| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!B3124EA7826C | 20200928 | 6.0.6.653 |
| Alibaba | AdWare:Win32/Wews87.755d9791 | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:AdwareSig [Adw] | 20200929 | 18.4.3895.0 |
| Tencent | 20200929 | 1.0.0.1 | |
| Kingsoft | 20200929 | 2013.8.14.323 | |
| CrowdStrike | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620918295.375124 IsDebuggerPresent |
failed | 0 | 0 | |
|
1620918314.812499 IsDebuggerPresent |
failed | 0 | 0 | |
|
1620918341.031499 IsDebuggerPresent |
failed | 0 | 0 |
| section | .ndata |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:3838712985&cup2hreq=24211bbd0443a72ec9189576cce3cdfab083b0959ab9bf6b1c08ffda2854f19b | ||||||
| request | GET http://a.clickdata.37wan.com/controller/istat.controller.php?item=8133tay6p9&platform=37wan&game_id=537&ext_1=2&ext_2=wd_37cs&ext_3=922608&ext_4=D4EFBC1F5B214983822B6449105E7831&ext_5=658b420402848a89d11120ab1cc20569&ext_6=2&browser_type=3000 |
| request | GET http://gameapp.37.com/controller/client.php?game_id=537&tpl_type=game&refer=wd_37cs&uid=922608&version=3000&installtime=20210513&runcount=1&curtime=20210513200514&showlogintype=3®times=1&pagetype=1&thirdlogin=1 |
| request | GET http://img1.37wanimg.com/syol/css/client/game.css?t=1620889632 |
| request | GET http://d.wanyouxi7.com/yx/syol/wd_37cs/922608/app.ini |
| request | GET http://ptres.37.com/js/sq/widget/sq.login.js?t=20210413091738 |
| request | GET http://ptres.37.com/js/sq/lib/sq.core.js?t=20140304 |
| request | GET http://img2.37wanimg.com/2019/04/16181600wKssp.jpg |
| request | GET http://img1.37wanimg.com/syol/js/client/game.js?t=1620889632 |
| request | GET http://ptres.37.com/js/sq/widget/sq.tab.js |
| request | GET http://img1.37wanimg.com/syol/css/client/game/log-bg.jpg |
| request | GET http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game |
| request | GET http://img1.37wanimg.com/syol/css/client/game/check-on.png |
| request | GET http://img1.37wanimg.com/syol/css/client/game/btn-log.png |
| request | GET http://img1.37wanimg.com/syol/css/client/game/btn-to-reg.png |
| request | GET http://img1.37wanimg.com/syol/css/client/game.css?t=1620889636 |
| request | GET http://ptres.37.com/js/sq/widget/sq.clientclass2.js?t=1620889636 |
| request | GET http://img1.37wanimg.com/syol/js/client/game.js?t=1620889636 |
| request | GET http://img1.37wanimg.com/syol/css/client/game/reg-bg.jpg |
| request | GET http://img1.37wanimg.com/syol/css/client/game/btn-reg.png |
| request | GET http://ptres.37.com/js/sq/widget/sq.statis.js |
| request | GET http://img1.37wanimg.com/syol/css/client/game/btn-to-log.png |
| request | GET http://img1.37wanimg.com/syol/css/client/game/37logo.png |
| request | GET http://img1.37wanimg.com/syol/css/client/game/kv-a.png |
| request | GET http://img1.37wanimg.com/www2015/images/common/third-logo-24.png |
| request | GET http://gameapp.37.com/controller/ |
| request | GET http://ptres.37.com/js/sq/widget/sq.dialog2015.js?t=1620907541692&_=1620907541692 |
| request | GET http://a.clickdata.37wan.com/controller/istat.controller.php?platform=37wan&item=u3tfl5ftfl&game_id=537&sid=&position=1&ext_1=4&ext_2=wd_37cs&ext_3=922608&ext_4=&ext_5=gy&ext_6=&login_account=&browser_type=&user_ip=&refer=wd_37cs&uid=922608&page=4&t=1620907540551 |
| request | GET http://img1.37wanimg.com/syol/css/client/game/kv-a-on.png |
| request | GET http://regapi.37.com/proxy_yk.html |
| request | GET http://img1.37wanimg.com/www/css/images/common/dialog2/bg-dialog-avatar.png?v=1 |
| request | GET http://cm.he2d.com/1/ |
| request | GET http://img1.37wanimg.com/www/css/images/common/ico.png |
| request | GET http://img1.37wanimg.com/www2015/images/reglog/200x42.png?v=1 |
| request | GET http://ptres.37.com/js/sq/lib/sq.core.js |
| request | GET http://cookiem.37.com/sys/?u=LtCcYDsmZnYBAAAAWFhU&fdata= |
| request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAeYNgOt45kIIZygDCe8imw%3D |
