查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Baidu | 20180511 | 1.0.0.2 | |
Avast | 20180515 | 18.4.3895.0 | |
Tencent | 20180515 | 1.0.0.1 | |
Kingsoft | 20180515 | 2013.8.14.323 | |
McAfee | 20180515 | 6.0.6.653 |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://trans.hiido.com/zhsdkinfo.php?ver=1&EC=1 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://config.hiido.com/api/getDeviceConfig?sys=10&appkey=yygame&deviceid=78a6567f4e2f39ced876d23b733daaf3&hmid=b70d7fe9151d4aabaff10db0102674db&EC=1 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=6e5f37f913fd4df4bfb0819fc352bda0&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstartup%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=4aefe57387fe47c0874fa98171c1468e&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fstart%26eid_desc%3DygUpdateDisp%252F%25E5%2590%25AF%25E5%258A%25A8%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://sz.duowan.com/s/lobby/config/yygame_downloader.json | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=bacfb62999e3457dbfb24d948df2a40e&sdkver=ya-cpp-2.2.4&key=9094d03c57d70f7f6b3ae24bfd5efd0b&time=1620947546&ati=20210514071226&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fconfig%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E9%2585%258D%25E7%25BD%25AE%252F%25E8%258E%25B7%25E5%258F%2596%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a49cf8a2cb39456d8fb87f3aadc61d87&sdkver=ya-cpp-2.2.4&key=9094d03c57d70f7f6b3ae24bfd5efd0b&time=1620947546&ati=20210514071226&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdetect%2Fmissing%26eid_desc%3DygUpdateDisp%252F%25E6%25A3%2580%25E6%25B5%258B%252F%25E7%259B%25AE%25E6%25A0%2587%25E7%2589%2588%25E6%259C%25AC%25E4%25B8%258D%25E5%25AD%2598%25E5%259C%25A8%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=75bdfa7217404ac99a30815f37d3c154&sdkver=ya-cpp-2.2.4&key=9094d03c57d70f7f6b3ae24bfd5efd0b&time=1620947546&ati=20210514071226&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdownload%2Frepeat%2F1%26eid_desc%3DygUpdateDisp%252F%25E4%25B8%258B%25E8%25BD%25BD%252F%25E9%2587%258D%25E8%25AF%2595%252F%25E6%25AC%25A1%25E6%2595%25B0%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=cb7b040acd97499ea154e79f9bfd8538&sdkver=ya-cpp-2.2.4&key=9d23b940365e4685b277dc0faeef819f&time=1620947584&ati=20210514071304&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdownload%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E4%25B8%258B%25E8%25BD%25BD%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a00973775a9a4904b0969294489d2e1c&sdkver=ya-cpp-2.2.4&key=f91addbfd80dc30fa777827ad6f22243&time=1620947588&ati=20210514071308&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Funzip%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E8%25A7%25A3%25E5%258E%258B%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=0d1ff120427c41ba927fce850910e380&sdkver=ya-cpp-2.2.4&key=f91addbfd80dc30fa777827ad6f22243&time=1620947588&ati=20210514071308&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fexecute%2Fupdate%26eid_desc%3DygUpdateDisp%252F%25E6%2589%25A7%25E8%25A1%258C%25E6%259B%25B4%25E6%2596%25B0%25E7%25A8%258B%25E5%25BA%258F%252F%25E6%259B%25B4%25E6%2596%25B0%25E6%25A8%25A1%25E5%25BC%258F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=6d47ee853d954db0b57d771bef79fb5e&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fexit%26eid_desc%3DygUpdateDisp%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://stat.game.yy.com/data.do | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a80c2490bb3d4671be2dee6e0876dd8a&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&dur=52484&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dheartbeat%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=f36a51f4f4d84a4c9a9d3fd17d60e8b4&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&dur=52484&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dendup%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://sz.duowan.com/s/lobby/config/schedule_config.json | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=178a81b6e6bb4229b21cd535fd1dff0c&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstartup%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a04e67fb1d8c4520bba908432dda1d78&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fstart%2Fupdate%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E5%2590%25AF%25E5%258A%25A8%252F%25E6%259B%25B4%25E6%2596%25B0%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=3f7d9c8440e844768950c2a9a1d0ac12&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Frequest%2Fsuccess%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E8%25AF%25B7%25E6%25B1%2582%25E9%2585%258D%25E7%25BD%25AE%25E4%25BF%25A1%25E6%2581%25AF%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=1ec25b1e7be94f0c87cdfa42c75b8bf9&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071312&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fschedule%2Fstart%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E8%25AE%25A1%25E5%2588%2592%25E4%25BB%25BB%25E5%258A%25A1%252F%25E5%25BC%2580%25E5%25A7%258B%25E5%25AE%2589%25E8%25A3%2585%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=d279b44e82654bb2baf13b95a3d9febb&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fschedule%2Finstall%2Fsuccess%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E8%25AE%25A1%25E5%2588%2592%25E4%25BB%25BB%25E5%258A%25A1%252F%25E5%25AE%2589%25E8%25A3%2585%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=425f59b1f21e4010b4085cfbd5a9d350&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fexit%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=720ea3279f81480f9b67fd8786ac0355&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&dur=1922&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dheartbeat%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=13e9c6c0b09845ae8a2e670472dafbc3&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&dur=1922&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dendup%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://trans.hiido.com/zhsdkinfo.php?ver=1&EC=1 |
request | GET http://config.hiido.com/api/getDeviceConfig?sys=10&appkey=yygame&deviceid=78a6567f4e2f39ced876d23b733daaf3&hmid=b70d7fe9151d4aabaff10db0102674db&EC=1 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=6e5f37f913fd4df4bfb0819fc352bda0&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstartup%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=4aefe57387fe47c0874fa98171c1468e&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fstart%26eid_desc%3DygUpdateDisp%252F%25E5%2590%25AF%25E5%258A%25A8%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://sz.duowan.com/s/lobby/config/yygame_downloader.json |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=bacfb62999e3457dbfb24d948df2a40e&sdkver=ya-cpp-2.2.4&key=9094d03c57d70f7f6b3ae24bfd5efd0b&time=1620947546&ati=20210514071226&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fconfig%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E9%2585%258D%25E7%25BD%25AE%252F%25E8%258E%25B7%25E5%258F%2596%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a49cf8a2cb39456d8fb87f3aadc61d87&sdkver=ya-cpp-2.2.4&key=9094d03c57d70f7f6b3ae24bfd5efd0b&time=1620947546&ati=20210514071226&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdetect%2Fmissing%26eid_desc%3DygUpdateDisp%252F%25E6%25A3%2580%25E6%25B5%258B%252F%25E7%259B%25AE%25E6%25A0%2587%25E7%2589%2588%25E6%259C%25AC%25E4%25B8%258D%25E5%25AD%2598%25E5%259C%25A8%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=75bdfa7217404ac99a30815f37d3c154&sdkver=ya-cpp-2.2.4&key=9094d03c57d70f7f6b3ae24bfd5efd0b&time=1620947546&ati=20210514071226&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdownload%2Frepeat%2F1%26eid_desc%3DygUpdateDisp%252F%25E4%25B8%258B%25E8%25BD%25BD%252F%25E9%2587%258D%25E8%25AF%2595%252F%25E6%25AC%25A1%25E6%2595%25B0%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://yygame.duowan.com/yydt/Setup/popup/yygame_popup100901.7z |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=cb7b040acd97499ea154e79f9bfd8538&sdkver=ya-cpp-2.2.4&key=9d23b940365e4685b277dc0faeef819f&time=1620947584&ati=20210514071304&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdownload%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E4%25B8%258B%25E8%25BD%25BD%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a00973775a9a4904b0969294489d2e1c&sdkver=ya-cpp-2.2.4&key=f91addbfd80dc30fa777827ad6f22243&time=1620947588&ati=20210514071308&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Funzip%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E8%25A7%25A3%25E5%258E%258B%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=0d1ff120427c41ba927fce850910e380&sdkver=ya-cpp-2.2.4&key=f91addbfd80dc30fa777827ad6f22243&time=1620947588&ati=20210514071308&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fexecute%2Fupdate%26eid_desc%3DygUpdateDisp%252F%25E6%2589%25A7%25E8%25A1%258C%25E6%259B%25B4%25E6%2596%25B0%25E7%25A8%258B%25E5%25BA%258F%252F%25E6%259B%25B4%25E6%2596%25B0%25E6%25A8%25A1%25E5%25BC%258F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=6d47ee853d954db0b57d771bef79fb5e&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fexit%26eid_desc%3DygUpdateDisp%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | POST http://stat.game.yy.com/data.do |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a80c2490bb3d4671be2dee6e0876dd8a&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&dur=52484&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dheartbeat%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=f36a51f4f4d84a4c9a9d3fd17d60e8b4&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&dur=52484&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dendup%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc |
request | GET http://sz.duowan.com/s/lobby/config/schedule_config.json |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=178a81b6e6bb4229b21cd535fd1dff0c&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstartup%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a04e67fb1d8c4520bba908432dda1d78&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fstart%2Fupdate%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E5%2590%25AF%25E5%258A%25A8%252F%25E6%259B%25B4%25E6%2596%25B0%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=3f7d9c8440e844768950c2a9a1d0ac12&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Frequest%2Fsuccess%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E8%25AF%25B7%25E6%25B1%2582%25E9%2585%258D%25E7%25BD%25AE%25E4%25BF%25A1%25E6%2581%25AF%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=1ec25b1e7be94f0c87cdfa42c75b8bf9&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071312&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fschedule%2Fstart%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E8%25AE%25A1%25E5%2588%2592%25E4%25BB%25BB%25E5%258A%25A1%252F%25E5%25BC%2580%25E5%25A7%258B%25E5%25AE%2589%25E8%25A3%2585%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=d279b44e82654bb2baf13b95a3d9febb&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fschedule%2Finstall%2Fsuccess%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E8%25AE%25A1%25E5%2588%2592%25E4%25BB%25BB%25E5%258A%25A1%252F%25E5%25AE%2589%25E8%25A3%2585%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=425f59b1f21e4010b4085cfbd5a9d350&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fexit%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=720ea3279f81480f9b67fd8786ac0355&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&dur=1922&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dheartbeat%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | GET http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=13e9c6c0b09845ae8a2e670472dafbc3&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&dur=1922&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dendup%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 |
request | POST http://stat.game.yy.com/data.do |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\duowan\yygame\popup\package\0.0.8\BoxGameDaemonTask.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\duowan\yygame\popup\package\0.0.8\popup\hjGameUpdate.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\duowan\yygame\popup\package\0.0.8\BoxGameDaemonTask.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\duowan\yygame\popup\package\0.0.8\popup\hjGameUpdate.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\duowan\yygame\popup\package\0.0.8\BoxGameDaemonTask.exe |
wmi | select * from Win32_VideoController |
wmi | select * from Win32_OperatingSystem |
wmi | select * from Win32_SoundDevice |
wmi | select * from Win32_LogicalDisk |
wmi | SELECT * FROM Win32_DiskDrive WHERE InterfaceType = 'IDE' OR InterfaceType = 'SCSI' |
wmi | SELECT * FROM Win32_NetworkAdapter |
wmi | select * from Win32_DiskDrive |
wmi | SELECT * FROM Win32_BaseBoard |
wmi | SELECT * FROM Win32_BIOS |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620969145.877374 Process32NextW |
process_name:
892b15d5d40b45c870213bd166ff88c2.exe
snapshot_handle: 0x000002c0 process_identifier: 580 |
success | 1 | 0 |
Zillya | Dropper.AgentCRTD.Win32.10133 |
TrendMicro-HouseCall | Suspicious_GEN.F47V0422 |
Ikarus | not-a-virus:Downloader.YgData |
wmi | select * from Win32_LogicalDisk |
wmi | SELECT * FROM Win32_BIOS |
host | 172.217.24.14 | |||
host | 203.208.41.65 | |||
host | 203.208.41.98 |
file | C:\Windows\Tasks\HuanjuGameUpdate.job |
dead_host | 172.217.27.142:443 |
dead_host | 203.208.41.65:80 |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49185 | 119.41.210.238 yygame.duowan.com | 80 |
192.168.56.101 | 49177 | 121.11.220.194 config.hiido.com | 80 |
192.168.56.101 | 49207 | 121.11.220.194 config.hiido.com | 80 |
192.168.56.101 | 49180 | 124.225.134.229 sz.duowan.com | 80 |
192.168.56.101 | 49201 | 124.225.134.229 sz.duowan.com | 80 |
192.168.56.101 | 49174 | 14.17.109.17 trans.hiido.com | 80 |
192.168.56.101 | 49178 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49179 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49181 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49182 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49183 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49188 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49189 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49191 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49192 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49198 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49199 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49206 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49208 | 183.36.1.203 ylog.hiido.com | 80 |
192.168.56.101 | 49209 | 183.36.1.203 ylog.hiido.com | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49713 | 114.114.114.114 | 53 |
192.168.56.101 | 50002 | 114.114.114.114 | 53 |
192.168.56.101 | 50568 | 114.114.114.114 | 53 |
192.168.56.101 | 53210 | 114.114.114.114 | 53 |
192.168.56.101 | 53237 | 114.114.114.114 | 53 |
192.168.56.101 | 53380 | 114.114.114.114 | 53 |
192.168.56.101 | 57236 | 114.114.114.114 | 53 |
192.168.56.101 | 57756 | 114.114.114.114 | 53 |
192.168.56.101 | 58367 | 114.114.114.114 | 53 |
192.168.56.101 | 58970 | 114.114.114.114 | 53 |
192.168.56.101 | 60384 | 114.114.114.114 | 53 |
192.168.56.101 | 61680 | 114.114.114.114 | 53 |
192.168.56.101 | 62318 | 114.114.114.114 | 53 |
192.168.56.101 | 62912 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
192.168.56.101 | 50534 | 224.0.0.252 | 5355 |
192.168.56.101 | 51963 | 224.0.0.252 | 5355 |
URI | Data |
---|---|
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=425f59b1f21e4010b4085cfbd5a9d350&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fexit%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=425f59b1f21e4010b4085cfbd5a9d350&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071313&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fexit%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=6e5f37f913fd4df4bfb0819fc352bda0&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstartup%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=6e5f37f913fd4df4bfb0819fc352bda0&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstartup%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://config.hiido.com/api/getDeviceConfig?sys=10&appkey=yygame&deviceid=78a6567f4e2f39ced876d23b733daaf3&hmid=b70d7fe9151d4aabaff10db0102674db&EC=1 | GET /api/getDeviceConfig?sys=10&appkey=yygame&deviceid=78a6567f4e2f39ced876d23b733daaf3&hmid=b70d7fe9151d4aabaff10db0102674db&EC=1 HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: config.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a80c2490bb3d4671be2dee6e0876dd8a&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&dur=52484&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dheartbeat%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=a80c2490bb3d4671be2dee6e0876dd8a&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&dur=52484&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dheartbeat%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://sz.duowan.com/s/lobby/config/yygame_downloader.json | GET /s/lobby/config/yygame_downloader.json HTTP/1.1 Host: sz.duowan.com Accept: */* |
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=cb7b040acd97499ea154e79f9bfd8538&sdkver=ya-cpp-2.2.4&key=9d23b940365e4685b277dc0faeef819f&time=1620947584&ati=20210514071304&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdownload%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E4%25B8%258B%25E8%25BD%25BD%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=cb7b040acd97499ea154e79f9bfd8538&sdkver=ya-cpp-2.2.4&key=9d23b940365e4685b277dc0faeef819f&time=1620947584&ati=20210514071304&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fdownload%2Fsuccess%26eid_desc%3DygUpdateDisp%252F%25E4%25B8%258B%25E8%25BD%25BD%252F%25E6%2588%2590%25E5%258A%259F%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://stat.game.yy.com/data.do | POST /data.do HTTP/1.1 Connection: Keep-Alive User-Agent: HttpPost by ygdata_report Content-Length: 326 Host: stat.game.yy.com |
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=6d47ee853d954db0b57d771bef79fb5e&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fexit%26eid_desc%3DygUpdateDisp%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=6d47ee853d954db0b57d771bef79fb5e&sdkver=ya-cpp-2.2.4&key=dfc321d541737d8dd9ceb79a1557c4da&time=1620947591&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fexit%26eid_desc%3DygUpdateDisp%252F%25E9%2580%2580%25E5%2587%25BA%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=a04e67fb1d8c4520bba908432dda1d78&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fstart%2Fupdate%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E5%2590%25AF%25E5%258A%25A8%252F%25E6%259B%25B4%25E6%2596%25B0%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=a04e67fb1d8c4520bba908432dda1d78&sdkver=ya-cpp-2.2.5&key=63a96b9419cf921ce9452a308fb16752&time=1620947594&ati=20210514071311&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=BoxGameDaemonTask-3.9.5470.0.20170516.30903&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3Dstatus%2Fstart%2Fupdate%26eid_desc%3D%25E7%258A%25B6%25E6%2580%2581%252F%25E5%2590%25AF%25E5%258A%25A8%252F%25E6%259B%25B4%25E6%2596%25B0%26sdk_ver%3Dya-cpp-2.2.5%26session_id%3D081aae1b-6e96-49ff-84a9-dede80a1acf8 HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
http://ylog.hiido.com/c.gif?act=zhwebevent&smkdata=0&EC=1&action=4aefe57387fe47c0874fa98171c1468e&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fstart%26eid_desc%3DygUpdateDisp%252F%25E5%2590%25AF%25E5%258A%25A8%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc | GET /c.gif?act=zhwebevent&smkdata=0&EC=1&action=4aefe57387fe47c0874fa98171c1468e&sdkver=ya-cpp-2.2.4&key=b3fc00467d10208e22025506e77f5fec&time=1620947538&ati=20210514071215&cha=from_push&hiido_mid=b70d7fe9151d4aabaff10db0102674db&ive=1.0.0.5-ygUpdateDisp&lla=zh_cn&mid=78a6567f4e2f39ced876d23b733daaf3&os=Windows7&pro=yygame&rso=from_push&extra=dty%3Dpas%26eid%3DygUpdateDisp%2Fstart%26eid_desc%3DygUpdateDisp%252F%25E5%2590%25AF%25E5%258A%25A8%26sdk_ver%3Dya-cpp-2.2.4%26session_id%3D5b1476f4-3788-4ee4-a72a-4b2488fb10cc HTTP/1.1 Accept: */* Content-Type: application/octet-stream Connection: Close Host: ylog.hiido.com Cache-Control: no-cache Content-Length: 0 |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts