HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Win32.IEDummy.FD (Lavasoft MAS)Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 20e36ad04ff6515d68b61362b2a06512
SHA1: 4f0152fe37f0d5dffa275d3d786b90c9582ac834
SHA256: 1c4994fb9ea24c0037e8d905211e66ab0a005631c39ff05cc43127c8c7f92886
SSDeep: 98304:BmRAsB9AM0rOOXF7rW12QyUf9axezFFoE1PK7BdUCAqNpDg8zA:Bm7B9AM0jXQmUfIezFfY/Ju8E
Size: 4868347 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2007-09-20 15:34:46
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
msisetup.exe:592
msisetup.exe:1564
%original file name%.exe:348
The Trojan injects its code into the following process(es):No processes have been created.
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process msisetup.exe:1564 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\BYBRWJVG\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3I2TUWDI\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TFZ1DZO2\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B55C40TD\desktop.ini (67 bytes)
The process %original file name%.exe:348 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (169540 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\__tmp_rar_sfx_access_check_276359 (0 bytes)
Registry activity
The process msisetup.exe:592 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 C2 E6 CE AF AC 73 5A 48 55 74 E7 61 0A DD 3F"
The process msisetup.exe:1564 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"
[HKLM\SOFTWARE\Microsoft\ESENT\Process\msisetup\DEBUG]
"Trace Level" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CB CA 54 A3 1E 27 84 CB 97 9B 4D AF 74 DA 5D 15"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Internet Explorer]
"iexplore.exe" = "Internet Explorer"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\ESENT\Process\msisetup\DEBUG]
"Trace Level"
The process %original file name%.exe:348 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A7 7E D6 77 38 55 F4 D6 3C 61 DA E3 FF 1D F3 C3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\RarSFX0]
"msisetup.exe" = "msisetup"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Dropped PE files
MD5 | File path |
---|---|
52801f1610d2b3121b1a374b49b68eb8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\RarSFX0\msisetup.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
msisetup.exe:592
msisetup.exe:1564
%original file name%.exe:348 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\BYBRWJVG\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3I2TUWDI\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\TFZ1DZO2\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\B55C40TD\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\RarSFX0\msisetup.exe (169540 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 81920 | 79872 | 4.48153 | 8c499086717691066d921075ed5bdb09 |
.data | 86016 | 28672 | 2560 | 3.40313 | 0cb811e47f78b5404a658fb36b591857 |
.idata | 114688 | 4096 | 4096 | 3.55201 | 8bf175092a70a21f11fd06cc4087c7d0 |
.rsrc | 118784 | 16822 | 16896 | 2.98979 | e56287babd73f9c7a9cd2d4d38334457 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://presentaci.ru/downloads/752_55394.ppt | 5.187.5.232 |
hxxp://presentaci.ru/style.css | 5.187.5.232 |
hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/font-awesome/4.1.0/css/font-awesome.min.css | |
hxxp://vk.com/js/api/openapi.js?115 | 87.240.131.120 |
hxxp://presentaci.ru/fonts/glyphicons-halflings-regular.eot? | 5.187.5.232 |
hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/font-awesome/4.1.0/fonts/fontawesome-webfont.eot? | |
hxxp://presentaci.ru/images/logo.png | 5.187.5.232 |
hxxp://counter.yadro.ru/hit?t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 | 88.212.196.101 |
hxxp://counter.yadro.ru/hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 | 88.212.196.101 |
hxxp://counter.rambler.ru/top100.jcn?2768890 | 81.19.88.80 |
hxxp://counter.rambler.ru/top100.scn?2768890&rn=139404967&v=0.3i&bs=1256x677&ce=1&rf&en=utf-8&pt=404 ÑÂтрðýøцð ýõ ýðùôõýð&cd=32-bit&sr=1276x846&la=en-us&ja=1&acn=Mozilla&an=Microsoft Internet Explorer&pl=Win32&tz=-120&fv=11.6 r602&sv&le=0 | 81.19.88.80 |
hxxp://vk.com/js/api/xdmHelper.js | 87.240.131.120 |
hxxp://googleapis.l.google.com/ajax/libs/jquery/2.1.1/jquery.min.js | |
hxxp://cdnjs.cloudflare.com/ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js | 198.41.215.66 |
hxxp://yandex.st/share/share.js | 178.154.131.217 |
hxxp://bootstrapcdn.jdorfman.netdna-cdn.com/bootstrap/3.1.1/js/bootstrap.min.js | |
hxxp://plus.l.google.com/analytics.js | |
hxxp://mc.yandex.ru/metrika/watch.js | 87.250.250.119 |
hxxp://plus.l.google.com/r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 ÑÂтрðýøцð ýõ ýðùôõýð&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 | |
hxxp://a767.dspw65.akamai.net/msdownload/update/v3/static/trustedr/en/authrootseq.txt | |
hxxp://a767.dspw65.akamai.net/msdownload/update/v3/static/trustedr/en/authrootstl.cab | |
hxxp://netdna.bootstrapcdn.com/bootstrap/3.1.1/js/bootstrap.min.js | 108.161.188.218 |
hxxp://www.google-analytics.com/r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 ÑÂтрðýøцð ýõ ýðùôõýð&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 | 216.58.214.238 |
hxxp://ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js | 216.58.209.202 |
hxxp://maxcdn.bootstrapcdn.com/font-awesome/4.1.0/css/font-awesome.min.css | 108.161.188.218 |
hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt | 77.222.148.97 |
hxxp://maxcdn.bootstrapcdn.com/font-awesome/4.1.0/fonts/fontawesome-webfont.eot? | 108.161.188.218 |
hxxp://www.google-analytics.com/analytics.js | 216.58.214.238 |
hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | 77.222.148.97 |
apis.google.com | 216.58.214.238 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /ajax/libs/jquery-cookie/1.4.1/jquery.cookie.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdnjs.cloudflare.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/javascript; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Mon, 28 Apr 2014 23:00:06 GMT
Expires: Sat, 25 Feb 2017 11:15:51 GMT
Cache-Control: public, max-age=30672000
Access-Control-Allow-Origin: *
Content-Encoding: gzip
CF-Cache-Status: HIT
Server: cloudflare-nginx
CF-RAY: 27fda1c8f33302db-AMS
22f............}TMo.@...W.=...1AJ.....T.Z...$'.....`...B....c..FQO..7.f......X..n.....o3......~~.....z.Z'N.M%...!B.m.&.R...~....H...c.v&S.Y@L......Z...HR....@.z..I...............V{s...H..........(.....>A.w )...^@b:........_~...3.m."x<8h]@....!..t....."W....CU...#~3b..2...'.2....26.`.`....mGG........./9..V..@..t...lW..g4...m..R..(.....I_U..c$,Jh...n.31.....gku$Ng.>...TF7F..mO.Y.............N..F.($..].xN.........D.T-..8...l../.W. \...'U..,..?.........&Y.....8..o..S$.O.".z]g28.}g....:@..D......{.m.6..B*.$[..n....dm.)h-....0JSBPe..f.\@..5.}.........\9.]...S..-7...8a...s.37.......]g)...v.A._...~5W..., .#!L.x<....}.v....3........%.Yj..c.=........ux>..q.1.f..o.tP..t.......F.=...z.....G.nF5......f._..