| request | GET http://a.clickdata.37wan.com/controller/istat.controller.php?item=8133tay6p9&platform=37wan&game_id=537&ext_1=4&ext_2=wd_37cs&ext_3=922608&ext_4=D4EFBC1F5B214983822B6449105E7831&ext_5=658b420402848a89d11120ab1cc20569&ext_6=2&browser_type=3000 |
| request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR0tOcjGcdlkhVARHvHzj6Qwhh26wQUpI3lvnx55HAjbS4pNK0jWNz1MX8CEAUuRglrDLAjXSvUqBHFXTo%3D |
| request | GET http://img1.37wanimg.com/syol/css/client/game/btn-reg-h.png |
| request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
| request | HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620889216&mv=m&mvi=1&pl=23&shardbypass=yes |
| request | HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=cc12ca6065264b10&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620889458&mv=m&mvi=3 |
| request | GET http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=cc12ca6065264b10&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620889458&mv=m&mvi=3 |
| request | GET https://my.37.com/httpsEnable.gif?t=1620907541957 |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:3838712985&cup2hreq=24211bbd0443a72ec9189576cce3cdfab083b0959ab9bf6b1c08ffda2854f19b |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:3838712985&cup2hreq=24211bbd0443a72ec9189576cce3cdfab083b0959ab9bf6b1c08ffda2854f19b |
| name | RT_VERSION | language | LANG_CHINESE | offset | 0x00043a88 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000224 | ||||||||||||||||||
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\sq.clientclass2[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\sq.login[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\sq.statis[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\sq.dialog2015[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\37游戏中心\灭神\灭神.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQSDCVAE\game[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\syol\uninst.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQSDCVAE\sq.tab[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\37游戏中心\灭神\卸载灭神.lnk |
| file | C:\Users\Administrator.Oskar-PC\Desktop\灭神.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\syol\wdgq_wqeqd.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\game[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\sq.core[2].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\sq.core[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\syol\config.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\sq.core[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsw6E86.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsw6E86.tmp\FindProcDLL.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\37游戏中心\灭神\卸载灭神.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\37游戏中心\灭神\灭神.lnk |
| file | C:\Users\Administrator.Oskar-PC\Desktop\灭神.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsw6E86.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsw6E86.tmp\FindProcDLL.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\syol\config.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\syol\wdgq_wqeqd.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\syol\uninst.exe |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620918300.250124 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| host | 172.217.24.14 | |||
| host | 93.184.220.29 | |||
| process | wdgq_wqeqd.exe | useragent | HTTPDownloader | ||||||
| process | wdgq_wqeqd.exe | useragent | Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) | ||||||
| dead_host | 172.217.160.110:443 |
| MicroWorld-eScan | Gen:Variant.Adware.Ursu.372699 |
| FireEye | Generic.mg.b3124ea7826c1d66 |
| CAT-QuickHeal | Application.Agent.ZZ5 |
| McAfee | Artemis!B3124EA7826C |
| Cylance | Unsafe |
| VIPRE | Trojan.Win32.Generic!BT |
| K7AntiVirus | Adware ( 004fef751 ) |
| Alibaba | AdWare:Win32/Wews87.755d9791 |
| K7GW | Adware ( 004fef751 ) |
| Cybereason | malicious.7826c1 |
| Arcabit | Trojan.Adware.Ursu.D5AFDB |
| Symantec | SMG.Heur!gen |
| APEX | Malicious |
| Kaspersky | not-a-virus:HEUR:AdWare.Win32.Generic |
| BitDefender | Gen:Variant.Adware.Ursu.372699 |
| NANO-Antivirus | Trojan.Win32.Wews87.fofick |
| Avast | Win32:AdwareSig [Adw] |
| Ad-Aware | Gen:Variant.Adware.Ursu.372699 |
| Emsisoft | Gen:Variant.Adware.Ursu.372699 (B) |
| Comodo | ApplicUnwnt@#1zkwazubp75r5 |
| F-Secure | Adware.ADWARE/Wews87.cciac |
| DrWeb | Program.Unwanted.3980 |
| Zillya | Adware.Generic.Win32.113323 |
| Invincea | Generic PUA ND (PUA) |
| McAfee-GW-Edition | Artemis!PUP |
| Sophos | Generic PUA HK (PUA) |
| Ikarus | AdWare.Wews87 |
| Avira | ADWARE/Wews87.mlhsq |
| Microsoft | PUA:Win32/GameBox |
| ZoneAlarm | not-a-virus:HEUR:AdWare.Win32.Generic |
| GData | Gen:Variant.Adware.Ursu.372699 |
| ALYac | Gen:Variant.Adware.Ursu.372699 |
| MAX | malware (ai score=99) |
| VBA32 | BScope.Adware.Wews |
| Malwarebytes | PUP.Optional.Chickil |
| ESET-NOD32 | a variant of Win32/Wews87.B potentially unwanted |
| Rising | Trojan.Generic@ML.92 (RDML:PQJc7VnbqJSPMcTjYojqUw) |
| eGambit | Unsafe.AI_Score_91% |
| Fortinet | Riskware/Wews87 |
| AVG | Win32:AdwareSig [Adw] |
| Panda | Trj/CI.A |
| Qihoo-360 | Win32/Trojan.Adware.37e |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49222 | 113.108.239.194 r1---sn-j5o7dn7e.gvt1.com | 80 |
| 192.168.56.101 | 49223 | 113.108.239.196 r3---sn-j5o7dn7e.gvt1.com | 80 |
| 192.168.56.101 | 49213 | 115.231.95.105 cm.he2d.com | 80 |
| 192.168.56.101 | 49214 | 115.231.95.105 cm.he2d.com | 80 |
| 192.168.56.101 | 49215 | 117.18.237.29 ocsp.digicert.com | 80 |
| 192.168.56.101 | 49194 | 117.27.241.66 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49195 | 117.27.241.66 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49196 | 117.27.241.66 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49207 | 117.27.241.66 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49208 | 117.27.241.66 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49192 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49193 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49197 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49201 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49202 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49203 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49204 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49206 | 120.39.212.70 img1.37wanimg.com | 80 |
| 192.168.56.101 | 49181 | 121.201.30.167 a.clickdata.37wan.com | 80 |
| 192.168.56.101 | 49191 | 14.18.237.128 gameapp.37.com | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 50002 | 114.114.114.114 | 53 |
| 192.168.56.101 | 50433 | 114.114.114.114 | 53 |
| 192.168.56.101 | 50568 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53210 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53237 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53380 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53500 | 114.114.114.114 | 53 |
| 192.168.56.101 | 54178 | 114.114.114.114 | 53 |
| 192.168.56.101 | 54260 | 114.114.114.114 | 53 |
| 192.168.56.101 | 54991 | 114.114.114.114 | 53 |
| 192.168.56.101 | 57236 | 114.114.114.114 | 53 |
| 192.168.56.101 | 57367 | 114.114.114.114 | 53 |
| 192.168.56.101 | 57756 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58367 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58970 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60088 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60221 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60966 | 114.114.114.114 | 53 |
| 192.168.56.101 | 61680 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62318 | 114.114.114.114 | 53 |
| URI | Data |
|---|---|
| http://ptres.37.com/js/sq/widget/sq.statis.js | GET /js/sq/widget/sq.statis.js HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: ptres.37.com Connection: Keep-Alive Cookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522537%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522922608%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A4%253A%2522game%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220210513%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
| http://img1.37wanimg.com/syol/css/client/game.css?t=1620889632 | GET /syol/css/client/game.css?t=1620889632 HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?game_id=537&tpl_type=game&refer=wd_37cs&uid=922608&version=3000&installtime=20210513&runcount=1&curtime=20210513200514&showlogintype=3®times=1&pagetype=1&thirdlogin=1 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img1.37wanimg.com Connection: Keep-Alive |
| http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=cc12ca6065264b10&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620889458&mv=m&mvi=3 | HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=cc12ca6065264b10&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620889458&mv=m&mvi=3 HTTP/1.1 Connection: Keep-Alive Accept: */* Accept-Encoding: identity User-Agent: Microsoft BITS/7.5 X-Old-UID: cnt=0 X-Last-HR: 0x0 X-Last-HTTP-Status-Code: 0 X-Retry-Count: 0 X-HTTP-Attempts: 1 Host: r3---sn-j5o7dn7e.gvt1.com |
| http://img1.37wanimg.com/www/css/images/common/dialog2/bg-dialog-avatar.png?v=1 | GET /www/css/images/common/dialog2/bg-dialog-avatar.png?v=1 HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img1.37wanimg.com Connection: Keep-Alive |
| http://img1.37wanimg.com/syol/css/client/game/kv-a-on.png | GET /syol/css/client/game/kv-a-on.png HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img1.37wanimg.com Connection: Keep-Alive |
| http://cm.he2d.com/1/ | GET /1/ HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: cm.he2d.com Connection: Keep-Alive |
| http://img1.37wanimg.com/syol/css/client/game/btn-to-reg.png | GET /syol/css/client/game/btn-to-reg.png HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?game_id=537&tpl_type=game&refer=wd_37cs&uid=922608&version=3000&installtime=20210513&runcount=1&curtime=20210513200514&showlogintype=3®times=1&pagetype=1&thirdlogin=1 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img1.37wanimg.com Connection: Keep-Alive |
| http://cookiem.37.com/sys/?u=LtCcYDsmZnYBAAAAWFhU&fdata= | GET /sys/?u=LtCcYDsmZnYBAAAAWFhU&fdata= HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Cookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522537%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522922608%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A4%253A%2522game%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220210513%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3; 37wanrefer=gameapp.37.com Connection: Keep-Alive Host: cookiem.37.com |
| http://ptres.37.com/js/sq/widget/sq.clientclass2.js?t=1620889636 | GET /js/sq/widget/sq.clientclass2.js?t=1620889636 HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?action=register&game_id=537&tpl_type=game Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: ptres.37.com Connection: Keep-Alive Cookie: sq_client_data=a%253A8%253A%257Bs%253A7%253A%2522game_id%2522%253Bs%253A3%253A%2522537%2522%253Bs%253A7%253A%2522version%2522%253Bs%253A4%253A%25223000%2522%253Bs%253A5%253A%2522refer%2522%253Bs%253A7%253A%2522wd_37cs%2522%253Bs%253A3%253A%2522uid%2522%253Bs%253A6%253A%2522922608%2522%253Bs%253A13%253A%2522showlogintype%2522%253Bs%253A1%253A%25223%2522%253Bs%253A8%253A%2522tpl_type%2522%253Bs%253A4%253A%2522game%2522%253Bs%253A11%253A%2522installtime%2522%253Bs%253A8%253A%252220210513%2522%253Bs%253A10%253A%2522thirdlogin%2522%253Bs%253A1%253A%25221%2522%253B%257D; client_type=3 |
| http://img1.37wanimg.com/syol/css/client/game/log-bg.jpg | GET /syol/css/client/game/log-bg.jpg HTTP/1.1 Accept: */* Referer: http://gameapp.37.com/controller/client.php?game_id=537&tpl_type=game&refer=wd_37cs&uid=922608&version=3000&installtime=20210513&runcount=1&curtime=20210513200514&showlogintype=3®times=1&pagetype=1&thirdlogin=1 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img1.37wanimg.com Connection: Keep-Alive |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts