBEF8CFCD5259BF
          SHA1:3B8AABF9FA146B3B2EB15CC11B7F42BF7C8F51DA
          SHA-256:DDA0DFCC4DF529B78DF78BE43F70C4B159A805FB4116D3836C9E6D5755A246E2
          SHA-512:181320ECA8088F1B09872FCCE2EC18E3FE43D3EC13AA22F9BC2788BB548A496ABA2768EEB25E9868F0330A764297EC72B7758DB4322A6A676B0C3936DD6985BB
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCAYactd.woff
          Preview: wOFF....../l......X(........................GDEF.......J...j...tGPOS.......s...V.y}.GSUB...T...5...6....OS/2.......N...`y..!cmap............d..1cvt .......X...X/...fpgm.......4......".gasp................glyf.......,..=....$hdmx..*H...L.......&head..*....6...6.*.hhea..*........$.z..hmtx..*.........*.<.loca..,p............maxp..-.... ... ...[name..-..........s=rpost...|....... .m.dprep...........:z/.Wx......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x....d.....>=6.......g.5g.x.z.m.6.m.Vp.~.q..;.._.......(2@..B2k.U\.z..-\.~...\..m..q.."B_.l^.c.e.!....qt.1L.d...f...5..f.....O..m....7..q...E..\1?/....s..O...$.O^.....e........j.|<..<.<...._....._....'...1....J..t.. .3.a.t.#..h.0.q.g...D.i.f.sY.B.....d....7.....Y....Mlf+]t....b7{....../..:ZdG...x..q/c..&.L.....&g.r....2W9_....R.J.6G......n.7.b.....G...V...)...."..f.....z.e5..m....=e}.....=..5......}.....u....@.-..41X.....hd..y.+.k.f....mG...~.../..|..>$.g...........[....l7...`9.J.}..f...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCkYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 19336, version 1.1
          Category:downloaded
          Size (bytes):19336
          Entropy (8bit):7.969764131367131
          Encrypted:false
          SSDEEP:384:0DZlFJDHc+NBrJEDFavj11+lXa+jJO7a6a2x2imKj8LqeM+5uQPqm:oZlLDHdJEe4XagJO7akjuqexuBm
          MD5:0CFD3062309D8398F99B8F9BC796FDDF
          SHA1:0E6190CB6676820D802C65C31A586B6E7D3BE501
          SHA-256:CB5A0544D849F44A030F2DE963B7E2639C6CC58EC1000E6594C076252F6915CB
          SHA-512:1D96496CE8B93F63D4682FC1402CC0160B9DACC5F88200AD95625C92021060519C9A87EF7A2246AB1F741F9966ED8528B6828A04E63C6D62DB0495022AE5EE61
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCkYactd.woff
          Preview: wOFF......K.................................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......M...`z...cmap............S.(Ncvt .......X...X/...fpgm... ...4......".gasp...T............glyf...`..:...nD.0.Mhdmx..D|...n......(.head..D....6...6.*.hhea..E$.......$.z.shmtx..ED.........F?loca..G.........NQ2}maxp..I.... ... ...[name..I..........s=rpost..J........ .m.dprep..J........:z/.Wx............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\red-clock-icon[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 50 x 60, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):961
          Entropy (8bit):7.14415385158716
          Encrypted:false
          SSDEEP:12:6v/7OljlyiahzWIHmWHnSKkp9aH9vyxa9NOA/Kaxe89Sq2LAMQEpBA4iktXbJn:rjczZzSLp9i9sa95/BQLAMQgddn
          MD5:5778AD2233BD1F34E2C24E69FF0B2E72
          SHA1:85DAB60C5332E0469CB7CEFF44C0CD3FBA03DDB4
          SHA-256:44ADAC927AC68FAA401BD44FCEED5F45A63297EEFABF9234E7CF87F37C53341B
          SHA-512:6441AB27F5E979288F83829031F1068E04A085DA783BDB1F3096EEC8815CCE70224894CE40793AF7BD4F52E92D128DD8944917813B39E097AADCFF46B4E9B835
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/red-clock-icon.png
          Preview: .PNG........IHDR...2...<.............PLTEGpL.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.OP.#.=...5tRNS......#...N.p...(..i.d0,\..W..........7wR~.?G_..9.!YNJ....IDAT.....b.8....*d.0.............@$Z.spG.x........................bD../)Yp.....3.s...d.G&c...?..~1P...+..7....`.Bo7...].Uz..@.{.....Q.....].n.[F2....|..-._>...Mk.>l>.v.g.F....'.*.T.+[..J..vE..GG...Q...P.XP}XZ.......g..F..b2.Q.qQ[.5.Q.q.Q+...]...4.8.5E...9..vD..P......a9.X..i...>..."J!.....l..k...JQ.cI....X.L......B....U.V...?.}....\Cr..b.`L...$..pt(....9lu...Z...D..X.....KJ..<..[......<..[.'eXf.o.B..,^..?.R....E....J`.P...(..x.G..8..S...%...R.h.8P....F...Gc._|P..G+./.".X@d.:.S-EQ.H#....S.%.K.u<...F..QD.<..)..';......42..+.......Xx..C.Q.wd.F..K....+...:.....|x..>.........j..f]*.7.}.g...I.'...#^.E.w.Y.........F...R}.hQ.f..J....0.....p.?W-...XT.....IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\rpmlvonsnj[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with no line terminators
          Category:downloaded
          Size (bytes):64
          Entropy (8bit):4.461789500408212
          Encrypted:false
          SSDEEP:3:nmNjJMzVJu+1mA4tERq:GMRJVmH2s
          MD5:27F9A91FF2AC0A6564ADEB00E17EEDE3
          SHA1:309372C3B3DD2B81F989B9BD6D6600CD5D057E24
          SHA-256:49F6C89A0F68C7FC6498DE1A103E9AB39FCC6F9A954BF388CED8B91F2D1F91C6
          SHA-512:8E5F79ACDC68BE06D46F8FF27CCCC5A348864CC07D71918204F5AFEC344CF22066F4FF0619AD9935C50834A2DAC3C1F415D293371780E041396045672B6168D5
          Malicious:true
          Yara Hits:
          • Rule: JoeSecurity_Phisher_1, Description: Yara detected Phisher, Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\rpmlvonsnj[1].htm, Author: Joe Security
          Reputation:low
          IE Cache URL:http://drtjsmith.com/rpmlvonsnj.html?jhBgVdSEQAZSXDRcFvgHBnjMOmmKIjnHHBUgyVtFCcRESXRDCfVGBH
          Preview: <meta http-equiv="refresh" content="0;http://heygamersnort.at/">
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\safe2[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 286 x 53, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):4746
          Entropy (8bit):7.900528726783289
          Encrypted:false
          SSDEEP:96:Z6iadNEZzMYiUX8U0+wwVatj2mXBzkOoZbSR9P79/kRUj/Eb:Z6iaEqYiUHVatfg7ZbG7EUj/O
          MD5:B0DB130477645C81093C262BB1DBE20B
          SHA1:CDD647C27DCC3C25F27C12977D4369E0AB03FC98
          SHA-256:A50065139A338969EE70C1901BAE43F5546167C533E4D4B8767FCDE1D34655C4
          SHA-512:39FF5E491B313B9B69DCE97EF5E2210708994D221D0A227EA12D9A58149AAE56AFFC51B1C48D3B69E409EE129010982DF249B4B8DC627E664ED69E463B28B3C2
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/safe2.png
          Preview: .PNG........IHDR.......5.......t.....PLTEGpL.....................................................................................................................................[.@...,tRNS.....Fx.2M....f....8.S.!?..Y.._rl.,.'...L..}....IDAT....W....e.#.<...a....|....<S..r....:.N....]-..<4u.G.V.nN...r..6E.........Y...^.Z.k^..Nk.....+.tY.2..>.U........wy...........>.t.W....;..J.:..?...J.....|.u34.._.b...S.b".....VN.M...e..]z.Ae.M.w....Hv....[.~..G......6..P.?.6...*...<7.....I..*M)^..t...8^\..........M....r.~'K.SI.U.|..{."......h....q...c...u.Y.o../%.S.w.y..5....;....J~.9.......T.....V{ K..2...s.....[...q.....<.9..3/.Ci..K.1....?q..d.&.....Ao. ..|1..<...k.U.......o'..`X3.\/.~...U7.n.s.....)..Y.4u...4...7.._..(..e|.].zh.Q.../....1..T~.C....$-f.x.]....)..n....Z~T.t3............M(.._d.l...)....p.l..k.d.5+......e|..b'8..Z.5...%.a..?..2.^e.^..<.]..%.T.Y...>.........'.=.4~1)...M.W...g.7.4..8....wXq.w[[oF..fW.b....`.J...U...F=..#.W..t5?..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\style[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with very long lines, with no line terminators
          Category:downloaded
          Size (bytes):72884
          Entropy (8bit):5.03560665831924
          Encrypted:false
          SSDEEP:768:07MHeaIUw7Jq3ZnFQSvZrGT74p0LIqEF/t6fpmM7bqhUS9C:CYeaIUw7Jq3ZnFQcZrGT74p08qaun
          MD5:CCF65EF9B71A0035B384583A575FB54C
          SHA1:5F47B1812F86AAC68D3580F469D43FB83F1ADAA6
          SHA-256:ED2F872EFB16107654AD329B41BA0ACD8892481349A29D27E4222ECB0464E1E9
          SHA-512:5E805D817D028F5FBDD574F7A6A7B8989F964DB56AD5771A191B839F16AFD8353100B30188681F7B480E135273BBAC440A31A78E212DE7B8242C191156CB645C
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/style.css
          Preview: .shadow_none{-webkit-box-shadow:none;-moz-box-shadow:none;box-shadow:none}.fontAwesome{font-family:FontAwesome;font-weight:400;font-style:normal}body,html{height:100%}html *{max-height:999999px}img{border:0}p:last-child{margin-bottom:0}.clear{clear:both}.clearfix:after,.clearfix:before{content:" ";display:table}.clearfix:after{clear:both!important;height:0}* html .clearfix{position:relative;zoom:1}.trim_spaces{text-align:center}.trim_spaces.left{text-align:left}.trim_spaces .scalable{display:inline-block;white-space:nowrap;-webkit-transform-origin:left top;-moz-transform-origin:left top;-o-transform-origin:left top;-ms-transform-origin:left top;transform-origin:left top}.trim_spaces .scalable.middle{-webkit-transform-origin:left center;-moz-transform-origin:left center;-o-transform-origin:left center;-ms-transform-origin:left center;transform-origin:left center}a{-webkit-transition:all .3s;-moz-transition:all .3s;-ms-transition:all .3s;-o-transition:all .3s;transition:all .3s;outline:0
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\terms[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):27179
          Entropy (8bit):4.992114546937935
          Encrypted:false
          SSDEEP:384:SIFr26VjfVRr3T5ozeJfSIO8kpAAsTWMnfW:Sg2QD56c28kXM+
          MD5:703BABF6E7F0F2438777515D6417C4FE
          SHA1:05803387061F42BA799740EA432CB5349F24ED3B
          SHA-256:9CA10CA7AE9E8D241A34850BD16134FB624AA3765262ECD9064B0F7C377B8561
          SHA-512:AD5FE64BF308CD9A9EA9EA249F38C40B343E1EB6CB70B45FB9CD4E811552ED71748758C4264B5A9B0AD1695229EE891BE545F50136FCD33D3975FCA7496B3DE5
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/terms.html
          Preview: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>.. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">.. <title>Terms of Use</title>.. <link rel="shortcut icon" href="favicon.ico">.. <style type="text/css">.. .. body,td,th {.. font-family:Arial, Helvetica, sans-serif;.. font-size:14px;.. color: #111;.. line-height:20px;.. }.. body{.. background-color: #FFF;.. margin-left: 0px;.. margin-top: 10px;.. margin-right: 0px;.. margin-bottom: 0px;.. }.. a {.. color:#111.. }.. -->.. </style>....</head>..<body>.... <table width="1100" border="0" align="center" cellpadding="0" cellspacing="0">.. <tr>.. <td>&nbsp;</td>.. </tr>.. <tr>.. <td height="70" align="center" style="color:#111; font-size:24px"><strong>WEBSITE TERMS OF USE <br>.. <br>.. IMPORTANT --
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\top-arrow[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 111 x 80, 8-bit/color RGBA, non-interlaced
          Category:downloaded
          Size (bytes):2961
          Entropy (8bit):7.665566941283762
          Encrypted:false
          SSDEEP:48:m1nuNn2veJ363EzCeahl3sdo/W6wDuRpIZw3yQaXgSZ:m1S2Czchlckyufwr
          MD5:E2980701AAD64CEF71BD2296F5F6386B
          SHA1:83355C373AE4C499B72AA9C709387076B3053C1B
          SHA-256:C4D3B32E24EA06591E7F166B20939F84CB767BB0742BC3C51F07C6F4B684F1E0
          SHA-512:B6AAE9617FED5454FA56F0D9A2CD963412E024174B78C51717E651981251F836D330AF700D676B9D4D4DB1A512339A4ADE9FD7C249F5F87DF9CDD73014027329
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/top-arrow.png
          Preview: .PNG........IHDR...o...P.......+.....tEXtSoftware.Adobe ImageReadyq.e<...&iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c067 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)" xmpMM:InstanceID="xmp.iid:EE9E2A488DCE11E59127810D20D2010C" xmpMM:DocumentID="xmp.did:EE9E2A498DCE11E59127810D20D2010C"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:EE9E2A468DCE11E59127810D20D2010C" stRef:documentID="xmp.did:EE9E2A478DCE11E59127810D20D2010C"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>@E."....IDATx..i..U..;.^....l8..A......!..DC..1..D..|0.A.b.&&.. .].C.,.r.%+."..\.;3..c.|oy...zmiw......;..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\twitter-it[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 590 x 709, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):35366
          Entropy (8bit):7.9730415870592495
          Encrypted:false
          SSDEEP:768:fP6lVqR/hY4+gz8q8Pjqj5p1QNqsDSTI/A6g6Vj4cmu:fClcR/S49N/jSvDS0/zDjku
          MD5:B758D9428612D7052256D8EC89F3686A
          SHA1:7B9F58F9B6807B3690527092B3CF7E6E84F4A757
          SHA-256:D563D5FD7D12A369C36B29EB7E55E7669248BD3C9C42306B3B747E9420226E44
          SHA-512:A019349855B80382EA023C7FA4169829EE305DD3DD6AF184677BEB70E8F534E5E08CE3A67D1BA947C62066C2B4771C9823D02703099161EBBBBC1706F4082E60
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/twitter-it.png
          Preview: .PNG........IHDR...N................gAMA......a.....sRGB.........PLTEGpL...$+0...............................@DG......z}~...ilnUZ]...................................................................'..............Y=..........`C............B(..gN.U=$$#.....fP.......tS..5..)..._H.........y^.m[.......p.ya...........|.{y=(.N/..........I610.O!...~.gA+.o.hFC.....fM.k[2...tl::8......{.f...X..k..c~YBm1..w.....V>-5&.....pR.`B.@).dW2.tK;.xQ...~rI1!}kf.zR,..{...gQ8..g?._!.......tg..Y.s.....vE...xbY.uB.......y.aq\MxL...\.Q...~:..u_..oLNJ..cb^JB9...dRI..Z.....VTR..........d(.r\....s...[G=.........`*...L...p..................x.......i...vyErz........ul.....\r.AZp.6K.....tRNS....ML....'.....)IDATx..k....#......$..,......).p..z..S....-.BBd..nV2H..... @H.PF86.`.+...8`@.l.q.....H.l9..gZ...H...W....y^................'.....{C.q..'SS.."0.{+<.....d ..%}.6u.........d...-.Np"Fp"Fp"Fp"F..D..D..D......S,v.}v.p.!..q...ZH.)*L.c.!../V...DI.e
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\volume[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 256 x 256, 1-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):875
          Entropy (8bit):7.511760855505471
          Encrypted:false
          SSDEEP:24:ha2FCgVxHNYUwvdLL9+YAICX33ne/9XgZtD:hZCUfBwFLL8vT3e/9XgZtD
          MD5:25209F54CCEEB6AC42097D82256CBFAB
          SHA1:A2CBCFB42B1CE89A17AED8BF640B90F057319390
          SHA-256:CF53BA9A7F63136E884DA82519C4F9343A04B1F56C4AD19B8014A91078F88E77
          SHA-512:3339857CC88D309A443D1ACA56CFDD9CC8C6C7B4BB080EBC01B55B19E7F5A1CB34959BECC89B437DA7FBFA745F95ADF6D232BCFA48CE7DF8A98000BD59AD3D62
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/volume.png
          Preview: .PNG........IHDR.............f.:%....PLTE.............tRNS.@..f....IDATh....m.0..`.<...v..B*...m].KQ.>. h.,Cd6KQ...d..#....R^..9..o.3......9.........I...,..7.".....@..A&P.{P...T..<....\f.E.'..@....2.L.GY..|..A....g.....`@.QF.......H..#>.j..Z,...@_..p..W....@j.....U..2..r..,...].mK..s......2wI ..D.\<l..@..L k.b.,...T-..ZO..).DA.......o.l.....$.YkHfA..i.*l..W.. ..hV.<..B......... 9.Z.....Q..tWYP-......w.<....2..`..N.x(...r.......AB.y..Oa.J........e..@..A.U.....y.K.E.G@S..|.zFz5.R.... .... ..E...5...w.......(=.C.70....c 1.=...@.).....9.. ...'xo.m... ..`.P%....V..+@.:pb.._@.p ...v....@.V ...~=......'...<.....0?...P......X....].\0\Q..&P.T.\.\.Jtu.....Ee.(9...Pmn*.U..P........".....&.....r.`p.N..i..v....7au...B.}..m....E."Cq@....X....B.l....B...,a.B.I.Ui.C.n... ...-0S...$.I.K.K...<..ls...&%^..I-O......<O.........S...w.O..t..o.F......IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOjCnqEu92Fr1Mu51TjASc0CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 16696, version 1.1
          Category:downloaded
          Size (bytes):16696
          Entropy (8bit):7.95451688755879
          Encrypted:false
          SSDEEP:384:O+Y/C7AGgElPb09gO6mvPSNV/tu9+08IdvNq8SRIkdOgW8Y:O+x7nFR09tZPSNV/k9+08clLSRIkdOgq
          MD5:075DEE11FF931A36B5D3CB1B3E318192
          SHA1:4525C23CC30AFD5F24D33673154A31F69D158B4E
          SHA-256:8F4258CC440CA440A43D13F8F1C1D58BB743B5E0B9846337B9C241FEE94C321D
          SHA-512:1954C69AC10C6E0650E55D31B9EF23DF7C1990A99C5799A53A267E3BB5C40994E4948A8DA5BD67D1DF3F356910CD95FECAE047EDA6D974220FF503B488149221
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc0CsLKlA.woff
          Preview: wOFF......A8......x,........................GDEF.......5...@.`..GPOS.......6..../..FGSUB............N.K.OS/2.......P...`t.BRcmap............%...cvt .......X...X/...fpgm...@...4......".gasp...t............glyf......1...^@0.)-hdmx..:l...j..../0C-head..:....6...6...mhhea..;...."...$...rhmtx..;4........#.83loca..=L.........l..maxp..?@... ... .,..name..?`..........>.post..@<....... .a.dprep..@T.......?.1 .x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..3. W.........c.L..k.el....}...6...U..].R.W_{.-.g....`.}.8..]#.9_9$JP..}..9.m%.J)..nV.l.t..w~%*].A..`...V.WK....[.."..:.JK..S.F..t..m+Im..@Z..g9.f...."F..3...N..j...H.#..mq:!.8.A..!.....>.Y.....4.>.U.#..6..xu..i.[Nszf.&]8.(...E.v.....:5..t.J..}.iM.E..$R...o..Y.tG-.B.9...M.9. C!...gy6....m.w..=.!.{....2..C.3..#.2...7.D.L6.T.L...=.).x..^....m.z..>...}.S........}.{?...f.e.y.Xd.eVXi...Xk..6.U.Q..m.u..[.^}......[...........F....k9$.K.F+,S..Jm..)..F..[c...u....)..K.3..Z.....[..j.....7w.o.K..2."c.....B.T...n
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOjCnqEu92Fr1Mu51TjASc3CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21460, version 1.1
          Category:downloaded
          Size (bytes):21460
          Entropy (8bit):7.967122535003185
          Encrypted:false
          SSDEEP:384:vmf3jW3ZoGkAdPZwxaIIcYO2ha2od0HII3TFUxW4IJEhBXXcW8Y:vuC3ZRixNIn7haFg7D+xTKEhBXXclY
          MD5:5FBA81BDD8A62FB709A32FD8A07519F6
          SHA1:3C36FF8CD141017F9AE3E53428EB34A835DF2C05
          SHA-256:7E0C34286AED8971224DAAF2DEAF77EF38B5B97AC2B37B19B5087124AE849514
          SHA-512:1E6617B5A7282887AB558E0750D9B777C41EC6F3E89AE28373FC00967C78CD58A95B3F2D00B568A8747B87EC5A4E5087ACFE8675DD20AE42A01B1908D9BBF8F3
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc3CsLKlA.woff
          Preview: wOFF......S.................................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......L...`z..Rcmap............S.(Ncvt .......X...X/...fpgm.......4......".gasp...P............glyf...\..B2..u@.m..hdmx..L....q....<3P3head..M....6...6...mhhea..M<..."...$...bhmtx..M`........W..6loca..P.........f.I.maxp..Q.... ... ....name..Q...........>.post..R........ .a.dprep..R........?.1 .x............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOjCnqEu92Fr1Mu51TjASc6CsI[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 22204, version 1.1
          Category:downloaded
          Size (bytes):22204
          Entropy (8bit):7.9742393611260916
          Encrypted:false
          SSDEEP:384:X4RPU21exwpjqNUdgwvWwW9i5ZTkudHjv3vQWsdV8bT3XV6qvihHbF9qW8Y:XsPN1eae2SwvWr2TkuDvvQWc8bT3XARH
          MD5:4DF32891A5F2F98A363314F595482E08
          SHA1:A8AB4E03143BCF7646C96A8CB33B3E596A9E55BD
          SHA-256:0BE0AE6EFD852B3695CB7A76286096F60E93B7D31C16E0B71CA35ECED7FDE8F6
          SHA-512:3C1775EE5F2D42B53C4196280D11E3405B9EEAEEFF1FDF8291E7D87D7748D28BBCB1ECD7A225AD266144EAB28ADE08A7EB4659824B2FA649884B86B1783EF2ED
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc6CsI.woff
          Preview: wOFF......V........l........................GDEF.......G...d....GPOS................GSUB.......'......r.OS/2.......N...`t6.<cmap...$..........W.cvt .......X...X/...fpgm...t...4......".gasp................glyf......B...s.._{*hdmx..O....m........head..P....6...6...mhhea..P8..."...$...nhmtx..P\.........FIloca..R..........b'maxp..T.... ... .(..name..T...........>.post..U........ .a.dprep..U........?.1 .x...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x.l..h.a........l.m.6.1+.X....i...y....&...._..63..5....2>...x|D...ct.Kx..H@b.3..l..#u.....L.*.....^.*.4.....rP..{.*......Q...JT.:Xu>..T./>...oq...........~..@.....lq../.... ..#..".&.8.H$..r...J)..jj...&..f.=.9..N9.....'F..8.4.....m...m...m.m..n..&.X..}....S.|.....n........PHaE...J*...4..MjJ.*..nW)..rn3'/.....ks5zY5c...Mgg.5..p..rR{c...p..t\.8.c=..p...X.(.......7....=.........!...H ........(.0...(.q.JT?.b..z].'T...m..vNi.....t....:P.R..H....t.........&?.:.j.51+.S.":j.SK'I.^....}S.i.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOjCnqEu92Fr1Mu51TzBic-CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 13176, version 1.1
          Category:downloaded
          Size (bytes):13176
          Entropy (8bit):7.943301295343486
          Encrypted:false
          SSDEEP:192:lYmfe+aogL9lbJdtvsfm1jWet0y9gOLvWa/UKcFhmy2Cnk8AKXz+To3wxwQdZ6xy:6Mg9J6e1BaO3WGQiCkWaTXiSJCo
          MD5:D97548E6F3FC5DE93D2FD93CA5602B84
          SHA1:054AE9C55434782B6B2B19661F8FB6115F786A85
          SHA-256:CBC498288420B7F214CDD8C58D20A6585B3E04218E653A4003075C3659567E4D
          SHA-512:CCAC153257A784E64F1A25A97B384A26CE65E90370C6F61AD681222F71DCCF66B11506EFD7CD7186157634DA27F758FD7108077A8E04A6A5A97DDA8546613A16
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic-CsLKlA.woff
          Preview: wOFF......3x......\.........................GDEF.......J...j...tGPOS...........z...CGSUB...h...5...6....OS/2.......N...`{:..cmap............d..1cvt .......J...J..,ofpgm.......3....c...gasp................glyf...$.."(..@F..K.hdmx...L...M.......Ahead.......6...6...`hhea......."...$...=hmtx............|...loca..0|............maxp..1.... ... ....name..1......... .=$post..2........ .a.dprep..2.........9..Bx......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x.,.CB.Q..._.d.m.m{........Fm#..7..?./P....@.kh.#d.xg....UB..6.A....i...........*.......B.J.../.E..e....m~iO.......K...o.f`..{r.0.o..."BT..a.k.d..YrG<;.o.#UY&[...r.......%.x.H$.dRH%.t2."..r.#...)...J)..z.h..V..^..d.1&.d..f.c.eVXe.M..f.=.9......s.e..V...?....'...n..s89..S.6T.K'8fffff...Q..}Z=YN..X.........|......b.1..&.>..;..7M........U...C..?t:..R.......:.....L[...&.Y..P.5P.!.I..Fh.0.B.L!>B.^..a<............|...T...s*..._...j..Z...G7B.....`.9"..%....j1z...J{V.T.X>...M.j.TB5.@-.l.....ah
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOjCnqEu92Fr1Mu51TzBic3CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20772, version 1.1
          Category:downloaded
          Size (bytes):20772
          Entropy (8bit):7.96969178887396
          Encrypted:false
          SSDEEP:384:DYB6pTmJRbQ87tM+fNxK60s50Wy/gORrUf8tcUeDL5qrviSJCo:3pTCh5M+fNxLZy/gO+czeDc6SJV
          MD5:92242FF1DD478088CF6400D3D509F556
          SHA1:B7D0C438E46C42C0B27E967008B83C6F8667FD88
          SHA-256:F9DEBA2EF1CEDE72AE4B1C05CC5E0345ACC7D5FD2453143BE4D584D3D56A38C7
          SHA-512:B96CC4A06A8A98150BAC20F25764BFA61F21E00CB57E67A0813C333BF07F50A667EF47CB4BF43D57C3A61045385197B03EA42D9073F882B2B5CF2ADBE56FEAAD
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic3CsLKlA.woff
          Preview: wOFF......Q$................................GDEF.............~..GPOS.......1...BqmeEGSUB...P...5...6....OS/2.......M...`{...cmap............S.(Ncvt .......J...J..,ofpgm.......3....c...gasp...H............glyf...T..?...r8Kc8Phdmx..I....r....KI[Ahead..Jp...6...6...`hhea..J...."...$....hmtx..J.............loca..M\.........L..maxp..O8... ... ....name..OX........ .=$post..P8....... .a.dprep..PP........9..Bx............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x.....I..O...?/ccm.f.l.m.m.c.H6...tFk..R...9....I>=.7.......G[...Y........wW=*...\.S..].,".s%...-G.E.nW.0g.s..|.t.W...X%<...*c...U.Q........^L\../...&...P.5...>S3.T+.V[..~O..(..8M.dM.:m.6m..........>..q..y].U].u..M..m.(A.JS.2..W..Xu.'5..5.4.J..~...|.T.Kc.].x.T..-"....l.f.0..x.C=.v.u...8.W u..S..X3y./&...=....E..}.f(\....|[...S..p)..M......U.F"....j....>....T;....E..CV...5..-~1hF.....t...f=..vf=..;Qo&... |".8C..p)P...E&.D.....i.^...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmEU9fBxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9188, version 1.1
          Category:downloaded
          Size (bytes):9188
          Entropy (8bit):7.903896899901036
          Encrypted:false
          SSDEEP:192:2BlEdqSgddzEp3/k+luQ+U5qdzTeRBlW4flS3aYV9X0qA:klNSgP8MCSdzTeRBfleaYDX0n
          MD5:BF1AC455BA538F8D2B876026C5B67AA0
          SHA1:9A62D71194545B0E9701BEF5DAE82B53F2C1D35B
          SHA-256:7E8F914078B69AAB4F3F70884DDCD5946C64AD16CABD3AE49724ECDADD795299
          SHA-512:B08569BFB06A003CDFF61E78AB5D2352357B9ED1EF3DC0E844AD7D14EB517F5AE80101D863E281D2456E3FE8E2C7F91DD8A5226F865A6708238A387665CDE7C7
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fBxc-EsA.woff
          Preview: wOFF......#.......:$........................GDEF.......E...d...sGPOS.......,....4...GSUB.......5...6....OS/2...@...M...`xn..cmap.......Q....$V".cvt .......\...\1..Kfpgm...@...2......$.gasp...t............glyf..........'...O.hdmx...\...=...p....head.......6...6...rhhea...........$....hmtx.......%.....[.Zloca..!.........B.L.maxp..!.... ... ....name.."...........:.post.."........ .m.dprep.."........S...)x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.}.C..Y.....{e..m....`7....ms.}......<.&..J5....6f...wnZC..MKW..f.u..Cb..x..nZG0....@...+....y.E..../.....o^........{'..U.-.lW.h...l........F..d.I.9.G.E.RA.5....a....p.e...D&3.9, .\.D.EQa...RcAt..tS..E....a.$...c.~Unj.7U...x.4.t.N....G~..c.....v...~M. SZcO.#?D..).$..<Ev......=*..U..j.E..u..v..vA.<......c...3C.Yv.9..x...QB.,..B./.(!...c.]......S..P<G....J....-m.....].&L....W.[T..*..v!.)..4G..."{....\.A...n.]...*...(.?U......9.X..}.....M|C...v..U...t.>a..!HS.u.z...Buo...pu.S(....R"4yGx
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmSU5fBBc-[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20348, version 1.1
          Category:downloaded
          Size (bytes):20348
          Entropy (8bit):7.971548837012925
          Encrypted:false
          SSDEEP:384:sSRPUR1eEsGitLcRtdt6S1PvpjwY9O1V6LTFY88fFFEagMR3SAFNE/A:saP+1eBX4Rtdt6EJjwY9O1V6Pm82lR39
          MD5:B00849E00F4C2331CDDD8FFB44A6720B
          SHA1:5B7820FEC8F9810E291E1EB98764979830ED6621
          SHA-256:76B05400FFF9DA5B43862E3713099E3913916A629560265ED24B19D031227CBF
          SHA-512:64F2BB1D16525CB5435CC3AA253D83669C321D68695CDF14218EEE43B5347DD6BC67B23D6F5E359971B1FFA72857C2C9DCEC0370535F12EDC20AF42CF41CF661
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fBBc-.woff
          Preview: wOFF......O|................................GDEF.......G...d....GPOS................GSUB.......'......r.OS/2.......P...`t6..cmap...$..........W.cvt .......X...X/...fpgm...t...4......".gasp................glyf......;...lxRn..hdmx..Hl...l........head..H....6...6.Y.ihhea..I........$....hmtx..I0.........._Gloca..K.........k.N.maxp..M.... ... .(.\name..M........|..9.post..N........ .m.dprep..N........:z/.Wx...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x.l..h.a........l.m.6.1+.X....i...y....&...._..63..5....2>...x|D...ct.Kx..H@b.3..l..#u.....L.*.....^.*.4.....rP..{.*......Q...JT.:Xu>..T./>...oq...........~..@.....lq../.... ..#..".&.8.H$..r...J)..jj...&..f.=.9..N9.....'F..8.4.....m...m...m.m..n..&.X..}....S.|.....n........PHaE...J*...4..MjJ.*..nW)..rn3'/.....ks5zY5c...Mgg.5..p..rR{c...p..t\.8.c=..p...X.(.......7....=.........!...H ........(.0...(.q.JT?.b..z].'T...m..vNi.....t....:P.R..H....t.........&?.:.j.51+.S.":j.SK'I.^....}S.i.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmSU5fBxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9284, version 1.1
          Category:downloaded
          Size (bytes):9284
          Entropy (8bit):7.908896722387549
          Encrypted:false
          SSDEEP:192:jxtuos3uGejEmprcIyJsFIFkcc+aywlJIdJfDWc3g2IPoy7:OorGejE8asmF0badNWckR7
          MD5:90E9DBBD09EEBB0E4FA6CF01B60ECD4D
          SHA1:9C814266F3C0F41739659B122A6D3B0D7499F0F0
          SHA-256:0AF8DBD5722ED9E8A362F653791E392C9F117254C59F3A7340CEDDC55E135A0A
          SHA-512:2595728DC783047BA34BCDE19F73837FAE712497DF93FF7ECA1EC6BFAB9E188057C234EA14D222045F680670A322516B35329FC4DDF6566EE8CDE5F708957231
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fBxc-EsA.woff
          Preview: wOFF......$D......;.........................GDEF.......E...d...sGPOS.......g...J5...GSUB...D...5...6....OS/2...|...L...`w..jcmap.......Q....$V".cvt .......X...X/...fpgm...t...4......".gasp................glyf.......!..'....hdmx.......A...p.}..head.. ....6...6.Y.ihhea.. T.......$....hmtx.. t...$......%@loca..!.........N.Ximaxp.."`... ... ...\name.."........|..9.post..#T....... .m.dprep..#h.......:z/.Wx......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.|...eW.E.....m..6c.S..R\Fl.....Y.....>.{r..T...5k.U.<..NQ..g.{.2O9...(AfA.;..NS....y.$....`K.../...%zY.....P..t......'T....~V..=.....U.&.g..!.C.r..R.r..<.`..De*W.jT.:5.I.j.>:@.j..j....R-.r.....#..B;R.v.*,U5.n.[....j.9j...-.....{...9Y. ..h<...7.o...xe........A.h.i.r.r.}...h.>P.h.Q....R.=..Ub..~a.A..T.3..O5.:.f..5.....7...j...f....*.k.Y...}.C.u8...G"S.0......T:..._.h...8.V...^.~...#...T.A...~*...:p...G.h.t....M`..J%*.X....\.l.n..J.*..v:...H..q...Th.*.O............WHy._...T..1.....M .A<..m/
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmSU5fChc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15584, version 1.1
          Category:downloaded
          Size (bytes):15584
          Entropy (8bit):7.956227219725951
          Encrypted:false
          SSDEEP:384:cym1qTdOguw09ALdFkzWnUZYi2gUhufP+ocbjr+WN:cymYdEGXsWnKYiRfWxr+w
          MD5:C911FA7E4C52938B3DE84BEF22414385
          SHA1:6FA0CEA447DFD1DDC1A15C1A7AD874F0E582FF06
          SHA-256:B7FC1420D9B8697575A6D12666D3EE8D4C64C804C5DE828C9371B4A8766FE977
          SHA-512:3C7FC999AEF9F06F1AB0C0020ABEAA05E7B45A56A049ED9BF87F5FB9198673B34EFC01C230401AD364259219BD0C9633B94099B58BF29DBA66F760209DE42505
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fChc-EsA.woff
          Preview: wOFF......<.......s,........................GDEF.......5...@.`..GPOS.......6..../..FGSUB............N.K.OS/2.......Q...`t.B.cmap............%...cvt .......X...X/...fpgm...D...4......".gasp...x............glyf......-...Yr.)Vhdmx..60...j..../2D2head..6....6...6.Y.ihhea..6........$....hmtx..6.........:6[.loca..9.........C.-fmaxp..:.... ... .,.\name..;........|..9.post..;........ .m.dprep..<........:z/.Wx......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..3. W.........c.L..k.el....}...6...U..].R.W_{.-.g....`.}.8..]#.9_9$JP..}..9.m%.J)..nV.l.t..w~%*].A..`...V.WK....[.."..:.JK..S.F..t..m+Im..@Z..g9.f...."F..3...N..j...H.#..mq:!.8.A..!.....>.Y.....4.>.U.#..6..xu..i.[Nszf.&]8.(...E.v.....:5..t.J..}.iM.E..$R...o..Y.tG-.B.9...M.9. C!...gy6....m.w..=.!.{....2..C.3..#.2...7.D.L6.T.L...=.).x..^....m.z..>...}.S........}.{?...f.e.y.Xd.eVXi...Xk..6.U.Q..m.u..[.^}......[...........F....k9$.K.F+,S..Jm..)..F..[c...u....)..K.3..Z.....[..j.....7w.o.K..2."c.....B.T...n
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmSU5fCxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7164, version 1.1
          Category:downloaded
          Size (bytes):7164
          Entropy (8bit):7.8723706796583155
          Encrypted:false
          SSDEEP:192:Cc6BfVUrghKduRhbLgS3tujP47Mbgnqp8gvo:cfYdduvbLgS3tp70PNvo
          MD5:A8D6BB6196588127A93CE6E5EEEF39A2
          SHA1:8EFBAE4A7BB4B82851586CD25A098EB9FB40B43B
          SHA-256:7535AA82A08970F99DDA44CE9C50464A637914ABF23221ED6CAE4CCF5F7BF5A5
          SHA-512:94B078F6854840D3D9CCFB925346A05AB608BCE4932DF7E9072D2FC933A42932CB6B634CE0CDDA52CCEB5FF72C2C147251A6D0CE6BD857E5EF020B87AD8ABBC0
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCxc-EsA.woff
          Preview: wOFF..............3,........................GDEF.......'........GPOS.............P.0GSUB.......5...6....OS/2.......O...`t..?cmap...<........C.B.cvt .......X...X/...fpgm.......4......".gasp...L............glyf...X...?..$pP..:hdmx.......7.......2head.......6...6.Y.ihhea...........$....hmtx...(........8}..loca..............."maxp....... ... ...\name...8.......|..9.post........... .m.dprep... .......:z/.Wx..... ..0..Q*jj.eoN......8......x.'.x..%PEQ.E.}......\...h...C.{oH.D...V.|.sp..g.yz1@.d.......6..w..7u.v..v........... `T/....[x....a.W"(...r.......*...;....c.K...>=...}.r..Sr.f^.].,...<...DS...$RF3It..g..M:...!.*..>B...G/..}......NP..=..*...........<?h.;A.*.}{...yKI...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.g.a`e``..j...(.../2.1100.1.(00. .....3802).fc.....>....q>H..u....2.......x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.h.Z.`.V...N.n.....N.`.F.......`......
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmWUlfBBc-[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20356, version 1.1
          Category:downloaded
          Size (bytes):20356
          Entropy (8bit):7.972919215442608
          Encrypted:false
          SSDEEP:384:of+dt1ebKR28EPpAXxR5wthZZv4B8Te/h4+ctr5NH9NwZaUp4VsEgm:of+P1eeRcU8Hqdy+UHHbEw/
          MD5:ADCDE98F1D584DE52060AD7B16373DA3
          SHA1:0A9B76D81989A7A45336EBD7B48ED25803F344B9
          SHA-256:806EA46C426AF8FC24E5CF42A210228739696933D36299EB28AEE64F69FC71F1
          SHA-512:7B1D6CC0D841A9E5EFEC540387BC5F9B47E07A21FDC3DC4CE029BB0E3C74664BBC9F1BCCFD8FB575B595C2CC1FD16925C533E062C4C82EEE0C310FFD2B4C2927
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfBBc-.woff
          Preview: wOFF......O.................................GDEF.......G...d....GPOS.............~..GSUB.......'......r.OS/2.......Q...`u...cmap...\..........W.cvt ...T...H...H+~..fpgm.......3...._...gasp................glyf......;...k....hdmx..H....m....!$..head..H....6...6...\hhea..I,.......$.&..hmtx..IL...y.....XF.loca..K.........`.C.maxp..M.... ... .(..name..M........~..9.post..N........ .m.dprep..N........)*v60x...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x....dK...{....?..F?.|.~.m...ms.{.Z..;......U.]7s......\.=D.=.7...>....x...D..O|.U:...|o..3.x.j.r"B.............../.)x$.'"j.....1LGmaGxQxG....~.:'.A..hd.z,.k..KO.....^.}H|#z_.O......R..A...9..A..!.(./..."..:.Iq1.r..s..r.7r.7s..q.wr....nz..]...2..d4c..c....d....T.1...d....\....,c9k.g..Yv.#O."%...... ...t"uM..%.......j.#^.....}\c.q.i...<jy.D...C.01.2.r.....V..z.W.7b..L.S.41]..kUs.X/6..b.........(..(...K..{.^..'........`#./..B......N+p.m`...].lQ....Drg.M..Kx.^.S.*..........h ..$.k.'Hy.I.ze..4z.-T.....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmWUlfBxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9024, version 1.1
          Category:downloaded
          Size (bytes):9024
          Entropy (8bit):7.904393600637633
          Encrypted:false
          SSDEEP:192:drBlEdeAOL+XGS0cFhEvPoe1pOBWnpLanGSh9yFGSLTgEgm:TldAOL+2SlfEIe9npLanT/yESQEgm
          MD5:72F3618B634D40785278DBC792A2A38A
          SHA1:F22B6289E5B67867A54C9B91F4AA9327CA1F25DA
          SHA-256:ABCCD5EA59776E67FB063EC801DB2E8CF4E886157FB8EFDB961C9B4163316A92
          SHA-512:B6666D515B79AC83A65819BE9E0D5861104032740BB76AC9A10C649AD85F62950836B906181036DC27AD95E6BCE2600C0FF9DEE345E74948D4CF17CC62819782
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfBxc-EsA.woff
          Preview: wOFF......#@......9.........................GDEF.......E...d...sGPOS.......,....4...GSUB.......5...6....OS/2...@...M...`y6..cmap.......Q....$V".cvt .......H...H+~..fpgm...,...3...._...gasp...`............glyf...l...u..&.%..hdmx.......>...p....head...$...6...6...\hhea...\.......$.&./hmtx...|..."........loca.. .........B.K.maxp..!h... ... ....name..!........~..9.post.."X....... .m.dprep.."l.......)*v60x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.}.C..Y.....{e..m....`7....ms.}......<.&..J5....6f...wnZC..MKW..f.u..Cb..x..nZG0....@...+....y.E..../.....o^........{'..U.-.lW.h...l........F..d.I.9.G.E.RA.5....a....p.e...D&3.9, .\.D.EQa...RcAt..tS..E....a.$...c.~Unj.7U...x.4.t.N....G~..c.....v...~M. SZcO.#?D..).$..<Ev......=*..U..j.E..u..v..vA.<......c...3C.Yv.9..x...QB.,..B./.(!...c.]......S..P<G....J....-m.....].&L....W.[T..*..v!.)..4G..."{....\.A...n.]...*...(.?U......9.X..}.....M|C...v..U...t.>a..!HS.u.z...Buo...pu.S(....R"4yGx
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmWUlfChc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15472, version 1.1
          Category:downloaded
          Size (bytes):15472
          Entropy (8bit):7.962052578972593
          Encrypted:false
          SSDEEP:384:OwqltGLd/Vztaqblo2B8z+JrS+PdaKiVeCNc/8iXxuEgm:Ow+cvoIopz72TvCNcbxP/
          MD5:589F94CE3337722019E86473D557CFE0
          SHA1:208DEC609A1D1D0C8B81DF64A45D2B0722EE7B8E
          SHA-256:6B02689B1A4A4F6829213C7C454AD0BE61EA00F2DB6738FA8AAB5D1CD5949DD2
          SHA-512:A574E4344A2C3CFCE630C1A9593D2158BF121DF3722C0EF3BC3C2393A20AECE0554494973EA7A5F265665BE872E8BC9D65E7844F669EF49203DB5C9F5E60CAE7
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfChc-EsA.woff
          Preview: wOFF......<p......r.........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......Q...`vYB.cmap............%...cvt .......H...H+~..fpgm...8...3...._...gasp...l............glyf...x..-X..YP.B.hdmx..5....f....A?S8head..68...6...6...\hhea..6p.......$.&..hmtx..6.........] <nloca..8............qmaxp..:.... ... .,..name..:........~..9.post..;........ .m.dprep..;........)*v60x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOlCnqEu92Fr1MmWUlfCxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7172, version 1.1
          Category:downloaded
          Size (bytes):7172
          Entropy (8bit):7.864514620759078
          Encrypted:false
          SSDEEP:192:EgY1Ya+0CaX9RbywrQI32EncxkgvceIQmOEgm:Ef/XzxIEnUdpdEgm
          MD5:048C8C3D842D45A28AA4EC36D9ADFA24
          SHA1:FB1839F43CA412E1621415751A0E72452C23CA85
          SHA-256:16BA77C902557BB4254BCE50EACAAF3DC6636226C292D8451133E71EE7D0A0F0
          SHA-512:8000DFFE215867E63662034D00A97150BED197CDE5D56B5976AC0D1CC0D072AEDC9B69AF64F76C63664EC63EF596F1F3C674C1F06EB4237BB32EF49D34C74FCF
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmWUlfCxc-EsA.woff
          Preview: wOFF..............3.........................GDEF.......'........GPOS...............0GSUB.......5...6....OS/2.......O...`v:.Wcmap...8........C.B.cvt .......H...H+~..fpgm.......3...._...gasp...8............glyf...D...a..%.z...hdmx.......8.......6head.......6...6...\hhea...........$.&.Rhmtx...8........M...loca.............a..maxp...,... ... ....name...L.......~..9.post........... .m.dprep...0.......)*v60x..... ..0..Q*jj.eoN......8......x.'.x..5R.@.D.....p9.n........$8.Dh......]..UO......a......4=.k`.o..h..8.L."(@..M.c.O...6...@Y.1....[...o.y........."........{..}...@.W.]..4........N.XI..h...~....dJ....bV..E:m(...cEgJ....'.1&..t.........3.w.......c.T..n..H.....J.x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`fY......u..1...<.f........P.....,.............C..,&.... 9.+....@........x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.......N.`.1.......|.-.....`..... .!...:..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\bootstrap.min[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):37051
          Entropy (8bit):5.176369382454599
          Encrypted:false
          SSDEEP:768:72rGy27UwlNqMl95qNmCFejhqs8snmi+CSFXfgx8Gf3Zq7Q:yg73zhq0GvgJ3ZKQ
          MD5:04C84852E9937B142AC73C285B895B85
          SHA1:8FB8A9319055253D085EDFC3BB72D20F614EC709
          SHA-256:36460E494E4C628443AFDED40B2743B5EDE9A4A76FB4F7B9EF2345CC7E59FD64
          SHA-512:E27BE06BC898DCF893F06CC49CAFCBB6BA6E3A69106A89A500F6993E57600B3636392784811237A1A783967DBE05D57A0769C78F8074A0C3A59B16B655B1D350
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/bootstrap.min.js
          Preview: /*!.. * Bootstrap v3.3.7 (http://getbootstrap.com).. * Copyright 2011-2016 Twitter, Inc... * Licensed under the MIT license.. */..if("undefined"==typeof jQuery)throw new Error("Bootstrap's JavaScript requires jQuery");+function(a){"use strict";var b=a.fn.jquery.split(" ")[0].split(".");if(b[0]<2&&b[1]<9||1==b[0]&&9==b[1]&&b[2]<1||b[0]>3)throw new Error("Bootstrap's JavaScript requires jQuery version 1.9.1 or higher, but lower than version 4")}(jQuery),+function(a){"use strict";function b(){var a=document.createElement("bootstrap"),b={WebkitTransition:"webkitTransitionEnd",MozTransition:"transitionend",OTransition:"oTransitionEnd otransitionend",transition:"transitionend"};for(var c in b)if(void 0!==a.style[c])return{end:b[c]};return!1}a.fn.emulateTransitionEnd=function(b){var c=!1,d=this;a(this).one("bsTransitionEnd",function(){c=!0});var e=function(){c||a(d).trigger(a.support.transition.end)};return setTimeout(e,b),this},a(function(){a.support.transition=b(),a.support.transition&&(a.e
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\check-button-bg[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 50 x 176, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):854
          Entropy (8bit):7.628966732901405
          Encrypted:false
          SSDEEP:12:6v/7GVlGJyjVVKvkASeSvc3o6VkdmIYz8UdGe0MXTpgsxq+WOwfHZFCKIhkRduES:xTOvX2uo6K0SDIpgsxq+WFfXRRdli
          MD5:86A6B2D85F9F6059C43A8C03F30B0389
          SHA1:304DCEEED6683CC216B7A431005EE0E6C71B5B01
          SHA-256:43FF7D45A581F459A105BF642086282FEF9B9088F1B645CD2997E324B25C78BE
          SHA-512:BAC2814C408D5B12100CAD2A7A323D1B33161A351ACF92A574587E4507A99E237AC97F358AC29C0005EB4A4845D49AA6BFDCC080BB5CCC9F044E4759D9964946
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/check-button-bg.png
          Preview: .PNG........IHDR...2.........z..P...?PLTE@.Eu.L..OP.GK.F{.M..ME.F:.D..Ol.K..Ng.JY.H..Pb.IT.Hp.K].I1.:z.CZ.l.....tRNS.....................\.......IDATh..Y. ...h....}.g.....5.|.s9Zr.p.R!.W6.[Kn.!$Jn.[...9'.7...?.. a....6..c..m....K..tgo;..4.4.....D.RZQ......F.a.R....O=...o..{.UP..8)....u.3.r.. ...f.2s.IN|.C.l..q...BX#.%.,..6.H..q]._6ZIf..w..8.l....Z...F......f..J.wJ^.h*18..7...`.h$..H.7.52.n.b...l4....og.KIs....U}Y.<.).vt6.~t..........1..!..[...B....a...8..'o......sr.....Lsqz9?....l.t.....R.<)........b*...i....TY....*..p.MS.)...o....._.0B..................Nv..7$.F....}I.......O...........0....L.l..uO.x.1..d..R...{.,fr.it.ks.=%.....G.5......:...F.._c.].e..S .K.S.M...$B..]*.W5^>...F2..~.b.......}.S..=.U.Nl?..PTh....]...O.l..Y..x.}S..vJ..6.$.V...'6K}L....@.#...VS.[.]w......K.Y.f=[...y..N6...!.....IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\check-icon[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 43 x 41, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):877
          Entropy (8bit):7.199384563544088
          Encrypted:false
          SSDEEP:24:URRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRgCqObRR4A2xke2881lO:PCqIKxkL1BRngkGJDR
          MD5:55C79A1B22AABC679A4AFE16FF6A32D7
          SHA1:263DB61AB0AA421C1C1B95D241B1339E5DCA61BD
          SHA-256:4688EBF4433DF9C502A4B7D9BE10FFAE095C2B8F01975108FFF581CBC674B71D
          SHA-512:F1D9E0FE1D6AA361AD420B82F5C2DE67AB2E14A03567BAD73F10E1F80AF0A4C5CD77AA9C8CBE8DFA65B6D2E0E9A90BD60E6E5A821396DC5BED96EB413151794A
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/check-icon.png
          Preview: .PNG........IHDR...+...)......K .....PLTEGpL6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO6CO.....0tRNS..9.~.....+...A..aS...N".3...v...&..FYr..ofk./........\IDAT8....0.E.u..D....]G....<.m.9}*.LR.N*....gC..ZO.)........{y../..[....'.....)VU.=....-..:n.]<........U/H.iz.C.o...*....9@/..`.y.9.......4V@.~=..?....8..=..."...%.??M..0....<......>.O..L.F.uE\...........Z......@.......e....p.1pT....<..Pu...%.....X>.k...F,xw..\.dDL.('W...R......7.>Q..^.ZhF"...Y..%x..=.d.5~.e.e.."2Ku...e...x...@..;.9.;..(.L........E...$.-En0>.w...LD...A.j..gp....h....'.HP=........o.t.wWm9.Gg....i..........,v..;......O..c.}...<.7T..y..o.:....<..,..).A..=*`.Y.b..]....m...e.`....L..,_.0.(OV.I\(.g.>T...U].. Y.k..5..m.a...F..@W....mJ.j..?/.A...S/..[.......{SN......IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\close-button[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 18 x 17, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):295
          Entropy (8bit):5.905906866433798
          Encrypted:false
          SSDEEP:6:6v/lhPBllA+Ra4mwM5p2UiX9Y6iwf1Swl7J+8QSvjp:6v/7b64mwMfi1zPQSvN
          MD5:E4B8FB8F9488107514604220F4F326F8
          SHA1:2E55E60A61A6B9B52095EFF6C105AAFBE90A728D
          SHA-256:96A782161AAE5DB56AE571DA527ECF24618F3B26D8D8958DB1B33E5523C6D951
          SHA-512:4FE5067F9860791E54F8022C20FE5242CAC77AA3138CE31728B3274BC9267679FFACEAC11B9488F3343F51B4EBDC35B86915DCCDCBA6D9FA00352898C2D49965
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/close-button.png
          Preview: .PNG........IHDR...................EPLTE........................GpL..................................................tRNS...e.......mF@......l.}....{IDAT..E.Y..0......%....Z.........p><w.*"n..v%.7.QC{...V .^M..... .\.N.b..1.'.l.d..<...=c+hu.3...3..4@v..4,..u.:.?...L...K....IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\device.min[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):2606
          Entropy (8bit):4.929787743864095
          Encrypted:false
          SSDEEP:48:eKnN+tn3O+zUFyUAHK1dNzz1JhxHCrasMM89Dv4+E8eeHr0NTLCgg:3OAwaZ2ds
          MD5:B7B1E286E1DE210EF5031729AE4AB971
          SHA1:FA4AEA8C420B8C5D1FAAB2ADE1975E47E087F27A
          SHA-256:2D564B495EEEFEE92BD0C1612058FE2858973EF6BFD46F7A68EB7860FB262AA9
          SHA-512:0C4CE80D109ECA1CE136E708845D7669B72B61792994F261A657651F2AEAE8EA067A7F2E00B8924BD27B6ED2446F9240D1964C969955B4B201B48668BF57358B
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/device.min.js
          Preview: /*! device.js 0.1.57 */..(function(){var a,b,c,d,e,f,g,h,i;window.device={},b=window.document.documentElement,i=window.navigator.userAgent.toLowerCase(),device.ios=function(){return device.iphone()||device.ipod()||device.ipad()},device.iphone=function(){return c("iphone")},device.ipod=function(){return c("ipod")},device.ipad=function(){return c("ipad")},device.android=function(){return c("android")},device.androidPhone=function(){return device.android()&&c("mobile")},device.androidTablet=function(){return device.android()&&!c("mobile")},device.blackberry=function(){return c("blackberry")||c("bb10")||c("rim")},device.blackberryPhone=function(){return device.blackberry()&&!c("tablet")},device.blackberryTablet=function(){return device.blackberry()&&c("tablet")},device.windows=function(){return c("windows")},device.windowsPhone=function(){return device.windows()&&c("phone")},device.windowsTablet=function(){return device.windows()&&c("touch")},device.fxos=function(){return c("(mobile; rv:")
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\font-awesome.min[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):29047
          Entropy (8bit):4.751953428831453
          Encrypted:false
          SSDEEP:384:Bu5yWeTUKW+KlkJ5de2UYDyVfwYUas8l8yQ/8dwwdZ:6lr+Klk3Yi+fwYUf8l8yQ/eV
          MD5:EDB152BDD1A2AA675C8282574E797BD3
          SHA1:C3F536DEE929DFF49537096B6EF41AF9F7819C00
          SHA-256:286E7BA6F67F0443DE8C658916BE44F3F1EBD31C9364843E30C12D99A4B247CB
          SHA-512:A86BD6358905CC761A08CD94C759D0F92191856D837C138848751CDA9882DB03AD2277B8E1FB2AF316F5DC32E3F484ACDB8A8692D8A92267B60AA4B40AAE6451
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/font-awesome.min.css
          Preview: /*!.. * Font Awesome 4.6.3 by @davegandy - http://fontawesome.io - @fontawesome.. * License - http://fontawesome.io/license (Font: SIL OFL 1.1, CSS: MIT License).. */@font-face{font-family:'FontAwesome';src:url('../fonts/fontawesome-webfont.eot');src:url('../fonts/fontawesome-webfont_1.eot#iefix&v=4.6.3') format('embedded-opentype'),url('../fonts/fontawesome-webfont.woff2') format('woff2'),url('../fonts/fontawesome-webfont.woff') format('woff'),url('../fonts/fontawesome-webfont.ttf') format('truetype'),url('../fonts/fontawesome-webfont.svg#fontawesomeregular') format('svg');font-display:block;font-weight:normal;font-style:normal}.fa{display:inline-block;font:normal normal normal 14px/1 FontAwesome;font-size:inherit;text-rendering:auto;-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}.fa-lg{font-size:1.33333333em;line-height:.75em;vertical-align:-15%}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-fw{width:1.28571429em;text-a
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\getdetector[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):224
          Entropy (8bit):4.678388780195359
          Encrypted:false
          SSDEEP:6:E7EUygNFIlyGeqHnM3+mMt03+JOFgr7v6FgUrAen:ZDlzM3+J2UNUv
          MD5:16B2815AF2AD51004BE9316D30FA3FC1
          SHA1:75441594FE385CA984C4AB5128A5DB579E675A9A
          SHA-256:37589FB05F8577887697102CB8ED962EC86D78D8135AA58BFFF55E7CAF20EC11
          SHA-512:0BF56FFA662EB4FAEAA78BADD683BADB14394DC1631516061DF71AE16411269F75A9DE80CC63C33D3C5FC0EB37E09D0A3E6873EA3DF01CD9BA03D0BB1A28C979
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/getdetector.js
          Preview: $.urlParam = function(name){.. var results = new RegExp('[\?&]' + name + '=([^&#]*)').exec(window.location.href);.. if (results==null){.. return null;.. }.. else{.. return results[1] || 0;.. }..}
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoY9NfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 16636, version 1.1
          Category:downloaded
          Size (bytes):16636
          Entropy (8bit):7.952843027444461
          Encrypted:false
          SSDEEP:384:udx/ajOwSmmbhcytPnvEMt0ZTfZxFM2sbZuYFqFxOoBtbN:udEjObk1xgbZSXbN
          MD5:6F629E38286ED542D09317F2BF52C9A3
          SHA1:F82342E521DED70842641CEF45BBDFB62AC048B5
          SHA-256:36E2E191EADC9295579B4A071746CBDEA2A9602762AFF7211DA3762C07A95463
          SHA-512:C70FD89607C158707ECB3312CD302CBC059A9D36C05976E6633CF4D5D2DFFCF943DB19600C2C67B9E6DE375B504BF6BEF0DD338AA4E573159670290C1FFEA881
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoY9NfQyQ.woff
          Preview: wOFF......@.......w.........................GDEF.......5...@.`..GPOS.......6..../..FGSUB............N.K.OS/2.......P...`t.A.cmap............%...cvt .......X...X/...fpgm...@...4......".gasp...t............glyf......1...]x...6hdmx..:D...c........head..:....6...6...hhea..:...."...$....hmtx..;.........8.loca..=............hmaxp..?.... ... .,..name..?$........&.D'post..@........ .a.dprep..@ .......?.1$.x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..3. W.........c.L..k.el....}...6...U..].R.W_{.-.g....`.}.8..]#.9_9$JP..}..9.m%.J)..nV.l.t..w~%*].A..`...V.WK....[.."..:.JK..S.F..t..m+Im..@Z..g9.f...."F..3...N..j...H.#..mq:!.8.A..!.....>.Y.....4.>.U.#..6..xu..i.[Nszf.&]8.(...E.v.....:5..t.J..}.iM.E..$R...o..Y.tG-.B.9...M.9. C!...gy6....m.w..=.!.{....2..C.3..#.2...7.D.L6.T.L...=.).x..^....m.z..>...}.S........}.{?...f.e.y.Xd.eVXi...Xk..6.U.Q..m.u..[.^}......[...........F....k9$.K.F+,S..Jm..)..F..[c...u....)..K.3..Z.....[..j.....7w.o.K..2."c.....B.T...n
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYtNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7680, version 1.1
          Category:downloaded
          Size (bytes):7680
          Entropy (8bit):7.877001759058416
          Encrypted:false
          SSDEEP:192:eABfVtWbOctL/lkHE+iOG4AMcP+C4O/EWjN:XfGbXtWkFO1AMcWXOBjN
          MD5:1A45255FCB4D7D286EACFDA3C5290DDE
          SHA1:984988002147C970468F48A565AAB20B7DF5EC3F
          SHA-256:A98F8AE836C860B3ADE907A4878F8B30F32EBC3216002CBCF5848B73B53988B7
          SHA-512:74EE20542ECBB71819B09EE9600E0068A557EE30A3201304B230876301FECFF74A1A34181F7E5842C7425690EFEF06A7DB633B26AC679756DDA7A9B6971359AD
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEoYtNfQyQ.woff
          Preview: wOFF..............4.........................GDEF.......'........GPOS.............P.0GSUB.......5...6....OS/2.......N...`t..ecmap...<........C.B.cvt .......X...X/...fpgm.......4......".gasp...L............glyf...X......%./..Phdmx.......6........head.......6...6...hhea......."...$...-hmtx..............!Zloca............2.).maxp....... ... ....name...(........&.D'post........... .a.dprep...$.......?.1$.x..... ..0..Q*jj.eoN......8......x.'.x..%PEQ.E.}......\...h...C.{oH.D...V.|.sp..g.yz1@.d.......6..w..7u.v..v........... `T/....[x....a.W"(...r.......*...;....c.K...>=...}.r..Sr.f^.].,...<...DS...$RF3It..g..M:...!.*..>B...G/..}......NP..=..*...........<?h.;A.*.}{...yKI...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.M.5..P....2z..u...q.O.,%d'.w?cL..8pgw....d$...'`.C...JiyyjH.Y#...=.?.`Z...=..x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.h.Z.`.V...N.n.....N.`.F.......`......
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYNNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21364, version 1.1
          Category:downloaded
          Size (bytes):21364
          Entropy (8bit):7.97145447425
          Encrypted:false
          SSDEEP:384:ZX2BKWN5+RBSI/GYJBUiaVzqDBV02NLTMlxTcaXNBEiAhCYpY:BJk5Y/GEtaVzqhBTMlywNSTppY
          MD5:654F170089CF0406E20C40618CABB754
          SHA1:9930EDD5499757B81533456CA46767173AAE4339
          SHA-256:E7DD0A3641CBD4E262149772A9B9C3A3702FB15DAB63693D62E02E2C0A9302BB
          SHA-512:6092A03A1C0FC971D7C8DCDBEC0C94C32D77A261B318199E308089B8F45B11F8B35B7DEA90A302D5C798DBEDFE3B92D832452EE3F65A21D6429A9C85B3F9A16C
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYNNfQyQ.woff
          Preview: wOFF......St................................GDEF.............~..GPOS.......1...BqmeEGSUB...P...5...6....OS/2.......M...`{..#cmap............S.(Ncvt .......L...L0..Gfpgm.......3....g...gasp...H............glyf...T..A...vt...hdmx..LL...i......+.head..L....6...6...hhea..L...."...$....hmtx..M.............loca..O.........U.7.maxp..Q.... ... ....name..Q.........%.Czpost..R........ .a.dprep..R.........=...x............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x.....I..O...?/ccm.f.l.m.m.c.H6...tFk..R...9....I>=.7.......G[...Y........wW=*...\.S..].,".s%...-G.E.nW.0g.s..|.t.W...X%<...*c...U.Q........^L\../...&...P.5...>S3.T+.V[..~O..(..8M.dM.:m.6m..........>..q..y].U].u..M..m.(A.JS.2..W..Xu.'5..5.4.J..~...|.T.Kc.].x.T..-"....l.f.0..x.C=.v.u...8.W u..S..X3y./&...=....E..}.f(\....|[...S..p)..M......U.F"....j....>....T;....E..CV...5..-~1hF.....t...f=..vf=..;Qo&... |".8C..p)P...E&.D.....i.^...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYdNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2176, version 1.1
          Category:downloaded
          Size (bytes):2176
          Entropy (8bit):7.218218672925617
          Encrypted:false
          SSDEEP:48:X50Sal9vYgE/3wwK/5WpxCSCMpWt73bpQg:X50Sa/vek/5S/rpu
          MD5:8233D22A4456479E2EF1AD1DA82A39C0
          SHA1:B6E31AD7A97A2BE9FA561734EE0E93D61448F14D
          SHA-256:0FDFF124087F43D176B5F24EF3DC123D24548CEAEFCD7EC584F942CD9D597DE3
          SHA-512:9521F8236F2EE3E236650BE959A3848B9C8D6EAF2C2B37EA05BDFC9E314D650AF0CDDD3FCAC680D2D67153AEE7D534F0BDFB9CFB77423E6DEC67F6EB46B1C29B
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoYdNfQyQ.woff
          Preview: wOFF........................................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...M...`...]cmap.......7...X. ^.cvt .......L...L0..Gfpgm.......3....g...gasp...L............glyf...X........u...hdmx................head.......6...6...hhea...@..."...$....hmtx...d............loca...............?maxp....... ... .7..name............%.Czpost........... .a.dprep............=...x.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.b......:....Q.B3_dHcb``.b(p`@.........l......g11(00...X.n`P.Bf..L.I...x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......N.`.1.......|.......`..... .!...:..................................x.]..G.A..g.."@.....q....G...0_...].?......w.=.~........y.}>./..b...Oj.....z.<..p-e.L....4.H..ZN..[..t.]....9.M.X8.K....;..... .2.....8..V.f.._..z*.\...L....R2.:.X.B.....>.g......A.g(,..F..Z.P:'\D
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoadNfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 13556, version 1.1
          Category:downloaded
          Size (bytes):13556
          Entropy (8bit):7.951008436184045
          Encrypted:false
          SSDEEP:192:XuYmfe+aogLdlbDvej9D5s9ho6ND0aWYJPJm9J4jzFGSm0kvYyGjoPDqduZLdTK2:XnMgd1WUIK184dNjC4MLzdTYBLhbhY
          MD5:9090827E5E3162DE339783C3D9B7CF98
          SHA1:B8BA83B2B39769951664CE274495838388D0EE81
          SHA-256:30784C2F1917EDFD5CB3486D00E417E88005B2A55436CB72976CC5DCACD23ABB
          SHA-512:8560159C1701B329497DBCCE3B90B83ECBD8CF9A6D3396B4CFCBF32853B9203C66717E50414B3C0BF3182298BC07274AF965BBFA6631CE2CC84798DCC0DD1DD6
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoadNfQyQ.woff
          Preview: wOFF......4.......^.........................GDEF.......J...j...tGPOS...........z...CGSUB...h...5...6....OS/2.......N...`{:.&cmap............d..1cvt .......L...L0..Gfpgm.......3....g...gasp................glyf...$..#...B4..,.hdmx../....L.......(head..0....6...6...hhea..0L..."...$..."hmtx..0p........1...loca..1..........}..maxp..3.... ... ....name..3$........%.Czpost..4........ .a.dprep..4(........=...x......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x.,.CB.Q..._.d.m.m{........Fm#..7..?./P....@.kh.#d.xg....UB..6.A....i...........*.......B.J.../.E..e....m~iO.......K...o.f`..{r.0.o..."BT..a.k.d..YrG<;.o.#UY&[...r.......%.x.H$.dRH%.t2."..r.#...)...J)..z.h..V..^..d.1&.d..f.c.eVXe.M..f.=.9......s.e..V...?....'...n..s89..S.6T.K'8fffff...Q..}Z=YN..X.........|......b.1..&.>..;..7M........U...C..?t:..R.......:.....L[...&.Y..P.5P.!.I..Fh.0.B.L!>B.^..a<............|...T...s*..._...j..Z...G7B.....`.9"..%....j1z...J{V.T.X>...M.j.TB5.@-.l.....ah
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCcYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9076, version 1.1
          Category:downloaded
          Size (bytes):9076
          Entropy (8bit):7.910674698395474
          Encrypted:false
          SSDEEP:192:QzBlEd39RQl1aPawKStrasm5Dl7c7SLI1aouth7Z/:+lIAaaQtU7cATJ
          MD5:A4274D0C2278504C5B8A9EB4D1842604
          SHA1:A2ECC942D303D9D4073D5ECD1954B154F465DF94
          SHA-256:598EEAA89C5904D5A934151C8A28878A364047FB975653F4A09604CD13E2BF8E
          SHA-512:89C19E3B0E445208079D84470D752A9AC19C59917FE2AD8A6188907EE2C1C89D5FCE167ED4B98F9849AD696A06A15946A46740A423144400882F23D4D91BF429
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCcYactd.woff
          Preview: wOFF......#t......9.........................GDEF.......E...d...sGPOS.......,....4...GSUB.......5...6....OS/2...@...M...`y6..cmap.......Q....$V".cvt .......J...J.V0Xfpgm...0...3....c...gasp...d............glyf...p......&.o.f.hdmx.......@...pvvv.head...P...6...6...hhea...........$....hmtx.......'........loca.. .........>.G.maxp..!.... ... ....name..!.........!^?.post.."........ .m.dprep.."............x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.}.C..Y.....{e..m....`7....ms.}......<.&..J5....6f...wnZC..MKW..f.u..Cb..x..nZG0....@...+....y.E..../.....o^........{'..U.-.lW.h...l........F..d.I.9.G.E.RA.5....a....p.e...D&3.9, .\.D.EQa...RcAt..tS..E....a.$...c.~Unj.7U...x.4.t.N....G~..c.....v...~M. SZcO.#?D..).$..<Ev......=*..U..j.E..u..v..vA.<......c...3C.Yv.9..x...QB.,..B./.(!...c.]......S..P<G....J....-m.....].&L....W.[T..*..v!.)..4G..."{....\.A...n.]...*...(.?U......9.X..}.....M|C...v..U...t.>a..!HS.u.z...Buo...pu.S(....R"4yGx
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCoYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15376, version 1.1
          Category:downloaded
          Size (bytes):15376
          Entropy (8bit):7.959969151528919
          Encrypted:false
          SSDEEP:384:BAqOMYXi0dbRhC4OCzdJ0C6OU+QXEjdyTs4sK4sJ:BAfXjbRhC5jCzTkTjsK4K
          MD5:C8CFD6F5855C2DBCBDDEA03E25160DAF
          SHA1:E4201E16A6270398229F5751D1CB5EBD5DD8D8C3
          SHA-256:B37F649F9AF347053BF2641D06506CE667DEBA9A316AC12CAC6335DBEA3F045A
          SHA-512:AD8BFF5618A7298DBC7FF72228DB24E281C12B21168112D8A6662DE273498660F415D41C77837F73933693731FAFA3AF587041F8F0045B1F756929943EB46E20
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCoYactd.woff
          Preview: wOFF......<.......q.........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......P...`vYB6cmap............%...cvt .......J...J.V0Xfpgm...8...3....c...gasp...l............glyf...x..-...W..*..hdmx..5|...c......%.head..5....6...6...hhea..6........$....hmtx..68.........b>oloca..8H.........i.\maxp..:4... ... .,..name..:T........!^?.post..;4....... .m.dprep..;H...........x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCsYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7252, version 1.1
          Category:downloaded
          Size (bytes):7252
          Entropy (8bit):7.87545668979266
          Encrypted:false
          SSDEEP:192:EYh1YaMumISZStddlZ8BTnjaL2tV946uaqEG3wffh7Z/:E2qISrLjCSVu6nrx9J
          MD5:44C6560DE42698FFC1A7D43F171B57F9
          SHA1:C161B38BF31368224F26CA3145A82C8783A60005
          SHA-256:6E93CCA2DEC33FC1DAE2F74CABF3DA544CE75ACD19D0E8DEA6B875A4BABFA51D
          SHA-512:235CC642858223F2F5D7CA7EDC5710B6F115E1C2893CFDBBD80C9317A4BD40B64F165610F199EA892FAADA245A11AE92886ECAC95E29043026C83CC98864B72F
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-32meGCsYactd.woff
          Preview: wOFF.......T......3.........................GDEF.......'........GPOS...............0GSUB.......5...6....OS/2.......N...`v:..cmap...8........C.B.cvt .......J...J.V0Xfpgm.......3....c...gasp...<............glyf...H......$D(n..hdmx.......7........head... ...6...6...hhea...X.......$...-hmtx...x............loca...h...........Lmaxp...x... ... ....name............!^?.post...x....... .m.dprep...............x..... ..0..Q*jj.eoN......8......x.'.x..5R.@.D.....p9.n........$8.Dh......]..UO......a......4=.k`.o..h..8.L."(@..M.c.O...6...@Y.1....[...o.y........."........{..}...@.W.]..4........N.XI..h...~....dJ....bV..E:m(...cEgJ....'.1&..t.........3.w.......c.T..n..H.....J.x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.M.G..@.E.v..x.-.8..O..P.`.A.>.;.^t...t7P..MC...v..<Dq.!JK.. .O..~...*......8..x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.......N.`.1.......|.....`..... .!...:....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCcYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9140, version 1.1
          Category:downloaded
          Size (bytes):9140
          Entropy (8bit):7.903298972716609
          Encrypted:false
          SSDEEP:192:KYtuos3uGeVE5LPhixDonZc2xDpa9GbVnJ9oty+a187ak8GnxNx5c9QP1s:2orGeVE57hSgc2wGbVUSuzxG9QPS
          MD5:A0558B531B67223E2674A9B5C1BB8ED1
          SHA1:4CCFAEE942EA7507F6001D7064902F1D548565BF
          SHA-256:451D26A48AFCED0630BBCA4BB4C92B76571AC51027F79527EA5DFD56253EBAC4
          SHA-512:D5043258B8B85096439748C6251279D59FF86D7FA53D9B0675D409CE0FB5BB851D2A82022A79CF7D78B3CCBA95CE02B8483015D9C0395EBA19BC3E0C1A6E82CC
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCcYactd.woff
          Preview: wOFF......#.......:,........................GDEF.......E...d...sGPOS.......g...J5...GSUB...D...5...6....OS/2...|...M...`w...cmap.......Q....$V".cvt ... ...X...X/...fpgm...x...4......".gasp................glyf..........&.g.hdmx...H...=...pqns.head.......6...6.*.hhea...........$.z..hmtx..............%.loca..!.........@{I.maxp..!.... ... ...[name..!..........s=rpost.."........ .m.dprep.."........:z/.Wx......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.|...eW.E.....m..6c.S..R\Fl.....Y.....>.{r..T...5k.U.<..NQ..g.{.2O9...(AfA.;..NS....y.$....`K.../...%zY.....P..t......'T....~V..=.....U.&.g..!.C.r..R.r..<.`..De*W.jT.:5.I.j.>:@.j..j....R-.r.....#..B;R.v.*,U5.n.[....j.9j...-.....{...9Y. ..h<...7.o...xe........A.h.i.r.r.}...h.>P.h.Q....R.=..Ub..~a.A..T.3..O5.:.f..5.....7...j...f....*.k.Y...}.C.u8...G"S.0......T:..._.h...8.V...^.~...#...T.A...~*...:p...G.h.t....M`..J%*.X....\.l.n..J.*..v:...H..q...Th.*.O............WHy._...T..1.....M .A<..m/
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCsYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7172, version 1.1
          Category:downloaded
          Size (bytes):7172
          Entropy (8bit):7.875293186284016
          Encrypted:false
          SSDEEP:96:EapQ+BfViUCfpxmWyZheMv6K0exdqROmsxiOvoeEzNwU7axHeWugRR5KZyHcjYul:E45BfVirfRynbSbkT3vYzNRe5RRslUs
          MD5:2D403E49D44CEB71C8FD69043535C8EC
          SHA1:B41AFF9A23F6B0097D6DDCD3132B51342D08492E
          SHA-256:3AE8ABE49129ADD4D86FD06312428AE6F5A26F6BA7D143EE88789ACC53D74B34
          SHA-512:1465A2248E4C86ED1B5170C2533736FEFC904837A922A7E35CE09AF8B834EE1B319567FC018A8AA9976F3B1DCAFD15CA75CE580B5AC45CDEED614CC7A9B0B224
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCsYactd.woff
          Preview: wOFF..............2.........................GDEF.......'........GPOS.............P.0GSUB.......5...6....OS/2.......O...`t...cmap...<........C.B.cvt .......X...X/...fpgm.......4......".gasp...L............glyf...X...;..$...6.hdmx.......5........head.......6...6.*.hhea...........$.z..hmtx...$..........0.loca...............mmaxp....... ... ...[name...8.........s=rpost........... .m.dprep...(.......:z/.Wx..... ..0..Q*jj.eoN......8......x.'.x..%PEQ.E.}......\...h...C.{oH.D...V.|.sp..g.yz1@.d.......6..w..7u.v..v........... `T/....[x....a.W"(...r.......*...;....c.K...>=...}.r..Sr.f^.].,...<...DS...$RF3It..g..M:...!.*..>B...G/..}......NP..=..*...........<?h.;A.*.}{...yKI...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f~......:....Q.B3_dHcb``.b(P```A.p..wgp`dRX.....!.}..P..|........ d......x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.h.Z.`.V...N.n.....N.`.F.......`......
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\it[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:HTML document, ASCII text, with CRLF line terminators
          Category:dropped
          Size (bytes):162
          Entropy (8bit):4.43530643106624
          Encrypted:false
          SSDEEP:3:qVoB3tUROGclXqyvXboAcMBXqWSZUXqXlIVLLP61IwcWWGu:q43tISl6kXiMIWSU6XlI5LP8IpfGu
          MD5:4F8E702CC244EC5D4DE32740C0ECBD97
          SHA1:3ADB1F02D5B6054DE0046E367C1D687B6CDF7AFF
          SHA-256:9E17CB15DD75BBBD5DBB984EDA674863C3B10AB72613CF8A39A00C3E11A8492A
          SHA-512:21047FEA5269FEE75A2A187AA09316519E35068CB2F2F76CFAF371E5224445E9D5C98497BD76FB9608D2B73E9DAC1A3F5BFADFDC4623C479D53ECF93D81D3C9F
          Malicious:false
          Reputation:low
          Preview: <html>..<head><title>301 Moved Permanently</title></head>..<body>..<center><h1>301 Moved Permanently</h1></center>..<hr><center>nginx</center>..</body>..</html>..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\logo[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 217 x 34, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):1028
          Entropy (8bit):7.54772465661022
          Encrypted:false
          SSDEEP:12:6v/7JlBZnp969J1g5PNIwakvzWhsMnMLbu6sQ/U0mpZncyxEU79z6T5OBHL/WmEn:Iug5zLWGsMuVv0anciEUZzU52LbESw/N
          MD5:2F6EFD43AFF012D240490E2F6E01B03A
          SHA1:CA9F0A8FDF38A6D8F232C9E03B45736B8DAD2C16
          SHA-256:B23DBC29BD5900E3EEE27EBD86190E633EA00B92CFF504AA518450E950B5E894
          SHA-512:2596D02B3CAC48CB57BC2B8F4256D1A37157058FF128516BFD7A23A31FE8DCCD4A58D609D4CF9333DE60B91990C66A0440AEA9EA7D3EED9EC632FFC87AEBCB6D
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/logo.png
          Preview: .PNG........IHDR......."......5.....fPLTEGpL<<<<<<...<<<<<<<<<<<<<<<<<<<<<<<<<<<...<<<...<<<<<<...<<<....,,..........ff.RR....!!....AA...........0....tRNS.wf...D".U.3.....6...;IDATX..m......,.dm2.......~.\..Y9..zRG...~.........H.q...D-H.....c2....j.1..S1..v....CU~.&.........'.w.z.f..Fa.k./...Yn...*.S..W......\.V##..-h~N.......G........f&%kd...P...I._......%..^*.u..f.=..4.)}..~...7.D.O.@x..zs]T:5$.NA..K.Fv..L.......`!...>JI. ........Y.u].f20r..xY.d.jZ..."=.".q.s.l....U.m..P&.%2......y.,.7(.s.f.Y.<.'J......V!c..F..6.|W2g..1.9...C...V.^dn.A..d../.FFu.{...#(Z.......H=5.FW....y}<..9O...DFT.&.)."w${{r`o-{....h%2fd.......t%;>:.K.i.6.+Z...9.f......L..4..<..K...(.+Z.L.+......n`.w.O.vn. !`.V$...........Y.S.m...:E+.....XP.Nd...&..\.S..dcG....k.?...Qo..1..dmd.,.".~dT.&[?..pj.V....O.^..dT......KS.@.T{...d.u.Q..l+.v%.R.YO/..J.5T.X.Hr...w.r......7.JfKPR...y.2."..J.U....c..m..H....d.~_..`.X$c...$Q.:.......<On.>Kd.I%..N.....I.Wn.2..o...Y.[..?.d.......dc.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\money-bg[1].jpg
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x450, frames 3
          Category:downloaded
          Size (bytes):95329
          Entropy (8bit):7.964039938616045
          Encrypted:false
          SSDEEP:1536:mcEX9Rw57xW8hlgNII/fucXJqUhVje+m1hMWAAkbxB7gUJevcYq2UjF/9WiLl7yU:mcEX9SZDuII/ffbhVy+mpkbxB7gUJeUr
          MD5:C471AB03127C3A278DEEFB8D63EEE613
          SHA1:B8B65BF9D1329A788C535378761B5033D68AC40B
          SHA-256:58B6B57E550E707C65F2A17026503EFE7A9271C64926E759BC96AFA28E974435
          SHA-512:A66C40268B85331963C4317D85E3800B7EC9AB54C5C72A2F24ABC89D6D07E1582C821383A909E4CE134AA42B7E2CD5E672AC7D4C91EFB49BE2F8A04AB70AEA84
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/money-bg.jpg
          Preview: ......JFIF................................................................"..."*%%*424DD\.................................................."..."*%%*424DD\..........."..................................................w...t.rS..D..C..[...Y.....WB4m.w.E-L.k...j..b.XN....,9#u...Z.........k%%=...m..X.B....d..Z6)P4...V.Y..>..R.....E1.L.5..SZ.r.^.....>.rD.e..".m.Q.%"..VF..U.;....0.ZTh.vFj".HiEs....."..82.....{5L.."......F#,s.;.L0.~....`...........dWJ.....2b....(*..U...g;.Cc*eK....9iK.P..v.T.f.....ZL.r...f..y\...u..1...M..n.C.cw .............=........NCa(.:.3i...iR....v.......r..Q]Mo.h.x.:.y..&(l(*...F.l....[E.<|...Y.GI...PP....^K.4.3/?...4..f.].......Z.si-."...*.gj2..f.MC.p.......m..i..9..H..^.<..M.....h."h9...3....+....:f4...i... ...T.;.C...SF.....Nn....1.#..U....x$^......z..Ob.f.S(..B..[.m.1.....!..<.:.A::.T..: C...o..j.Lh...B.]# *.cC.k.*..*..&..P.`/,..dv.."...2....].V..IP....V.xmq4....T....#...E.m5.+^.A1Z...t....D.T5.Y......Y..9u...S.......R......Q
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\privacy[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):8001
          Entropy (8bit):4.637875978270753
          Encrypted:false
          SSDEEP:192:SIwLkSc82J+s0iJH2TkdWShB/Tm9ByZ4T:SIwnA3GkdbX/q9UZY
          MD5:988ED6374C5C7B402A06A4F24F0298E1
          SHA1:39D9C97B5459B547C0CFEC0D0D7CC80A991D0946
          SHA-256:FE40A60ACB7639A26516D984AF687B5BDEB5E232C29DDA1A8D5EBA7C6DA515F2
          SHA-512:BAE940175E93F5D460DC9652BAF02CD6FC336C74F3C67D1A6720895AF1BE675B6CA9ACAA4A51AAD2AFE9A35DA630CFEA4DAA4A88321E430BE8920073C45D40E9
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/privacy.html
          Preview: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>.. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">.. <title>Privacy Policy</title>.. <link rel="shortcut icon" href="favicon.ico">.. <style type="text/css">.. .. body,td,th {.. font-family:Arial, Helvetica, sans-serif;.. font-size:14px;.. color: #111;.. line-height:20px;.. }.. body{.. background-color: #FFF;.. margin-left: 0px;.. margin-top: 10px;.. margin-right: 0px;.. margin-bottom: 0px;.. }.. a {.. color:#111.. }.. -->.. </style>....</head>..<body>.... <table width="1100" border="0" align="center" cellpadding="0" cellspacing="0">.. <tr><td>&nbsp;</td></tr>.. <tr><td height="70" align="center" style="color:#111; font-size:24px">Privacy Policy</td></tr>.. <tr><td align="center">&nbsp;</td></tr>.. <tr
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\reset[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):1002
          Entropy (8bit):5.06492397311216
          Encrypted:false
          SSDEEP:24:7L97BVhyUD8+XR8jc7ovXUAWMTheTzxd0itv5as4PO:7NPhyWB8jc7yXVsTzxd08v5F
          MD5:C53C09C3BD34CD8480C1408A303BF619
          SHA1:6B9D92F9500E2A8786A710A49D7EBD420B210AC8
          SHA-256:8F2D1DD23403EA4E25B8CC30EDB184DECE1C4463816B106130E842B59D67AD22
          SHA-512:EAD9EC4913E03A47E4BB34AB51EADD864F0C13560316981474B948B0FA97221D2188C47EF75B198155090623BD0C8819C2116F21095B742F8F4FA629FBE53EF2
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/reset.css
          Preview: /*..Copyright (c) 2007, Yahoo! Inc. All rights reserved...Code licensed under the BSD License:..http://developer.yahoo.net/yui/license.txt..version: 2.2.0..*/..body,div,dl,dt,dd,ul,ol,li,h1,h2,h3,h4,h5,h6,pre,form,fieldset,input,textarea,p,blockquote,th,td{margin:0;padding:0;}..table{border-collapse:collapse;border-spacing:0;}..fieldset,img{border:0;}..address,caption,cite,code,dfn,em,strong,th,var{font-style:normal;font-weight:normal;}..ol,ul {list-style:none;}..caption,th {text-align:left;}..h1,h2,h3,h4,h5,h6{font-size:100%;font-weight:normal;}..q:before,q:after{content:'';}..abbr,acronym {border:0;}....em {font-style: italic;}..strong {font-weight: bold;}.....preloader {.. display: none;.. background: white;.. position: absolute;.. top: 0%;.. bottom: 0;.. left: 0%;.. right: 0;.. z-index: 5;.. background-image: url(../images/preloader.gif);.. background-repeat: no-repeat;.. background-position: 50% 50%;.. opacity: 0.5;.. /* margin: 0 15px; */..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\spots-arrow[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 183 x 114, 8-bit/color RGBA, non-interlaced
          Category:downloaded
          Size (bytes):5306
          Entropy (8bit):7.869515991260547
          Encrypted:false
          SSDEEP:96:Pk2eQhWOQNNgeo1fW/a20Cosq8Njl3itb9q41biA3/yvQRlw1ct2tGLLmSoXPNVI:1hNWgHel0CopExyo41bx/Lv+twMD+Z
          MD5:32ACDF2CCE46993B09041EBED9D00140
          SHA1:8FAEE19E63F4D39B2C567FB7C9DEFA9F668C12C7
          SHA-256:7C01610E53CBE2313BD441CD9182762CEC4240E4EECEBECA6D086F34E4672784
          SHA-512:522A2C1BCFCA1AF21B01B29E20AC4DE75C863BC1BDAD0D2144652A5C31BD33D7D1B26255A4EE070EA2B51F6897A5E607DEA63E0FFADF0F861A46F4A294A1E16C
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/spots-arrow.png
          Preview: .PNG........IHDR.......r......K@.....tEXtSoftware.Adobe ImageReadyq.e<...&iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c067 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)" xmpMM:InstanceID="xmp.iid:7C23FC0C8DCE11E59DF2A0543018A9C1" xmpMM:DocumentID="xmp.did:7C23FC0D8DCE11E59DF2A0543018A9C1"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:7C23FC0A8DCE11E59DF2A0543018A9C1" stRef:documentID="xmp.did:7C23FC0B8DCE11E59DF2A0543018A9C1"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>.a?....*IDATx..].........>8......e.V@P.%1A..>.5/1Oc....Q.y.D....KP..$/O1@^...p.=.3.,."*.r...;G.........g`.....3..]
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\styleCustom[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):1191
          Entropy (8bit):4.989515855329045
          Encrypted:false
          SSDEEP:24:tIg5nomA5WpDE3qilQ8aixPcxiOybdxiOW5pSLxil+DmfFEQ:th5s5oE3ZlhGiOeiOW5pSVigDqFN
          MD5:E198C920314F40AA1FFC9F85DC838EC1
          SHA1:AD89A7EA67082CAB5262E5C8016ABC57074EA661
          SHA-256:0BD50AA5D38A7C9B5FBB439734F3EE62010808CBBB134DEDBAAA75E510408B57
          SHA-512:099E1165AFDA08CED45A804D60627B3CEFD76969DEEBC65F82BFE90A42538C223F7C75AC386CEBC29087C49B548EF12233E8CD3B789DF0CEF21503D783856B61
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/styleCustom.css
          Preview: #WholeName{...color:black;..}..#WholeName:hover{...background-color: transparent !important;...cursor: default;...color: black;..}.....modal-backdrop , .signup-widget{...z-index:1!important;..}...video-container{.. cursor:pointer..}...playpause {.. background-image:url(../images/play-button_1.png);.. background-repeat:no-repeat;.. width:100px;.. position:absolute;.. left:0%;.. right:0%;.. top:0%;.. bottom:0%;.. margin:auto;.. background-size:contain;.. background-position: center;...cursor: pointer;..}....@media (max-width: 700px){....#logo a{....margin: 0 auto;....float: none !important;...}...}..#termsModal, #privacyModal {...font-size: 14px;..}...loadingoverlay{...z-index: 2;..}...home-link{...display:none !important;..}....stream .bmpui-ui-skin-modern .bmpui-ui-hugeplaybacktogglebutton{...background-color: transparent!important;..}..stream .bmpui-ui-skin-modern .bmpui-ui-hugeplaybacktogglebutton .bmpui-image{...background-image: url("../images/pla
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\Digital-7[1].eot
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Embedded OpenType (EOT), Digital-7 family
          Category:downloaded
          Size (bytes):29748
          Entropy (8bit):5.787695194770183
          Encrypted:false
          SSDEEP:768:nB/6ui+6uS4jauieA5zcY5w6MP9ab0P76MP9ab0PHbav3A:B/6ui+6uS+auiedYCPsYPsbv3A
          MD5:CE82E91C4A952E33C8F0A0B9B4CB9741
          SHA1:231FA40D2DC5DE1BC6369C995C7D81399F674B88
          SHA-256:AECD9F260A695B35B04FED1661ECB3D1480EE6A64A65A1CAEA6920B149A0D49E
          SHA-512:FD4A01CDE5C85ADA9BE34D0E48EF04466DECDD84DDE2E2B52D67379B18BB4AA84954DD6A9C165690A6FB05F455CDD7B814152219546F83A99582E5B665DE4D8E
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/Digital-7.eot
          Preview: 4t..hs............................LP...............................................D.i.g.i.t.a.l.-.7.....R.e.g.u.l.a.r...6.V.e.r.s.i.o.n. .1...0.2.0. .A.p.r.i.l. .0.7. .2.0.1.1.....D.i.g.i.t.a.l.-.7.................FFTM_*....sL....GDEF.(.r..s,....OS/2g>.P.......`cmapv"6m.......rcvt .u.=...,...ffpgm4D.........;gasp......s.....glyf..}....p..R.head...}.......6hhea.G.....D...$hmtx...P........locavNc.........maxp.......h... name....m0....postbH]4..r.....prepV.f....H................_.<....L......(2......(2.2...&.H................. .....X.....&.................l.....l.T...........@.......)...............................2..............................ALTS.@. 0. ....................... ...D.2.........,.....2.U.2...2...2.X.2.0.2...2.^.2.^.2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2.r.2...2.r.2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2...2.6.2...2.6.2...2...2...2...2...2...2...2...2...2...2...2...2
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOjCnqEu92Fr1Mu51TjASc1CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7672, version 1.1
          Category:downloaded
          Size (bytes):7672
          Entropy (8bit):7.877469743154291
          Encrypted:false
          SSDEEP:192:zcBfVyWTPHXYcQfFT3SmF1CYoKxOtNQiXum0U574XK9+VBurcwcGSnodW8Y:QfPbIl9iQ3EtNQieTU57F9+urc5VodWJ
          MD5:1C96FDDD2535342FA077634CE123C589
          SHA1:86240143C8C16C451166AEE3412CB79082AB3D09
          SHA-256:7C9B6264C107C75AD027C91CC616226A9FFE5D04208F2B28E0516694D4787627
          SHA-512:6586A8D63E6A7A8853AB90414DB65053D86FA923CB7FC5B9CAEEF21851F96799B66E15B687054B5A6E9F864F934832FB0AF5BF55944246C50531F216429D8EBA
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TjASc1CsLKlA.woff
          Preview: wOFF..............4.........................GDEF.......'........GPOS.............P.0GSUB.......5...6....OS/2.......O...`t...cmap...<........C.B.cvt .......X...X/...fpgm.......4......".gasp...L............glyf...X...!..%.&.).hdmx...|...5.......2head.......6...6...mhhea......."...$....hmtx............,. Gloca............5.,jmaxp....... ... ....name... ..........>.post........... .a.dprep...........?.1 .x..... ..0..Q*jj.eoN......8......x.'.x..%PEQ.E.}......\...h...C.{oH.D...V.|.sp..g.yz1@.d.......6..w..7u.v..v........... `T/....[x....a.W"(...r.......*...;....c.K...>=...}.r..Sr.f^.].,...<...DS...$RF3It..g..M:...!.*..>B...G/..}......NP..=..*...........<?h.;A.*.}{...yKI...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.d.a`e``..j...(.../2.1100.1.(00. .....3022).fc.....>....q>H..u....2.......x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.h.Z.`.V...N.n.....N.`.F.......`......
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOjCnqEu92Fr1Mu51TzBic2CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2168, version 1.1
          Category:downloaded
          Size (bytes):2168
          Entropy (8bit):7.193940665738964
          Encrypted:false
          SSDEEP:48:LshG3Ws+8pXCR+Rh2iBdzO9Gik5rlZVfKJC4l:LZ3J9K+6iBAIi8rDVSJCo
          MD5:2AD308EC96FB261D9823640ACF80A8D5
          SHA1:994D58B0376DC598E236BF1E4A88FE357ABE4B40
          SHA-256:0F2AC3473335CA6F846A1A4B0A0074F976AC709778F220DF650F4B7188B7BEF5
          SHA-512:55617334226EAC4E7528DA197FAE569E38AA977AB6AFB41FB429657C275F5E0037361B540191FB56D947CF2FEC155039F8FB42F8965C631984D3BC1673C4D191
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic2CsLKlA.woff
          Preview: wOFF.......x.......T........................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...M...`....cmap.......7...X. ^.cvt .......J...J..,ofpgm.......3....c...gasp...L............glyf...X........Su..hdmx................head.......6...6...`hhea...<..."...$....hmtx...`...........Iloca...|...........9maxp....... ... .7..name............ .=$post........... .a.dprep............9..Bx.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f.g......:....Q.B3_dHcb``.b(p`@.........l......g11(00...X.n`P.Bf........x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......N.`.1.......|.........`..... .!...:................................x.]..G.A..g.."@..1w.q....G...0_...].?......w.=.~........y.}>./.......O.......=.[p#e.L..-...HYDFN..'.N..._....9:.&.a.i,.r....).$......t... xm.M6h.e.o...E.n..D NH(%S.3.u"..E....}y.[{`..Y.v..!.`...i..{.5
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOjCnqEu92Fr1Mu51TzBic5CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9628, version 1.1
          Category:downloaded
          Size (bytes):9628
          Entropy (8bit):7.909578202765621
          Encrypted:false
          SSDEEP:192:cBlEdWzyUrVqjVlC+w6PGbH9kqrKgMPf3MxSJCo:GlvzyUr8e+1ebdTrGP/ISJCo
          MD5:1DDC71A3D84F7E26FA31A82129B0D0DB
          SHA1:949E6D1A55E717A909AD65EEDB687A38086850AE
          SHA-256:671CEF04E4731C11DEC7B6267E4D397F3D67FFB89635425A2367E0677813E42F
          SHA-512:2DE23687ED1404D1D5C71BB89C0753286FDDF23DEC89326E811A0BBF93FD10C9603C3EFC5B4D4CD7A4303386C6826A4E4AD4CC6413AF69ED9C3C3CE01EF880FC
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TzBic5CsLKlA.woff
          Preview: wOFF......%.......;.........................GDEF.......E...d...sGPOS.......,....4...GSUB.......5...6....OS/2...@...M...`y6.kcmap.......Q....$V".cvt .......J...J..,ofpgm...0...3....c...gasp...d............glyf...p......(."tm.hdmx..!(...@...p....head..!h...6...6...`hhea..!...."...$....hmtx..!....#.....B.Qloca..".........[.e.maxp..#.... ... ....name..#......... .=$post..$........ .a.dprep..$.........9..Bx......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.}.C..Y.....{e..m....`7....ms.}......<.&..J5....6f...wnZC..MKW..f.u..Cb..x..nZG0....@...+....y.E..../.....o^........{'..U.-.lW.h...l........F..d.I.9.G.E.RA.5....a....p.e...D&3.9, .\.D.EQa...RcAt..tS..E....a.$...c.~Unj.7U...x.4.t.N....G~..c.....v...~M. SZcO.#?D..).$..<Ev......=*..U..j.E..u..v..vA.<......c...3C.Yv.9..x...QB.,..B./.(!...c.]......S..P<G....J....-m.....].&L....W.[T..*..v!.)..4G..."{....\.A...n.]...*...(.?U......9.X..}.....M|C...v..U...t.>a..!HS.u.z...Buo...pu.S(....R"4yGx
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmEU9fBBc-[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20464, version 1.1
          Category:downloaded
          Size (bytes):20464
          Entropy (8bit):7.969622511404751
          Encrypted:false
          SSDEEP:384:edA/1eSg82dg1kGeF2BFDEE+/adkuouo34TjkWqTExYOYg/c1iuHotcO:ey/1eSnLkGeWFQECadcLIc/TEfYr1RO
          MD5:87284894879F5B1C229CB49C8FF6DECC
          SHA1:FB1BD3BAF122D5D350EB387F0536C20DA71F09DF
          SHA-256:BA98F991D002C6BFAAF7B874652FFDCDE9261A86925DB87DF3ED2861EA080ADF
          SHA-512:663BA95BBBC6F7E65D7B1293E4A044C9111438A03B16664FC38A2B2F2C1A4CE96991C847B36691388AB322525A83DB2724CB4D1B9BF0440727F0B5CA7073AB8C
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fBBc-.woff
          Preview: wOFF......O........D........................GDEF.......G...d....GPOS.............~..GSUB.......'......r.OS/2.......Q...`t...cmap...\..........W.cvt ...T...\...\1..Kfpgm.......2......$.gasp................glyf......;...l..(.4hdmx..H....l....."..head..I<...6...6...rhhea..It.......$....hmtx..I....x.....gO.loca..L........._.C|maxp..M.... ... .(..name..N...........:.post..N........ .m.dprep..O........S...)x...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x....dK...{....?..F?.|.~.m...ms.{.Z..;......U.]7s......\.=D.=.7...>....x...D..O|.U:...|o..3.x.j.r"B.............../.)x$.'"j.....1LGmaGxQxG....~.:'.A..hd.z,.k..KO.....^.}H|#z_.O......R..A...9..A..!.(./..."..:.Iq1.r..s..r.7r.7s..q.wr....nz..]...2..d4c..c....d....T.1...d....\....,c9k.g..Yv.#O."%...... ...t"uM..%.......j.#^.....}\c.q.i...<jy.D...C.01.2.r.....V..z.W.7b..L.S.41]..kUs.X/6..b.........(..(...K..{.^..'........`#./..B......N+p.m`...].lQ....Drg.M..Kx.^.S.*..........h ..$.k.'Hy.I.ze..4z.-T.....
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmEU9fChc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15476, version 1.1
          Category:downloaded
          Size (bytes):15476
          Entropy (8bit):7.958862701405374
          Encrypted:false
          SSDEEP:384:oHq1y0gIG9qoXo2wShjPGiMiIulUAnm3u8An3l7lPFQ:oHGdXMFo2wi/IulUKmXA3lpdQ
          MD5:74F47BBA13C26D97194E61A1F08BDEE9
          SHA1:E8DE913DB12AC68981CCB2E67AAB48AF5C3152D3
          SHA-256:38FBFE1E77A10325EB615A07870E73A65B62F8B7658320CC5A8E63288AED91C9
          SHA-512:2B54D13909DDC7200373F7AD44F23C7BDB99831A57D665F742C8FB3BDF9C9FF91B6128CEFBBFB5AC9A5B2DFC64CDD8356DBBEEE519059802F8BAFFA786EB46C5
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fChc-EsA.woff
          Preview: wOFF......<t......r.........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......Q...`u.B.cmap............%...cvt .......\...\1..Kfpgm...L...2......$.gasp................glyf......-...X...\.hdmx..5....j....7:J4head..6....6...6...rhhea..6L.......$....hmtx..6l........S.GRloca..8..........G.!maxp..:t... ... .,..name..:...........:.post..;p....... .m.dprep..;........S...)x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmEU9fCxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7248, version 1.1
          Category:downloaded
          Size (bytes):7248
          Entropy (8bit):7.870881593614385
          Encrypted:false
          SSDEEP:192:EI1Ug1YaJ0+TgA+qpiH1lb6qVGMPZ768jIlY9YwXA:EMLbgypiHuqVGMPZ79jIqYww
          MD5:5CADE72BC73F6C16EADD8BA171CCFECA
          SHA1:00A277E137B8AF67A6D9548E2C76A0484C8A5E99
          SHA-256:4D9508B258701F5166C335F335DB8E982F55DC782706D3788BF35744D839521D
          SHA-512:8502D073562D27941CE920D9E0FC4668D5D723FEE026DD0DAC3D37FB87AE00D779FAA0A1A8C2F17FA8B2D3A25A0E2E0D7574DAB47B1D22A2C61DC947752C95F7
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmEU9fCxc-EsA.woff
          Preview: wOFF.......P......3.........................GDEF.......'........GPOS...............0GSUB.......5...6....OS/2.......O...`ur.hcmap...8........C.B.cvt .......\...\1..Kfpgm.......2......$.gasp...L............glyf...X...p..$...i.hdmx.......9.......5head.......6...6...rhhea...<.......$...?hmtx...\........J."%loca...@...........xmaxp...P... ... ....name...p..........:.post...L....... .m.dprep...`.......S...)x..... ..0..Q*jj.eoN......8......x.'.x..5R.@.D.....p9.n........$8.Dh......]..UO......a......4=.k`.o..h..8.L."(@..M.c.O...6...@Y.1....[...o.y........."........{..}...@.W.]..4........N.XI..h...~....dJ....bV..E:m(...cEgJ....'.1&..t.........3.w.......c.T..n..H.....J.x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f........u..1...<.f........P.....,..............C..,&.... 9.+....@........x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*...........r...}.V._.N.`...........`......
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmSU5fABc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 12420, version 1.1
          Category:downloaded
          Size (bytes):12420
          Entropy (8bit):7.941248619606073
          Encrypted:false
          SSDEEP:192:18hSv6KFO/PCKklb2fHPRaMCNS3yrGfNCGVDCyt0kwkoEtRaexcNU:2CFO/PEAfvRaMCNfrGl/h+29dxc6
          MD5:9F024332B202519BF8EBC56B20767527
          SHA1:0F87A713DBB2FC2BA14DDCBD8A21C649FF4E83A0
          SHA-256:E5D036B0616DDE1818A7233F11981787DAE6882A7F1F588206D26745A29A332C
          SHA-512:9BBAC7656B80FC1F2800A3A2E7F7EF5CFBB515755B73E889079023F7A67BDB17195143D7D7476DF74A01CA5B2DBE2C8FC151BABC4AE27DF3C1A0CC84BB063DA2
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fABc-EsA.woff
          Preview: wOFF......0.......Z.........................GDEF.......J...j...tGPOS.......s...V.y}.GSUB...T...5...6....OS/2.......N...`y...cmap............d..1cvt .......X...X/...fpgm.......4......".gasp................glyf...... A..?...v`hdmx..+`...N.......>head..+....6...6.Y.ihhea..+........$....hmtx..,.........xr<.loca..-..........e.%maxp....... ... ...\name...........|..9.post../........ .m.dprep../........:z/.Wx......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x....d.....>=6.......g.5g.x.z.m.6.m.Vp.~.q..;.._.......(2@..B2k.U\.z..-\.~...\..m..q.."B_.l^.c.e.!....qt.1L.d...f...5..f.....O..m....7..q...E..\1?/....s..O...$.O^.....e........j.|<..<.<...._....._....'...1....J..t.. .3.a.t.#..h.0.q.g...D.i.f.sY.B.....d....7.....Y....Mlf+]t....b7{....../..:ZdG...x..q/c..&.L.....&g.r....2W9_....R.J.6G......n.7.b.....G...V...)...."..f.....z.e5..m....=e}.....=..5......}.....u....@.-..41X.....hd..y.+.k.f....mG...~.../..|..>$.g...........[....l7...`9.J.}..f...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmSU5fCRc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 19648, version 1.1
          Category:downloaded
          Size (bytes):19648
          Entropy (8bit):7.971367669938983
          Encrypted:false
          SSDEEP:192:K+UgXh/z6HzV2VNC1jTx7L+2VypP/mi9VidcDd5Np9wIWE60lGiLdlIxerBXF6V/:Zu4NC1p7RV6/mi9Wsd3e0DsS0O6mtRs
          MD5:D7604E4C543BA8C5BA7EE9A9190B2B33
          SHA1:3B31192C51CDB15CF60C126D3C46D141BA198610
          SHA-256:C5A0E60BDE1AC8FB46DD03E695CE824AAD4F4C53E6DF8A0C3BF896EC01716FF9
          SHA-512:49606DBBD7C8CBC12BB20F51BA016A72B9619C8786908B2802752B397DCD196C9C1F85B1929AF9EB2A26153610DCE30C08F9BFB36AFE4F63E640A630530C13E8
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmSU5fCRc-EsA.woff
          Preview: wOFF......L.................................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......M...`z...cmap............S.(Ncvt .......X...X/...fpgm... ...4......".gasp...T............glyf...`..;K..q*.bg.hdmx..E....q....B:T:head..F ...6...6.Y.ihhea..FX.......$...uhmtx..Fx........p.A.loca..I..........Kmaxp..J.... ... ...\name..J........|..9.post..K........ .m.dprep..K........:z/.Wx............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmYUtfBxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9180, version 1.1
          Category:downloaded
          Size (bytes):9180
          Entropy (8bit):7.905172589978829
          Encrypted:false
          SSDEEP:192:sC/BlEdyEEYqdEbV2+WOcALM+t4Dj9MrcOF9sYDxrGxOXjuNKp06SAguZ:HlaNqdEbcRALM+t4DjCrZ/lCOXCNKe6v
          MD5:FE67A0ABFF1F0CB5B4E8D3848C0D6D12
          SHA1:EBC11B437D533B253B252576E9CB0BE4D157D417
          SHA-256:C254EAEC1322687D32C8E5D233C4467CAF5A30B57AD68F35B171DAE0B2588BF5
          SHA-512:8CCE7488DE3C6A8752F877F0862F59FD0994B11B51F1645E6E2E4301D79A4327619E874D1B19E0E5F13F47BD19196B660A031CD9B46673658DF394703168B79D
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfBxc-EsA.woff
          Preview: wOFF......#.......:p........................GDEF.......E...d...sGPOS.......,....4...GSUB.......5...6....OS/2...@...M...`y...cmap.......Q....$V".cvt .......Z...Z...=fpgm...@...3......#.gasp...t............glyf..........'.P..<hdmx...p...@...p....head.......6...6...Rhhea...........$.].Dhmtx.. ....&.......loca..!0........J.T.maxp..!.... ... ....name.."........|..9.post.."........ .m.dprep..#........8...Cx......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.}.C..Y.....{e..m....`7....ms.}......<.&..J5....6f...wnZC..MKW..f.u..Cb..x..nZG0....@...+....y.E..../.....o^........{'..U.-.lW.h...l........F..d.I.9.G.E.RA.5....a....p.e...D&3.9, .\.D.EQa...RcAt..tS..E....a.$...c.~Unj.7U...x.4.t.N....G~..c.....v...~M. SZcO.#?D..).$..<Ev......=*..U..j.E..u..v..vA.<......c...3C.Yv.9..x...QB.,..B./.(!...c.]......S..P<G....J....-m.....].&L....W.[T..*..v!.)..4G..."{....\.A...n.]...*...(.?U......9.X..}.....M|C...v..U...t.>a..!HS.u.z...Buo...pu.S(....R"4yGx
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmYUtfCxc-EsA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7100, version 1.1
          Category:downloaded
          Size (bytes):7100
          Entropy (8bit):7.870301681416761
          Encrypted:false
          SSDEEP:192:Br41YaXfYqoBNoWdsb4JNEGlJW9j1NWUzoDZmzlAguZ:9qWq6f/7RlM9j3WUc9Ay
          MD5:5C8DD84449512182D0E3159F1BE3685F
          SHA1:D7F2D36815F0D32FE224386313CCE46C7947863F
          SHA-256:B92D2446AA44F58516496EFC81E48F9F1E41B2CD8DAB2F941E6852B84762C6C0
          SHA-512:E5D1C33B69647EC383C1EEE78FE9026080C9DDDCBCD1926A21A4AF9FF4A46287F031809C7390FC8805186AF9669C52907B1C650BC011AD4AD0A2E7A549B433CC
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOlCnqEu92Fr1MmYUtfCxc-EsA.woff
          Preview: wOFF..............3.........................GDEF.......'........GPOS...............0GSUB.......5...6....OS/2.......O...`w..cmap...8........C.B.cvt .......Z...Z...=fpgm.......3......#.gasp...L............glyf...X......%>w..hdmx...\...3.......7head.......6...6...Rhhea...........$.].ghmtx............Pr..loca................maxp....... ... ....name...........|..9.post........... .m.dprep...........8...Cx..... ..0..Q*jj.eoN......8......x.'.x..5R.@.D.....p9.n........$8.Dh......]..UO......a......4=.k`.o..h..8.L."(@..M.c.O...6...@Y.1....[...o.y........."........{..}...@.W.]..4........N.XI..h...~....dJ....bV..E:m(...cEgJ....'.1&..t.........3.w.......c.T..n..H.....J.x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f........:....Q.B3_dHcb``.b(P```A.p..wgp`dRX.....!.}..P..|........ d.......x.D....a....fRIR...PI.h.-#........(.,......r\.j.L-...c...J7..#_.._..b..|......l...&0....=.GTD..1.,.IaJ^..6.|aM.......Z."..G...*.......N.`.J.......}.............`.......9
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOmCnqEu92Fr1Mu4WxMOzY[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 9264, version 1.1
          Category:downloaded
          Size (bytes):9264
          Entropy (8bit):7.905824330948233
          Encrypted:false
          SSDEEP:192:atuos3uGek81/Bk+2b6rFVBYWwLtNMGzyyR1wNUy3BfbjroU7:LorGekIKQtwLtuGzyybwBbg2
          MD5:1DBDDCD99F22D9B317F6C34AEAA4352D
          SHA1:A3B2E6B384320B64A5B81FC8B6F86E5DB9705C18
          SHA-256:336E592673DC9313D4F1453D3308FE201388EBE8FDB01EF23637214B24007F1A
          SHA-512:C98227018ABF4E2E13EC860912CA5A90F1A7AAE1881AF4819FEF41B54765923EBCF7DAAE3C854838DC58BE1D0BC4D7A7BD89080BF00035B025A0FE9F421472A2
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu4WxMOzY.woff
          Preview: wOFF......$0......:.........................GDEF.......E...d...sGPOS.......g...J5...GSUB...D...5...6....OS/2...|...M...`x...cmap.......Q....$V".cvt ... ...T...T+...fpgm...t...5....w.`.gasp................glyf..........'.k..hdmx.......>...p.~..head.......6...6.j.zhhea.. (.......$....hmtx.. H...!......!.loca..!l........G:P.maxp.."4... ... ....name.."T.......t.U9.post..#$....... .m.dprep..#8.......I.f..x......Q....+..J....V.@e.!.'....T..e....Y..26e..89...x......Zh.5.{.,...x.|...eW.E.....m..6c.S..R\Fl.....Y.....>.{r..T...5k.U.<..NQ..g.{.2O9...(AfA.;..NS....y.$....`K.../...%zY.....P..t......'T....~V..=.....U.&.g..!.C.r..R.r..<.`..De*W.jT.:5.I.j.>:@.j..j....R-.r.....#..B;R.v.*,U5.n.[....j.9j...-.....{...9Y. ..h<...7.o...xe........A.h.i.r.r.}...h.>P.h.Q....R.=..Ub..~a.A..T.3..O5.:.f..5.....7...j...f....*.k.Y...}.C.u8...G"S.0......T:..._.h...8.V...^.~...#...T.A...~*...:p...G.h.t....M`..J%*.X....\.l.n..J.*..v:...H..q...Th.*.O............WHy._...T..1.....M .A<..m/
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOmCnqEu92Fr1Mu5mxMOzY[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 12600, version 1.1
          Category:downloaded
          Size (bytes):12600
          Entropy (8bit):7.939219345259656
          Encrypted:false
          SSDEEP:192:AFlv6KFO/PCKqlbTTrxAXYWA68jDBfWw9Td3rgUzhEPSU5U/UnFVc+SN5sO/5aRJ:WFO/PKBaX468pfFlcohMSUUcFVc1hGYA
          MD5:2675D8A1273F4191E99648B47239A403
          SHA1:4878D6D5DE9B0738022321A92AE224177E81AAA2
          SHA-256:7B6DA8CEC0C5E2FDD56453CD28DFDDF63549B85A621F9EFFA141C67A3C338378
          SHA-512:6E10DF1A5BB2B7F728058E0BC501607AC508C51CFD6F793321B569B0B6F91F939EBF87DE431651E12F0641AB17AE4F55AAF44CB62811CB255000EB6F8AA076EB
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu5mxMOzY.woff
          Preview: wOFF......18......Z.........................GDEF.......J...j...tGPOS.......s...V.y}.GSUB...T...5...6....OS/2.......N...`z...cmap............d..1cvt .......T...T+...fpgm.......5....w.`.gasp................glyf...... ...@l.../hdmx..+....O.......>head..,L...6...6.j.zhhea..,........$...'hmtx..,...........9.loca...,.........m.7maxp../<... ... ....name../\.......t.U9.post..0,....... .m.dprep..0@.......I.f..x......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x....d.....>=6.......g.5g.x.z.m.6.m.Vp.~.q..;.._.......(2@..B2k.U\.z..-\.~...\..m..q.."B_.l^.c.e.!....qt.1L.d...f...5..f.....O..m....7..q...E..\1?/....s..O...$.O^.....e........j.|<..<.<...._....._....'...1....J..t.. .3.a.t.#..h.0.q.g...D.i.f.sY.B.....d....7.....Y....Mlf+]t....b7{....../..:ZdG...x..q/c..&.L.....&g.r....2W9_....R.J.6G......n.7.b.....G...V...)...."..f.....z.e5..m....=e}.....=..5......}.....u....@.-..41X.....hd..y.+.k.f....mG...~.../..|..>$.g...........[....l7...`9.J.}..f...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOmCnqEu92Fr1Mu72xMOzY[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20032, version 1.1
          Category:downloaded
          Size (bytes):20032
          Entropy (8bit):7.968115132562132
          Encrypted:false
          SSDEEP:384:LhgWRuSyQprMMBGu4xujEMhm9aQTxcUlWzQM2l6:FgW0jYrMMBGu4kjEMhm9aQTzmAw
          MD5:507A914128672948015FF0892B799722
          SHA1:1B8786C6032C5F036E9BA9DCAC18586AE9C9764F
          SHA-256:4C7A2F27696F8503137604DFE35EDE4B33C81F5C4B375242BB50D22E9CC896B0
          SHA-512:C9263B11F6AC4E312FF1DD9F28D7E3D91548662515E464A04748C6E922220EA1F3041623E1F3B336FD3317D2FAB98F4C6970451CB515381DB73C2642BF728472
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu72xMOzY.woff
          Preview: wOFF......N@................................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......M...`zf..cmap............S.(Ncvt .......T...T+...fpgm.......5....w.`.gasp...T............glyf...`..<...s\ZUN&hdmx..G....n....HCX<head..G....6...6.j.zhhea..G........$....hmtx..G...........:.loca..Jh...........maxp..LD... ... ....name..Ld.......t.U9.post..M4....... .m.dprep..MH.......I.f..x............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOmCnqEu92Fr1Mu7mxMOzY[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2196, version 1.1
          Category:downloaded
          Size (bytes):2196
          Entropy (8bit):7.200802292162624
          Encrypted:false
          SSDEEP:24:uCVChQ3FKlCj61Uw7wOVQwO3Xm/zYpfeb+ioM8R0KyU2BJm7WBrlHrYP6qpyrq53:b2ykCjGU0qwOm/zjqyUJpzFnZ
          MD5:B182E0316F82C1D3CD298BBA0D396528
          SHA1:3C00EED8CA3CD636516CF71F86BC249367619BA3
          SHA-256:A1BC3BA2E1066B0B57F4C42CE0D0FB309A9F53670A8E2C169C47A28A5FAB7304
          SHA-512:18A62604339C96236748CDAD435E61FE0A5005F239D341088D024069C1B42944EAE0BAF1578D96A4FD0D3DA3005C75620853195E4B287AE4465B15AD03555055
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOmCnqEu92Fr1Mu7mxMOzY.woff
          Preview: wOFF...............P........................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...M...`.S..cmap.......7...X. ^.cvt .......T...T+...fpgm... ...5....w.`.gasp...X............glyf...d........ZFG9hdmx................head.......6...6.j.zhhea...L.......$....hmtx...l...........{loca...............kmaxp....... ... .7..name...........t.U9.post........... .m.dprep...........I.f..x.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`fic......:....Q.B3_dHcb``.b(p`@.........l......g11(00...X.n`P.Bf..W.....x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......x...d.N.Z...`.V.4.<.............`..... .!...:..............................x.]..G.A..g....#f...3...,v..l.a.P.;.@. ....[.....9.'Rs{.....x.`z.nf+.?....x?.......R.....`G...A...Ao|c#.N....c..8C.k...F.,...N.BL......&l4....4.....H...(..8!..L..,V.PD.{.F.o....}...Agk.-b.F
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\commonJs[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with no line terminators
          Category:downloaded
          Size (bytes):27
          Entropy (8bit):3.1578721140611075
          Encrypted:false
          SSDEEP:3:JJGYu:JJc
          MD5:4FE1321479A9A5EA7048916FDAE02FA1
          SHA1:850F89368D5FD58FC3F8FFE8D780DF4035BABF5A
          SHA-256:D007457BC9A5FDD5B1294C8D107B26FF85724CAA190FDBAF1A71673EAB8BD65F
          SHA-512:ED475F390A67ABE8708BB759D15B03E7A643C208A72E49EDCD887161B8AC4B3FEB208C761C7638AC53BA88B6885C623CFC4B483D4C058F003A157C2A1E02ABA8
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/commonJs.js?v=19
          Preview: ../../1commonJs/commonJs.js
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\css_1[1].css
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):1155
          Entropy (8bit):5.427159337579252
          Encrypted:false
          SSDEEP:24:81HYmyJOAylYmyeHto/3eDYmyl8wy9+DGSSf49:cH3d39toq37NkoG
          MD5:0F6A8AD0280D7E72778A5FE2694157E2
          SHA1:510515983ECFAB4A0A5630067BBF01A850520F8D
          SHA-256:8AEC994F01F6D748E9FE3AE0F1E1E0CA0FCF90629F05303AA5B0E0DA5D5AF302
          SHA-512:A1A3F48DC079888A3664B9EDCE89BD866F76EE17F31E1673BA7F75C89DA549D050C103D974C52D961CA1CA273E12A8A3DF0559AE134F3935FAA1B69B43FC4F24
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/css/css_1.css
          Preview: /* vietnamese */..@font-face {.. font-family: 'Exo';.. font-style: italic;.. font-weight: 500;.. src: local('Exo Medium Italic'), local('Exo-MediumItalic'), url(../fonts/4UaBrEtFpBISdkZS8yLux67x4w.woff) format('woff');.. unicode-range: U+0102-0103, U+0110-0111, U+0128-0129, U+0168-0169, U+01A0-01A1, U+01AF-01B0, U+1EA0-1EF9, U+20AB;.. font-display: block;..}../* latin-ext */..@font-face {.. font-family: 'Exo';.. font-style: italic;.. font-weight: 500;.. src: local('Exo Medium Italic'), local('Exo-MediumItalic'), url(../fonts/4UaBrEtFpBISdkZS8yLvx67x4w.woff) format('woff');.. unicode-range: U+0100-024F, U+0259, U+1E00-1EFF, U+2020, U+20A0-20AB, U+20AD-20CF, U+2113, U+2C60-2C7F, U+A720-A7FF;.. font-display: block;..}../* latin */..@font-face {.. font-family: 'Exo';.. font-style: italic;.. font-weight: 500;.. src: local('Exo Medium Italic'), local('Exo-MediumItalic'), url(../fonts/4UaBrEtFpBISdkZS8yLhx64.woff) format('woff');.. unicode-range: U+0000-00FF, U+0131, U+0152-0
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\currency[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:UTF-8 Unicode text, with CRLF line terminators
          Category:downloaded
          Size (bytes):860
          Entropy (8bit):4.713175403228815
          Encrypted:false
          SSDEEP:12:AZD/ZvqX2voxTnRXZqP+cJS3HvMWGsZGsJdlrAhvM28VvMaA6:uDByGA1nRXw+cJqHUBp0lMhUHUaA6
          MD5:E7EC335F36828303745EA8F2E98C0B39
          SHA1:1C32B67AC220BA3BF23F9959EFFCC78C5554DE41
          SHA-256:027D92BD47C6AE2851E6EE909D843644480152BF814D2567B47701597E979A96
          SHA-512:C64068D782EE3FD1D87060089993DE7F67554C22CEFE41B15044618C91FE8B9C827E4CD59881E26FB5EA069775043639F4DE043DDFA82952C08514FC185BC196
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/currency.js?v=1
          Preview: function addVisitorModule(){.. var isoCode;.. $.getJSON("/geo", function(data) {.. isoCode = data.country_code;.. countryGeo = data.country.. currency().. });.. function currency(){.. $(".country-name-geo").text(countryGeo).. var currency1 = ["AT","CH","DE","LI","LU","BE","CZ","ES","FR","GR","HU","IT","NL","PL","PT","RO","RS","HR","SK","SL","DK","FI","NO","SE"].. if(isoCode == "GB"){.. $(".currency--table-hide").text(".").. $(".currency").text(".").. return true.. }.. if(currency1.indexOf(isoCode)>=0){.. $(".currency--table-hide").text(".").. $(".currency").text(".").. }.... else{.. $(".currency--table-hide").text("$").. $(".currency").text("$").. }.. }..};..addVisitorModule()
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\disclaimer[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):8375
          Entropy (8bit):5.084435084364635
          Encrypted:false
          SSDEEP:192:3It/FB73dcJRv19e1PebETk9wy3dSedUBV63F:3IFhcv7e1PlkKdV61
          MD5:5FF8525C32AF3A20A3978931E0666E59
          SHA1:27F23856855A1BFA0088CAC2209CFC8D67EEC083
          SHA-256:C19A145C2D6183CE3EBAC76D4A4D4C3CDF30C6FB2D411E4448DCB780C366F61E
          SHA-512:12EE8F95ADECFEB59FFD90F198463A1CE367390B9EFF41CCDA25993E7B9D367608F322FA1DA82A9DA2F9B874ADC1D2A48454E10B9D6D125D48B9FD9337958DEA
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/disclaimer.html
          Preview: ..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>.. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">.. <title>Disclaimer</title>.. <link rel="shortcut icon" href="favicon.ico">.. <style type="text/css">.. .. body,td,th {.. font-family:Arial, Helvetica, sans-serif;.. font-size:14px;.. color: #111;.. line-height:20px;.. }.. body{.. background-color: #FFF;.. margin-left: 0px;.. margin-top: 10px;.. margin-right: 0px;.. margin-bottom: 0px;.. }.. a {.. color:#111.. }.. -->.. </style>.........</head>..<body>.. .. <table width="1100" border="0" align="center" cellpadding="0" cellspacing="0">.. <tr>.. <td>&nbsp;</td>.. </tr>.. <tr>.. <td height="70" align="center" style="color:#111; font-size:24px"><strong>Disclaimer</strong></td>.. </tr>..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\faq-list-title-bg[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 26 x 50, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):740
          Entropy (8bit):6.450172468447008
          Encrypted:false
          SSDEEP:12:6v/78n0yyY/tfT3ciYWYq502oxQEub0vH08EPU8Y9:XtLciYTiLKH9R9
          MD5:D5F8B024975A8A383EB46989B95B486A
          SHA1:851F9172B9D8C6069A386F541362CFA4200B4A9B
          SHA-256:3D5492D098EA858BBFA9F859CC1CA1BA8699168E2FC62CDBA6964098B23A3FA8
          SHA-512:A870185E702A125B190C5507BEF9AA2A04F806D25005CFF77ADD9E4C455CC670E72C8CDA2EF7B6868A9103A75546E36C581B295F9B1942C796D21C9D8D6079E5
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/faq-list-title-bg.png
          Preview: .PNG........IHDR.......2.....uk;.....PLTEGpL........................................................................................................................................................................................................................................~.V...LtRNS...0...<.;.0..|..&...H..?{....6.SK.....$}....cc....T4*..l.l.R........^^..5....]IDAT8.}..r.0...`0.B'...d..!.."......H..+..i.6Ic..G.\!N........0...\.?2...NM.f.....Q....o...7...p....*3.e.*.N...........Vk.*.N.k...p.P}...J...f8..R..s......s..e.T.&..9sc_.Z.;..&..nZ.1q.5J,...V...).7f.x.....L..O..5..R...v%...|FDY...2...J........Bu .P%..i_.i!..U....f.v...Z%...V.n`.,5..o...._JL..d6:e...h.]l.<kdk..:....x.#......>.,...-.......ZJ......IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\faq-title[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 89 x 61, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):1406
          Entropy (8bit):7.6231274345127975
          Encrypted:false
          SSDEEP:24:4GQ2cV3/s05V3CoKpQ8WwmbwqvehUSH3X0rGCUGx9cmrbDKsfRESWTY8EuB:e30+h6lmFWh7SGCU09zR5Wv3
          MD5:9BDF0E0D55D6E6CBB4D3DC56A5C386EE
          SHA1:664120EBF4933A5931398A2544D2A7F858C9AE38
          SHA-256:5BB7F3111AE0AE813B23A17408A85F1724A365B0448416240403B3A2F034C5D0
          SHA-512:4B5EFB9552BA64A985F49FED4EA78334C9AEBCB4AC98001D8DD7C929C9A1FEBF35BBDD77EE705D48370892A730EEA049AB7DDE1DBEEE12AC532AE96B13B8BE71
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/faq-title.png
          Preview: .PNG........IHDR...Y...=......5....~PLTEGpL..................................................................................................................................)tRNS...;........3......[..|D...ew$.R`,.Kq.jY.).....IDATX..[..0.D#.$..|!....o.~........v*.....u.C.&*P.....R......\g.n!..snU..K|w.....m.^..:l1}.i)..m..+..f........nn.......K!..w.......%....v..@V.x|.k...km.{H..?.....$?&.V;.P.k9..{{...cY^.$...%..xXv.2...E.j ..6..P.7;=...q.G...W.....N.4.?.....Z.g.....{!p4.=.|...(...(..)......z...3..../..g.Bj...F./B.o.E$.6WZ.j5>..|....\..B.!.....\....S.JH.c...n..F....4Y.....V.Q~...&..!.;9V.l....t....!.t.E5..Iq..~.IW.?.F.)....i...X.......d...EX.U.L.i..._wPju#v. o.4....g..F.!........]W..+.+ .B.A:...zEo8-.......0Gn.o.S...z...<...6.:rm.i!.C..A.2.....=.7....!.:{...40.Fs...MfA.!.h....J..=.9r.......q....~?....K..L..26..cB3.....2~.....9/.G._...Z.....8. ...Z9.......K..X.......|>...4....OH..5x...n.i....'..(.R......n.,.BjMN8[...q...l}^..X.du..v..=.*.:.../.r...N.Y..
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\favicon-32x32[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 32 x 32, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):676
          Entropy (8bit):6.953437855436919
          Encrypted:false
          SSDEEP:12:6v/7s6nMr9pyQhr4sfKDXaF0T0db/vUxjtWxAd7lLNzPqJQmxSELuo2CH6Gk2uHT:hM0gA4FT0dQxjtWxAd7HzAd56JMLxiT
          MD5:1E7A01832BCF6C8E5CCD9C978E2FF775
          SHA1:5ECDC763ABCCD112BA3FC232D9E183FA32114735
          SHA-256:00FF200FA2BEC5EFF63A12B1F1DAB9BD5D17077F8931D1B46A3932406EE0B6B7
          SHA-512:4143BD4C74798335E76BC6597C0C45EB1A91B8EA1B5F035F02297F975258483FC7D3A448F5171E4667BF1CB115B7AA85BA29C3227486C8C4EDC4DECB641CF9B2
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/favicon-32x32.png
          Preview: .PNG........IHDR... ... .....D.......gAMA......a.....sRGB........&PLTEGpL..................................... .ii..............................................uu...............................mm.EE.......**....vv.......~~....[[.......BB.......55................00.......jj........................................SS.ff..........tt.]]....ZZ....... ....QQ....%%.CC.......tRNS......jO.........Gk.D.P.....IDAT8...v.@.E..[.0Ill.I..{....A.R.;.w...Gg...-.,+._.4!.Y.......a....v.ml...o,B..r.V...!G...,........iY...o.SA...J...s..T.p...v..o..0.\..S.y.C...P...sh!R..x6.^TZ.p......p5A.o..xA...B.|a...-..q...E....wi.Z........R../~..([4.@...]b.v..E...v..a..K>..1.....IEND.B`.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\feature2[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 61 x 57, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):1247
          Entropy (8bit):7.294668556742584
          Encrypted:false
          SSDEEP:24:Cj0Dly/LCZUYWrPbWtxJwm4leKLQA0ZsuNwZNgpHDs:2W4LCZUYWrPbWtf4YA0quNlDs
          MD5:897F5A18A1F8E5734092C2021A05FCD2
          SHA1:A8144FCC65AF14C49EAED2EFB455931D1234DE31
          SHA-256:1D23ECCB9447259F8992F5401E0B680931E69A3069326AD741227B89064DE1B2
          SHA-512:BA2341173588067E29149D6AA1511EB5F786DEB6208934C87E91C60FA2EAF187762F7CC36EEC7B272AE794409674E5EDDBA7B66CBE22095F208ACF1C2DE39A76
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/feature2.png
          Preview: .PNG........IHDR...=...9......-......PLTEGpL.........................................................................................................................................................................................................-`*....CtRNS.........e.......t..Q"2.6..&wFMZ.J_j.<,.......V..~.{p>.9.../B.S'.....IDAT.....B.......@Xa.-.u....{..%T4~...Y.s.a...=../..o.... ...).Z?...K....%..cH.}..e..%YO._0..sz.qm6(H...g~..o.#....B-n.6kJ..!..}..V2.|..y...Z..i..i..#6A4e..6...&.T..Dh.#..Y.(.2.Y.......c.~.sR....#.k..'w....[K.v*R.O|.&..)..m.v.n.O&....j.;.d...].I.j=<.|.....FE..8..g.$Y..Sk..S...k.\......BSq.].F..V*.Y..k...n.xT....*..R....\2RN..M..^cHj..F......)).......!.....G<.{|..q......IM.4.K.<.">3s..5...2...9Y..[=sT.....u..!......U..,....T.!...d..4P...[+ ._@]c..Q6...i..*...T1.2U.+....+..e..Z...g.d..kb9Q._1..m....,...cV9........x..9..P..[.....,$)..KM..\.....OE.AJV....H~..:....5.w..I..gmS.P.)<.8..O..c.~..`I."'..M9.S...{<w...).oJ6'.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\feature3[1].png
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:PNG image data, 43 x 57, 8-bit colormap, non-interlaced
          Category:downloaded
          Size (bytes):1214
          Entropy (8bit):7.24881751932144
          Encrypted:false
          SSDEEP:24:RumIIlEAaAZbUDnoVn6U+3+n0ghiA46apmhiZ6Ld:RumIIyLA0noV6o0wUZsd
          MD5:ED15BDB91ABD611477455AFE967E1F97
          SHA1:DCC636B5F3173D3A56FD530E0A5DAA25743B9F0E
          SHA-256:34253F40A70EA82412E4D664DE424AF79F7D1067FF6EBA5EB31C12BF18C968B2
          SHA-512:AD119051EBC2B238CA5116D107C7398BEE4854430F3CC9D0A8C98CDC2D968ADA2697D9951752649A43466CF2AE2CA4FF486601562773F4102CDF72410A896EC3
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/feature3.png
          Preview: .PNG........IHDR...+...9......."b....PLTEGpL.................................................................................................................................................................................................................x...EtRNS.........Z....jW....S.o.w..f....:/..z2Js(.+}.7MA]...F..a....P.#5........VIDAT.....Z.H....2d.+.z.HS...y.WZ.........^....~u{...p.G...\E'.".)v.........2.7.;..X.[.9...8s..J..8.d.J.W8....+.8.g.J..\...b.\.5(.i...P:..3%.....g..Ai.up..1.9.6Lp..z..........&E\...>....U*..Pp,a.7....I}.....(.M.\4..z..^{.._.......u.3)..P."s......d..S2.-p.v..]..W..%O....*k..f"..._......B..G...&.P.^6.[.^.~...$.C../...Iz.E/......._..C.nL....o*.4.~.G/...a...*>lI....mG..Vv..-.>.y,V.r...C.n`.....+...\..n.&.....?P.....TT.._.0......:rk.).y....2.I.R.f.t..v..U].m..5..1.V~ud..N...Z.ovV....9]d]....b^..U..2=.$.#}.SAK..-(....kM[.w.J.....O.......|y.lE........vS.m...3...n\..(...n4.G G..J.=(..4..:..+KC>A..J..Fd....).hCaB.......^...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobdNf[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21908, version 1.1
          Category:downloaded
          Size (bytes):21908
          Entropy (8bit):7.972844340163731
          Encrypted:false
          SSDEEP:384:ToRPUu1ex3IWFLuoTMCR75ewzk8+13+/UuArOX7h11T0WLNCN8mMgN:YPV1emuLuoTM64wzk8+1wDXDhJEGtgN
          MD5:32318C7B683B98132D01BECE288CDEAC
          SHA1:4BA17B14B9E6C8540163F19A674BC777BE118A22
          SHA-256:44C1476BEB9E661572B4C89EDBE297CDA7EE73D5B09955F3D6BE0ABFF361610E
          SHA-512:249EAF1A3E1786BEBB96BDD9092188BAB4A11994BFD1129EBCA0EEE1B37026A44E8D59E28D9BA5B1A14689E83843DA0668F35699EA7D65F1770CD6431718218F
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDpCEobdNf.woff
          Preview: wOFF......U........l........................GDEF.......G...d....GPOS................GSUB.......'......r.OS/2.......O...`t6..cmap...$..........W.cvt .......X...X/...fpgm...t...4......".gasp................glyf......A...q....lhdmx..Nt...i........head..N....6...6...hhea..O...."...$....hmtx..O<...v....JGF@loca..Q.........Q/2.maxp..S.... ... .(..name..S.........&.D'post..T........ .a.dprep..T........?.1$.x...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x.l..h.a........l.m.6.1+.X....i...y....&...._..63..5....2>...x|D...ct.Kx..H@b.3..l..#u.....L.*.....^.*.4.....rP..{.*......Q...JT.:Xu>..T./>...oq...........~..@.....lq../.... ..#..".&.8.H$..r...J)..jj...&..f.=.9..N9.....'F..8.4.....m...m...m.m..n..&.X..}....S.|.....n........PHaE...J*...4..MjJ.*..nW)..rn3'/.....ks5zY5c...Mgg.5..p..rR{c...p..t\.8.c=..p...X.(.......7....=.........!...H ........(.0...(.q.JT?.b..z].'T...m..vNi.....t....:P.R..H....t.........&?.:.j.51+.S.":j.SK'I.^....}S.i.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoY9NfQyQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 16504, version 1.1
          Category:downloaded
          Size (bytes):16504
          Entropy (8bit):7.9650596200658645
          Encrypted:false
          SSDEEP:384:eUPqhHWpfIy9o6kaDkNa6CqY2jtgIABQjqkHH6gdC/8mvFA0VFY:eUPYUoqD/jSZ/HTcFAuFY
          MD5:14245F5E4B8EE8C001E0DACCFF43FEA3
          SHA1:2DF22AD73BA672C04445F9E1B1893081A10218D0
          SHA-256:77BD8DEEC691C2F4394708FC633722F784D8687EC17323FFEBE746553706A775
          SHA-512:18E3527161D0ED8CE3FD18A22F47853733652DE5436F898C3BB1D5FBBDDCF0DB610CAC534D7A3D3E1434BE428D9ECD3F97DEFB6937D7C29068FF0CD85634C13F
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVg2ZhZI2eCN5jzbjEETS9weq8-19eDtCYoY9NfQyQ.woff
          Preview: wOFF......@x......u`........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......P...`vYB#cmap............%...cvt .......L...L0..Gfpgm...8...3....g...gasp...l............glyf...x..1N..[jrV\{hdmx..9....c......".head..:,...6...6...hhea..:d..."...$....hmtx..:.............loca..<.............maxp..>.... ... .,..name..>.........%.Czpost..?........ .a.dprep..?.........=...x......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCQYaQ[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 20120, version 1.1
          Category:downloaded
          Size (bytes):20120
          Entropy (8bit):7.969624286614846
          Encrypted:false
          SSDEEP:384:TRPUt1eEKg7kcgF5hRucHHmaNgW1zKXTWJfXb1FXy5bAVdfn:VPO1e9ANcnmaSWdiu0bAfn
          MD5:B8F4E373A619C50643E7DFA36E9474D6
          SHA1:7E1024B851CCA6D5EBBC7DBD3744235F862F83C5
          SHA-256:C90953D2CB105A3FF6622B09C8748804280F009A7ABFFB94FF5BB1FC0003DE65
          SHA-512:825E70D21373E496731AAC08A8C2E1D1ADD69668FC84A5A4E862BC909B28345D79CB772A5CCF3A54E27B0A2DFFB52FA8B302E8AD390C4F516715DD071ED71F7D
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCQYaQ.woff
          Preview: wOFF......N........l........................GDEF.......G...d....GPOS................GSUB.......'......r.OS/2.......P...`t6..cmap...$..........W.cvt .......X...X/...fpgm...t...4......".gasp................glyf......:...k:....hdmx..G....i........head..G....6...6.*.hhea..H$.......$.z..hmtx..HD...~....Z awloca..J.........P{4.maxp..L.... ... .(.[name..L..........s=rpost..M........ .m.dprep..M........:z/.Wx...1..P......PB..U.=l.@..B)..w.......Y.e.u.m.C.s...x.h.~R....R...A.J.x.l..h.a........l.m.6.1+.X....i...y....&...._..63..5....2>...x|D...ct.Kx..H@b.3..l..#u.....L.*.....^.*.4.....rP..{.*......Q...JT.:Xu>..T./>...oq...........~..@.....lq../.... ..#..".&.8.H$..r...J)..jj...&..f.=.9..N9.....'F..8.4.....m...m...m.m..n..&.X..}....S.|.....n........PHaE...J*...4..MjJ.*..nW)..rn3'/.....ks5zY5c...Mgg.5..p..rR{c...p..t\.8.c=..p...X.(.......7....=.........!...H ........(.0...(.q.JT?.b..z].'T...m..vNi.....t....:P.R..H....t.........&?.:.j.51+.S.":j.SK'I.^....}S.i.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCoYactd[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 15424, version 1.1
          Category:downloaded
          Size (bytes):15424
          Entropy (8bit):7.955031150959659
          Encrypted:false
          SSDEEP:384:m5EyqiOPGJUwhVTeoRw1GkdrlRYmvw+61smGEDU:m5E8g8qoRFkrRYmv3+U
          MD5:6796BE151AD7E5B0DF05B7A87454E933
          SHA1:82F778EDEED5948397488FED8B852F2D43D44B14
          SHA-256:C7F87FC278949358A6D1965D9F7AB5A36872086CC62A567C1A47B1A3C865BC5B
          SHA-512:415ED7D5166DE4B8A44E68FEAA6DC259983DB7E49F5D8C401B7001FEB4B0FD44F870F7FFF4AAAB11DB154A7F08E1337EF594331CCCED9A2BCD238A9110D32A91
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVi2ZhZI2eCN5jzbjEETS9weq8-33mZGCoYactd.woff
          Preview: wOFF......<@......r0........................GDEF.......5...@.`..GPOS.......6..../..FGSUB............N.K.OS/2.......Q...`t.B.cmap............%...cvt .......X...X/...fpgm...D...4......".gasp...x............glyf......-...XPtX.dhdmx..5....d........head..5....6...6.*.hhea..6,.......$.z..hmtx..6L........5^.loca..8d............maxp..:T... ... .,.[name..:t.........s=rpost..;P....... .m.dprep..;d.......:z/.Wx......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..3. W.........c.L..k.el....}...6...U..].R.W_{.-.g....`.}.8..]#.9_9$JP..}..9.m%.J)..nV.l.t..w~%*].A..`...V.WK....[.."..:.JK..S.F..t..m+Im..@Z..g9.f...."F..3...N..j...H.#..mq:!.8.A..!.....>.Y.....4.>.U.#..6..xu..i.[Nszf.&]8.(...E.v.....:5..t.J..}.iM.E..$R...o..Y.tG-.B.9...M.9. C!...gy6....m.w..=.!.{....2..C.3..#.2...7.D.L6.T.L...=.).x..^....m.z..>...}.S........}.{?...f.e.y.Xd.eVXi...Xk..6.U.Q..m.u..[.^}......[...........F....k9$.K.F+,S..Jm..)..F..[c...u....)..K.3..Z.....[..j.....7w.o.K..2."c.....B.T...n
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAgM7UvI[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 21468, version 1.1
          Category:downloaded
          Size (bytes):21468
          Entropy (8bit):7.9722703367974255
          Encrypted:false
          SSDEEP:384:870UX21S2zKy6wAJ26lU7P3JoMwv71IAPDH7cq1w/q9oiuyDjZxU0:IX2Eg3o22hv7uEzTwM3jn3
          MD5:AFAA4DD3BE16C6BCF843AF9B7D3C1269
          SHA1:8291C217055AB6F9AAB4FA68DCB980E5FF6D0933
          SHA-256:FA2D129020D0B050ACC77C73F426C38A396D027CECBEA10A89FCBDBB42A82215
          SHA-512:6D2B8BB152F5DC65CD78A4D7F1BE48237B75226311947BFCC638CA55C22F8C51FF40C88A57BAEFE03CCDD1DD5518305F3034019F827CC3F1F9EC59B5305ABED2
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAgM7UvI.woff
          Preview: wOFF......S........$........................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......M...`zf..cmap............S.(Ncvt .......X...X,,..fpgm... ...4......".gasp...T............glyf...`..B...w,./c:hdmx..L|...j......(.head..L....6...6...hhea..M ..."...$....hmtx..MD.........M..loca..O.........}!_.maxp..Q.... ... ...}name..Q.........".A7post..R........ .a.dprep..R.........,...x............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAwM7UvI[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2272, version 1.1
          Category:downloaded
          Size (bytes):2272
          Entropy (8bit):7.2569545173252195
          Encrypted:false
          SSDEEP:48:GEjU2XLO7sWFCpZURsYoy1Wmr9S5437Ui3qupRmtRdvC:GcfXKCp6sSDr7vBpRmfFC
          MD5:B2D2F9AAB8A8C749EB2447EC48C8A232
          SHA1:CDC4B19ECD56BFD42B6208F495900AA1590AD68E
          SHA-256:8BE7E903E9BE50B3E6CEBF82766D9C5FD34FA3A1DB310E6D81D31FA4F920C11A
          SHA-512:BAEA8CAA9A25BC2EC9163AA525E84E6D70DA10C7E01528D93D6A63C1F5ABD872CF6F8316EF1945FE2FD998B8A19FE31FE4627AE77EE6BB6DEDBA2657A3ECCEFC
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLAwM7UvI.woff
          Preview: wOFF........................................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...L...`.S..cmap.......7...X. ^.cvt .......X...X,,..fpgm... ...4......".gasp...T............glyf...`.........O.?hdmx................head...$...6...6...hhea...\..."...$....hmtx................loca................maxp....... ... .7.}name............".A7post........... .a.dprep............,...x.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f~.8.....u..1...<.f........P.........}.}...10...bbP``...c.b........=..x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......x...d.N.Z...`.V.4.<.........f.......`..... .!...:..............................x.]..G.A..g.."@.....q....G...0_...].?......w.=.~........y.}>./..b...Oj.....z.<..p-e.L....4x...-'...[..t.]....9.a...p4.`.].wf....wAte.n5a.q............T"...E..$)..d.un.N."2.u.}./.vk.4z.A.g(,..F.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLCwM7UvI[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 13460, version 1.1
          Category:downloaded
          Size (bytes):13460
          Entropy (8bit):7.94869340291197
          Encrypted:false
          SSDEEP:192:UiJv6KFO/PCK3lbb8LNIhfIA6OcuTUcbe7kRAE/QNtp1DCTF+lIuA+Pzw0mSX7JZ:UgFO/PXpkNIWqTUcKKINtpQAzCSLU0
          MD5:5C9A5A3FF79887B4374D37A4228C20A0
          SHA1:89F8DB0D5C444886CF35C4753819C33997B57C86
          SHA-256:61E02190A4AB99E705E202AC7702F96E5BDCB71ED00981DBC3B34702E1F94A8C
          SHA-512:D0C96BFE6A5676D760D823C7608B1C7A3C28E86F7D7B8D3E22BC62BEB9D443C7A4055ABD225DCBA4843002535312C7002E029AE72B394ECB0C47D49495B13B68
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVj2ZhZI2eCN5jzbjEETS9weq8-19eLCwM7UvI.woff
          Preview: wOFF......4.......].........................GDEF.......J...j...tGPOS.......s...V.y}.GSUB...T...5...6....OS/2.......N...`z...cmap............d..1cvt .......X...X,,..fpgm.......4......".gasp................glyf......$...B...l.hdmx../$...K.......'head../p...6...6...hhea../...."...$...4hmtx../.........(y..loca..1P........&.8.maxp..2`... ... ...}name..2.........".A7post..3`....... .a.dprep..3x........,...x......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x....d.....>=6.......g.5g.x.z.m.6.m.Vp.~.q..;.._.......(2@..B2k.U\.z..-\.~...\..m..q.."B_.l^.c.e.!....qt.1L.d...f...5..f.....O..m....7..q...E..\1?/....s..O...$.O^.....e........j.|<..<.<...._....._....'...1....J..t.. .3.a.t.#..h.0.q.g...D.i.f.sY.B.....d....7.....Y....Mlf+]t....b7{....../..:ZdG...x..q/c..&.L.....&g.r....2W9_....R.J.6G......n.7.b.....G...V...)...."..f.....z.e5..m....=e}.....=..5......}.....u....@.-..41X.....hd..y.+.k.f....mG...~.../..|..>$.g...........[....l7...`9.J.}..f...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVl2ZhZI2eCN5jzbjEETS9weq8-19-7Cxs5[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 19824, version 1.1
          Category:downloaded
          Size (bytes):19824
          Entropy (8bit):7.966412172191744
          Encrypted:false
          SSDEEP:384:OCIjv7cL78483hBfkN2ah2MxeBJ85Amdan/Qn8pLYF0I+51P1C:OxjzK7848PfkN5YMF268Ufp+51dC
          MD5:793E7FC7F6D73062492856A8B4D38E6B
          SHA1:E38CDFD4BD87B1559043953DA023A457A80D6DDF
          SHA-256:2D746559103257896130E9BFD2E8CCDCD5CF2DB67E643082A933067D92BC380E
          SHA-512:BBD2BA1670E8DE456BB403EC19AD4D7B50331BF28098761D013B00DA5FFD6239F3C55D69591C7AC255BEAB757098913DC9531E250D57C0CC5F770395A9274782
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19-7Cxs5.woff
          Preview: wOFF......Mp................................GDEF.............~..GPOS.......2...Bq.d.GSUB...P...5...6....OS/2.......L...`zf.5cmap............S.(Ncvt .......X...X,...fpgm.......4......".gasp...P............glyf...\..;...p..C\.hdmx..F ...n......1.head..F....6...6.5.hhea..F........$...xhmtx..F...........>.loca..Ip........}.a:maxp..KH... ... ...{name..Kh..........<.post..LD....... .m.dprep..LX.........{.ox............@........M.(AAD..!($$I ...OD.....!H.....@..A..V-.Q...Z..:t.gA.....N....K]...[.v..9....g.z.w.....G...K.,....&....9...x..S.%].DwU.....g.6..m.m.m.z.....{...:...K.@..........2..Z..RUK.#.|.... .@"..r%.V$.Wxy/..H8.....j....~.4....,.....j..X3.u.._....................a...sc.{|...o..(.(NIJ.*.hF.Z..t`...d.0.iLg.3.."....g#.......... .8..N....?.G..M......]W.......R[.w.z>v.1..(.\G<5..x..w....<.E5..].Y.=...b.k..b.k.8.m$....o..N...)..L7...s...X.01V.l.+.9g...?OH.gW..C.)...rw%.:v...t..z...H'p..rY.......&.i`.i.....S_...Nz.....]..S.:.v.....E.<.......E[....V..v
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVl2ZhZI2eCN5jzbjEETS9weq8-1967Cxs5[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 2236, version 1.1
          Category:downloaded
          Size (bytes):2236
          Entropy (8bit):7.235007173259487
          Encrypted:false
          SSDEEP:24:yCVCppBFlpr+wOgFI/O4DGwdyhlWFC3h2c4DEqDOS5oT+Y20mfmAtJZ0aubz7lsn:/svF+X/OMsWFC3gc42zhYR0akz7ljs
          MD5:BDDE4FF06850999CDD5A2324608195DA
          SHA1:30FDA79D5FC7C07A5F08F2178E02430999C40862
          SHA-256:FFDE2FE7492517402F9EF908A8DDAAFDE6F4A04B571CD1E45174C88948619680
          SHA-512:1E76D0049B7B33FF44FFE5D37E556031DA03C5E3010180A8036A208D1D5C24269E565834A09B262B743E4ED7523E58235D34080DAB9DE3EAB20FAB3913CFCAF3
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-1967Cxs5.woff
          Preview: wOFF........................................GDEF...........&.F..GPOS.......U...p...GSUB.......5...6....OS/2...D...M...`.S.ocmap.......7...X. ^.cvt .......X...X,...fpgm...$...4......".gasp...X............glyf...d........B.Q^hdmx................head.......6...6.5.hhea...H.......$....hmtx...h............loca...............bmaxp....... ... .7.{name..............<.post........... .m.dprep.............{.ox.c`d`b.c..1 ...A.....a ......M.x.-...0...Kpj..L..4HE.....<...(...6..4..V..0^J..i#...) ,..".'+"(.*.H.... .w.y....[...x.c`d``.b0b0a`qq..a.J.,.aPI/J.fP.I,.cPa`a...........:...x.c`f..8.....u..1...<.f........P...........}.}...10...bbP``...c.b........C.-...x.%................I....X.L"~.MnE.......<$..#..X..6.....*.......x...d.N.Z...`.V.4.<.........f.......`..... .!...:..............................x.]..G.A..g.."@.....q....G...0_...].?......w.=.~........y.}>./..b...Oj.....z.<..p-e.L....4x...-'...[..t.]....9.a...p4.`.].wf....wAte.n5a.q............T"...E..$)..d.un.N."2.u.}./.vk.4z.A.g(,
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ieVl2ZhZI2eCN5jzbjEETS9weq8-19a7Cxs5[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 12560, version 1.1
          Category:downloaded
          Size (bytes):12560
          Entropy (8bit):7.940134038085282
          Encrypted:false
          SSDEEP:384:yFO/PvsA7LpyEA0ovL4/Nz8dlHYxjEQGNC:y2bLpn8vL4Gdlu4bC
          MD5:C3557026491569692D1370C4742A5C64
          SHA1:DA3A430D4DF528D3FDC8FDF073FAA88B2A4738CE
          SHA-256:0DB7668B21E3AF6A69623B9095A8C63105A9EA094B5BD3D0F2B499BA05A4E848
          SHA-512:B4AF1EF57160077B1776840E93222B84660B76518C5F8F7327E047E4DC4307E462744007D0CA44AC70E1846CC4C94C1D8FFA162D16FAA510DFEF8C3FA68B8545
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/ieVl2ZhZI2eCN5jzbjEETS9weq8-19a7Cxs5.woff
          Preview: wOFF......1.......Y.........................GDEF.......J...j...tGPOS.......s...V.y}.GSUB...T...5...6....OS/2.......N...`z..8cmap............d..1cvt .......X...X,...fpgm.......4......".gasp................glyf...... ...?:..R.hdmx..+....L.......'head..+....6...6.5.hhea..,4.......$....hmtx..,T........4.8.loca..-..........G..maxp....... ... ...{name../...........<.post../........ .m.dprep../..........{.ox......Q....ka....6.....1..'B..8...P...i.ah,L.e...>.'w..-|.D.!....`..J..x....d.....>=6.......g.5g.x.z.m.6.m.Vp.~.q..;.._.......(2@..B2k.U\.z..-\.~...\..m..q.."B_.l^.c.e.!....qt.1L.d...f...5..f.....O..m....7..q...E..\1?/....s..O...$.O^.....e........j.|<..<.<...._....._....'...1....J..t.. .3.a.t.#..h.0.q.g...D.i.f.sY.B.....d....7.....Y....Mlf+]t....b7{....../..:ZdG...x..q/c..&.L.....&g.r....2W9_....R.J.6G......n.7.b.....G...V...)...."..f.....z.e5..m....=e}.....=..5......}.....u....@.-..41X.....hd..y.+.k.f....mG...~.../..|..>$.g...........[....l7...`9.J.}..f...
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\it[1].htm
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:HTML document, UTF-8 Unicode text, with CRLF line terminators
          Category:downloaded
          Size (bytes):29967
          Entropy (8bit):4.044091095615121
          Encrypted:false
          SSDEEP:384:BHHFmUpR5yA2Cfr8EHJIY7b9dVPeNyVErt3j1z:BcUP54CfrxHJd9jeNRT1
          MD5:A55AF58CF1D627EF2C2F69F2A4F14CFB
          SHA1:CB0EFF1B9AD5597B71CA6180411FFD934C4EAEBC
          SHA-256:49D936DDAB5B8428125A3670EF832A7097532670BDB3D2670DE6B4EA98A4344C
          SHA-512:601F6E002C9D4F62948E7CCEF224F2DA679963018A166955FA75902C84B85152E145DD35EC118F0266918D3C8EA3DF7D24D4FEDFCA92749E954965FF56B155CD
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/
          Preview: <!DOCTYPE html>..<html lang="it_IT">....<head>.. <meta charset="UTF-8">.. <meta name="viewport" content="width=device-width, initial-scale=1">.. <meta http-equiv="X-UA-Compatible" content="IE=edge">.. <title>1K Daily Profit - Il Sito Ufficiale</title>.. <meta name="description" content="1K Daily Profit - Erhalte exklusiven Zugriff auf Industrie-Einblicke sowie effektive Tipps f.r die Maximierung deiner Profite.">.. .... <link rel="apple-touch-icon" sizes="57x57" href="images/apple-touch-icon-57x57.png">.. <link rel="apple-touch-icon" sizes="60x60" href="images/apple-touch-icon-60x60.png">.. <link rel="apple-touch-icon" sizes="72x72" href="images/apple-touch-icon-72x72.png">.. <link rel="apple-touch-icon" sizes="76x76" href="images/apple-touch-icon-76x76.png">.. <link rel="apple-touch-icon" sizes="114x114" href="images/apple-touch-icon-114x114.png">.. <link rel="apple-touch-icon" sizes="120x120" href="images/apple-touch-icon-120x120.png">.. <link r
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\jquery.min[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with very long lines, with CRLF line terminators
          Category:downloaded
          Size (bytes):97168
          Entropy (8bit):5.373735148795817
          Encrypted:false
          SSDEEP:1536:jYE1JVoiB9JqZdXXe2pD3PgoIiulrUdTJ5Fk/zkZ4HjL5o8srOaS9TwDhb7/Jp96:y4J+03jL5TCOauTwDhFdnCVQNLa98Hrc
          MD5:618538B4AB9639D444E962729A927F15
          SHA1:DACC1F76630A9708ADD066819B1AABF8DCE01056
          SHA-256:27D92130C0321DAD5A03760FD5AC98A3D04ED4C94D88418FE6D50DA1F7FC5CBE
          SHA-512:BCB6754EA246939A19A917CC0B810E1753C1B0F1A8B1B7E652128EF15DEE4FC79111E4D88FE12F9188449A307E82240D0261AF402D783428EDFE5785C860372D
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/jquery.min.js
          Preview: /*! jQuery v1.12.4 | (c) jQuery Foundation | jquery.org/license */..!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=a.document,e=c.slice,f=c.concat,g=c.push,h=c.indexOf,i={},j=i.toString,k=i.hasOwnProperty,l={},m="1.12.4",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return e.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:e.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a){return n.each(this,a)},map:function(a){return this.pushStack(n.map(this,function(b,c){return a.c
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\preloader[1].gif
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:GIF image data, version 89a, 530 x 260
          Category:downloaded
          Size (bytes):2391
          Entropy (8bit):7.690188443892358
          Encrypted:false
          SSDEEP:48:jAPcWIczhk9hDIIThAAPcWIc421qIITdVAPcWIcpzz9x9ngqPIITV:0EW1YUohNEWYolodeEWpBTngqgoV
          MD5:9129C06831233D5178D8E61C7F4FB208
          SHA1:5EFB0656C4941AF51E32C90AFFABB80CD445C5AF
          SHA-256:D05AE8164206B2CEF6B7890AF6551AA59ED403820877533583EC0916D2A6EDD1
          SHA-512:03FF425E321422FBB751597CEDAD9316D29E41D550071C196D778D37D90C9804549CBA80131E4CB643780985F6EEA08FA42AAA5B3648C450F98FB9E6E38A938D
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/images/preloader.gif
          Preview: GIF89a.......':.G..X.....!..NETSCAPE2.0.....!.......,...........................H........L..............L*.....J.....j..........N....................(8HXhx..........)9IYiy..........*:JZjz..........+;K[k{..........,<L\l|..........-=M]m}...........>N^n~........../?O_o..........0......<.0....:|.1...+Z..1....;z..2..$K.<.2..,[.|.3..4k..3..<{...4..D..=.4..L.:}.5..T.Z..5..\.z..6..d.=.6..2..}.........W...x...VL.......X.^....U.....r.;N.x...~3G.B.r..G....K..O.m..n.....v..Al..A.{.wp.....{w].......8..#p^.zt..8....v,.+.n.....oK.sz...[y. ..........~.......G`g..f...&....5...E.`_.Fa............:.au$...|+.hDys....U.c.:..c.>..d.B.Id.F..d.J..d.N>.e.RNIe.V^.e.Zn.e.^~.f.b.If.f..f.j..f.n..g.r.Ig.v.g.z..g.~..h...Jh....h....h..>.i..NJi..^.i..n.i..~.j...Jj....j....j....k...Jk...k....k....l...Kl!...!.......,...........................H........L..............L*.....J.....j..........N....................(8HXhx..........)9IYiy..........*:JZjz..........+;K[k{.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\scripts[1].js
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):3513
          Entropy (8bit):4.5241340586491114
          Encrypted:false
          SSDEEP:48:NSKMKZXIeDjObNo7CX92oDTCsAEmUtI2HkxkFukMDDbHXm29f1mdd1VgL0+dT/Zc:JZW+OT4EmUrkxAuD5mJqZBtmJSP7dtK
          MD5:435512EF713E421EFB2C7F0895DD6D23
          SHA1:FAC8029A65E8ED3FB55C74BFC099A0713BB12E10
          SHA-256:9AD6159A21B10041EDA86EF6EB468EE2AEED4889BD5FE76FF68C2A8F3BD70793
          SHA-512:B6A359DC926C7BC9B5B6619A0B77DD6CFB601827B57B6164CA3645EAF0D92A2EAFE59FB51004A9B715A616F8B5DD73407E1D8A8D6C14E5362D3F0733312EFA70
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/js/scripts.js
          Preview: $(document).ready(function() {.... ...... if ($('input[type="radio"]:checked').length) {.. $('input[type="radio"]:checked').parent("label").addClass('checked');.. }.. if ($('input[type="checkbox"]:checked').length) {.. $('input[type="checkbox"]:checked').parent("label").addClass('checked');.. }.... $('label input[type="radio"]').change(.. function(){.. var el = $(this);.... radioRender(el);.. }.. );.. $('label input[type="checkbox"]').change(.. function(){.. var el = $(this);.. var parent = el.parent('label');.. parent.toggleClass('checked');.. }.. );.... $('.to_top_button').click(function(){.. $('body, html').animate({scrollTop:0}, 300);.. return false;.. });.... $('.jv_nav li a').click(function(){.. var target = $($(this).attr('href')).offset().top-30;.. $('body, html').animate({scrollTop:target}, 300);.. return false;.
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\KFOjCnqEu92Fr1Mu51TLBCc0CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 16636, version 1.1
          Category:downloaded
          Size (bytes):16636
          Entropy (8bit):7.962803001876663
          Encrypted:false
          SSDEEP:384:LD/qzsqJAYE4gAt4m/g/NRS4DpFEq7LA9:LD/5qe4gHwg/m4DzfLA9
          MD5:782020150FFDD6E4F078C2E980B67261
          SHA1:7BD6594DDF82835143D6E30519C598A20BB93BBB
          SHA-256:B6C692DB5C8D16B786E56C06311035F1B0D8869EE46BB3D1FA2F224833F25847
          SHA-512:8BDEBDEA6DC775267D3D857A5BC5B817245EAA7B7AEF0676382A9E565A916F88060100ACBD09F2075D3D3D54820ED3C9718FBE5D3A24E2C6F6F408AE710122E8
          Malicious:false
          Reputation:low
          IE Cache URL:http://heygamersnort.at/index/it/fonts/KFOjCnqEu92Fr1Mu51TLBCc0CsLKlA.woff
          Preview: wOFF......@.......u.........................GDEF.......5...@.`..GPOS.......:..../...GSUB............N.K.OS/2.......Q...`w!B.cmap............%...cvt .......Z...Z...=fpgm...L...3......#.gasp................glyf......1...\....(hdmx..:D...g....@AO8head..:....6...6.G.Whhea..:...."...$.H..hmtx..;.........O@.ploca..=..........Z.5maxp..?.... ... .,..name..?(..........>.post..@........ .a.dprep..@ .......8...Cx......@...y...Y.J A..L.uagD....9]....'~].SD.......j...x..C..W....Y....jY...V..m.v..m.v>....<3.~O..w.k..t.].8...Z4r..-.m..FO.j.|.(AI.g[4q,.J.R......Q.BW..J..^.@#MlPafj.)Bu.j.P_..7e...E.)...Tg:...4..@....@V.j...2!..i..D.l.H5@......g#d..tP.vH.=pm..o..q.Y..dyVCf.....*..i..Y......T.,.....>...S..>..*...I.;...dVl..;.,wX...o1....Z.Aj.A>.\.i5@ZC.o..>...lO%.u.g<../j..F.k..f.k..V^.W..uox.[...w..}...W......g..._....j...:.....z....f.Q..g.I..f..f.m...o...[i.5.Yo...T.Q.N.......a... x.2n.._..C.ta..2...f....nd\m.56..P.Z....q.d=....>......Vj.{.psW.f.D..S*2.....l.*TJu
          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\KFOjCnqEu92Fr1Mu51TLBCc1CsLKlA[1].woff
          Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
          File Type:Web Open Font Format, TrueType, length 7600, version 1.1
          Category:downloaded
          Size (bytes):7600
          Entropy (8bit):7.876884906727642
          Encrypted:false
          SSDEEP:192:01YakZfHqIDsROIr8+ZqAP7T5UVjjMok4OZZKApADd7bSxH0Z:OqqIDsROIrvmv3spA5XSw
          MD5:C5BF9E4C05E80BC27BAA33260ABE7C9E
          SHA1:CD0130AB656D24A51ACD671F332CFA7EC0E7FD0A