>.......0..HTTP/1.1 200 OK..Date: Mon, 07 Mar 2016 11:15:51 GMT..Content-Type: application/javascript; charset=utf-8..Transfer-Encoding: chunked..Connection: keep-alive..Last-Modified: Mon, 28 Apr 2014 23:00:06 GMT..Expires: Sat, 25 Feb 2017 11:15:51 GMT..Cache-Control: public, max-age=30672000..Access-Control-Allow-Origin: *..Content-Encoding: gzip..CF-Cache-Status: HIT..Server: cloudflare-nginx..CF-RAY: 27fda1c8f33302db-AMS..22f............}TMo.@...W.=...1AJ.....T.Z...$'.....`...B....c..FQO..7.f......X..n.....o3......~~.....z.Z'N.M%...!B.m.&.R...~....H...c.v&S.Y@L......Z...HR....@.z..I...............V{s...H..........(.....>A.w )...^@b:........_~...3.m."x<8h]@....!..t....."W....CU...#~3b..2...'.2....26.`.`....mGG........./9..V..@..t...lW..g4...m..R..(.....I_U..c$,Jh...n.31.....gku$Ng.>...TF7F..m
<<< skipped >>>
GET /analytics.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 09:40:24 GMT
Expires: Mon, 07 Mar 2016 11:40:24 GMT
Last-Modified: Thu, 04 Feb 2016 00:31:28 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 10938
Age: 5728
Cache-Control: public, max-age=7200
...........}.s...... .\.j&....r.s(gw.-^...Ii$.&.@f./1|...nI......U.Su...K....W..H.....oy.dU...{.i?J...O...Y{U..x.........)...A.1WT..H.....(v.;.t/Y.4...........a......j...=......j.............kcc..^...f.l.z......v>~...?8.|t|r.....s....z.....f8....tr{w....\..|......~8...x;u......c.N......EC.q...?.......P.."..\.|.....\..a.}YX8.......FB9.-.F..9%.K&.;o.Ndi.y@...V.z=..0.~..d...zL...X.l..,R......N!.~..\.\.yf.\...|.......5..t....k..E.R5..X....%. (........J.O...?\B.....X::N.h.....\...8c.....v..'.J.......}1.&i<..(.....P... ...:8..m3M5.X.[<.r...y.....8lF.{."......4K..{.zn9....&.n.."V<Uo..F.S..n`\....d........O)..".v#........O... Wo.......x4...D.&|(po....iq.4..Gw.ea...ni..`.(E...}...[...%......r.B."....).}..VK...8T...L.T.].=.8^x....s{.....-.g".h.:x....'U.i.'..&.2x.0.@......@......*. .]8............7.m\..?.1..."..$*N_)8...%.....v.s.O.q......#.,d.3 F.../..&..S ....t.ci/C]....w<..d.&...&,..=,..X].8Vq.......i]./...OU...,.......^_>&.)a6.@'..,..t...z....z,j..{......r:....R....0c...E3..u...p2.T..6..8..@S.N!<......"...........a...l......m....]....Yd.N..........a<...<.=....C"...... ..L...De..Jq(..fgT..]...x..C...M..|0Q..N..@j.V......B;.x..qCEG.....@T.[..3.\..9I..].4. ..W.fI's]..q....f.... ^."...x.[O......@..q.E>....Gwl/.#1A.@..e.......@....%x.............W..pp.uz|MF...j..g....R[=.......|...jU..@L.....YC......PSO.....XG.v4...9....k...............).....r......N..H...%..K..*.]y.[....R.0.h....f9..-...S..=.`....T.-.j...2.B.........:.....e.......hl...$..@P...=..j.............l@Z`.i.....G......S#...0,7Ky.k'.p
<<< skipped >>>
GET /r/collect?v=1&_v=j41&a=496878869&t=pageview&_s=1&dl=http://presentaci.ru/downloads/752_55394.ppt&ul=en-us&de=utf-8&dt=404 ÑÂтрðýøцð ýõ ýðùôõýð&sd=32-bit&sr=1276x846&vp=1256x677&je=0&fl=11.6 r602&_u=AEAAAAAAI~&jid=824860184&cid=1816077546.1457349193&tid=UA-39033830-1&_r=1&z=918192947 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.google-analytics.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Date: Mon, 07 Mar 2016 11:15:52 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Server: Golfe2
Content-Length: 35
GIF89a.............,...........D..;HTTP/1.1 200 OK..Access-Control-Allow-Origin: *..Date: Mon, 07 Mar 2016 11:15:52 GMT..Pragma: no-cache..Expires: Fri, 01 Jan 1990 00:00:00 GMT..Cache-Control: no-cache, no-store, must-revalidate..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-Content-Type-Options: nosniff..Content-Type: image/gif..Server: Golfe2..Content-Length: 35..GIF89a.............,...........D..;..
GET /top100.jcn?2768890 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.rambler.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.4.7
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV INT"
Set-Cookie: ruid= iAgBudi3VYzBQAAAbjm3g==; path=/; domain=.rambler.ru; expires=Thu, 05-Mar-26 11:15:51 GMT
Set-Cookie: top100rb=NDQ4KzQ4OSs0OTE=; path=/; domain=.rambler.ru; expires=Mon, 14 Mar 2016 11:15:51 GMT
e1e..(function(window){var f=!0,i=!1,j,k=this;Math.floor(2147483648*Math.random()).toString(36);function l(a,b){this.width=a;this.height=b}l.prototype.toString=function(){return this.width "x" this.height};var aa=/^[a-zA-Z0-9\-_.!~*'()]*$/;function m(a){a="" a;return!aa.test(a)?encodeURIComponent(a):a};function o(){this.e={};this.i=[]}j=o.prototype;j.a=0;j.j=function(){return this.a};j.c=function(a){return Object.prototype.hasOwnProperty.call(this.e,a)};j.set=function(a,b){Object.prototype.hasOwnProperty.call(this.e,a)||(this.a ,this.i.push(a));this.e[a]=b};j.get=function(a,b){return Object.prototype.hasOwnProperty.call(this.e,a)?this.e[a]:b};j.h=function(){return this.i.concat()};j.d=function(){for(var a=[],b=0;b<this.i.length;b )a.push(this.e[this.i[b]]);return a};var p=Array.prototype;function q(a){return p.concat.apply(p,arguments)};function r(a){this.b=new o;this.q=!!a}j=r.prototype;j.a=0;j.j=function(){return this.a};j.c=function(a){a=s(this,a);return this.b.c(a)};j.h=function(){for(var a=this.b.d(),b=this.b.h(),c=[],e=0;e<b.length;e )for(var g=a[e],d=0;d<g.length;d )c.push(b[e]);return c};j.d=function(a){var b=[];if(a)this.c(a)&&(b=q(b,this.b.get(s(this,a))));else for(var a=this.b.d(),c=0;c<a.length;c )b=q(b,a[c]);return b};.j.set=function(a,b){a=s(this,a);this.c(a)&&(this.a-=this.b.get(a).length);this.b.set(a,[b]);this.a ;return this};j.get=function(a,b){var c=a?this.d(a):[];return 0<c.length?c[0]:b};function s(a,b){var c="" b;a.q&&(c=c.toLowerCase());return c}j.toString=function(){
<<< skipped >>>
GET /top100.scn?2768890&rn=139404967&v=0.3i&bs=1256x677&ce=1&rf&en=utf-8&pt=404 ÑÂтрðýøцð ýõ ýðùôõýð&cd=32-bit&sr=1276x846&la=en-us&ja=1&acn=Mozilla&an=Microsoft Internet Explorer&pl=Win32&tz=-120&fv=11.6 r602&sv&le=0 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.rambler.ru
Connection: Keep-Alive
Cookie: ruid= iAgBudi3VYzBQAAAbjm3g==; top100rb=NDQ4KzQ4OSs0OTE=
HTTP/1.1 200 OK
Server: nginx/1.4.7
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: image/gif
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Pragma: no-cache
Cache-Control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NON ADM DEV TAI PSA PSD IVA OUR IND UNI COM NAV INT"
Set-Cookie: top100rb=NDQ4KzQ4OSs0OTE=; path=/; domain=.rambler.ru; expires=Mon, 14 Mar 2016 11:15:51 GMT
890..GIF87aX......4j..r...\.............f....\.$......\....4............$.d...........ld..,.l...$~d$zlt.<......<v..r......l..|$.....,........D........t..<...........|.T.........<r...l..L.......n.l.<D..$..D..........\4.|D~..z....<..l.....<n..z...l....j.\.$........L...........l......4..t.<...Dz..v.......4.................L..T.$..l...|..4n..v...d..,.................,..................|..4.|...t.L...<z.......\........d.....L.$.........,.....D..|.d..TL............................d....j.\.,.v.......................................................................................................................................................................................................................................................................................................,....X.......'..H.`. ......!C8..X.8Q"...3V..................L.H..-.a..Is.M.8k....&..@."I..B...`.y.TK..L.:..u...X]X..U .I'......S.~..=.6m..n.....J..x..p../..~....x.....n....Q1y.....C..~,g...3...Cw^.8(....T.@cR.I.:t.#[6...o..4..n..c..=.......zc.P..4(H.!fL.<~h........;..........w...x..6..`$_..A.O'J$..$...r.$2..A..!..m......M.By..f.....@.Y..D.f...%.]..~..W`.2L2F.Z ......A.~le...L...........^..X...7..c.7bH...l...>d..........x.O....Ay...A....\..!.K.ev.$P^.a.Vf...$.$.~....$..."....Z%r...@2P..O2.......a.(.TI"..qc......Vb.%..\....).(...X'..-...@......m....^...=.q#... ...2...;l...j...k......Q...>".c..J..$. Z...uj....r...P..AO......r..|^.'.`xE..Z zI...&......... P..M....g0...M{.....D...,. e......J...Gh.b.`....i.n...
<<< skipped >>>
GET /ajax/libs/jquery/2.1.1/jquery.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ajax.googleapis.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/javascript; charset=UTF-8
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Date: Tue, 01 Mar 2016 13:51:38 GMT
Expires: Wed, 01 Mar 2017 13:51:38 GMT
Last-Modified: Fri, 16 Oct 2015 18:27:31 GMT
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 29497
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000, stale-while-revalidate=2592000
Age: 509053
............{..../....CD.....);.;.1..d.N$.........$f.....y.|.[...F..%..{.:q4......z............w...n.l......^.....?3._...Y. VKu..2.R..[...6..y...m~....Z..e.r~....[%.y...h.~..&g.Uv7..../...z..m...(.f..n./w..jn...l(x,&~.,..f....2.?.j.Ym|O.b.....|{............./.`..ww......B..{4.|R,..k....C..w.b..#..o..h4VY.v..!..U.Z..NM.r}...)]P...w.5.....f....nS,...nf........:.......;........eT....&b..,..b.o.j.].2..^......../z...v..b..T.|.=.P....?.........P.......k...x...a...ew.Y.V...Q '\(...ns..V.p...<.K.S.|9........l...j...n...>...3.w..0C...[Q<.].C.....t..q(..a.2...]..T...&4.E...\.....T\B..7....x........[s.....t.6.[...%%....M..*m.}.b...0.....e.....T/.g...*...z=..{..2.mQ...lw.*.o......,r..2.m..; ....w|,g...|...^F.v;.L.#^.t<.GcT..N....~....#...Dm.%....Gm.<ut...E....v".q..i.C.....T.&...D.z...v.,.........V.0.:KV.y./K.9m...hZ.l. .t.u.m..=...K..i...SB-...E..7........r6@E.geG.q.. @..... H..(....3mEQ.....A....b)s.gh8...7:=......i....v.2..)V2.....-...Gf..k.d.4|.*...............t....C}lx...y..f.../. .n..<Ns....aI..T..!...a..r.:.8..Ht...j.v..P.]..M..G..48.#W..&..f...Or2....vL5.]9.P....."m..U.A.....x.._.W1.'..6|.,ES.5......qw....t .)..W.V?..=.n...oU............U..g_-....=c.2p@W....._..S.H.7.;.....x.w..<..F..D@..|......U...z...{J./....3.)..B.2.}^GME..B..MOA..NJ.y7.....j.c...6..kzI...H..wg.........y.'A.....K.D..X.... L.m..4^.s..M3..].V...^.mn..w@..K54.~..xO.g...x..7...<.>i8Oq.a...F=.(.A..hK...RK.........2....2._..x...&Bk.!. .).9.s.k|...../N.%...s.......28...P.!`&P....J...@x..5B..r..~4......5b&X...)U...[w[......HR.
<<< skipped >>>
GET /hit?t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.yadro.ru
Connection: Keep-Alive
HTTP/1.1 302 Moved Temporarily
Date: Mon, 07 Mar 2016 11:15:51 GMT
Server: 0W/0.8c
Content-Type: text/html
Location: hXXp://counter.yadro.ru/hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165
Content-Length: 32
Expires: Sat, 07 Mar 2015 21:00:00 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="UNI"
Set-Cookie: FTID=1MtMBd3GLR5R1MtMBd; path=/; expires=Mon, 06 Mar 2017 21:00:00 GMT; domain=.yadro.ru
<html><body>Moved</body></html>.....
GET /hit?q;t44.11;r;s1276*846*32;uhttp://presentaci.ru/downloads/752_55394.ppt;0.1750978391247165 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: counter.yadro.ru
Connection: Keep-Alive
Cookie: FTID=1MtMBd3GLR5R1MtMBd
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Server: 0W/0.8c
Connection: Close
Content-Type: image/gif
Content-Length: 132
Expires: Sat, 07 Mar 2015 21:00:00 GMT
Pragma: no-cache
Cache-control: no-cache
P3P: policyref="/w3c/p3p.xml", CP="UNI"
Set-Cookie: VID=1sHqLj37UGbR1MtMBd; path=/; expires=Mon, 06 Mar 2017 21:00:00 GMT; domain=.yadro.ru
GIF87a.......k.....,..........c......c...........(..'..4.......h...B.;.;...`..*RN.....=...t.t.......2.0(.#&..f.........io.......P..;..
GET /js/api/openapi.js?115 HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vk.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: application/x-javascript
Last-Modified: Fri, 13 Nov 2015 15:33:32 GMT
Transfer-Encoding: chunked
Connection: keep-alive
ETag: W/"564602cc-112d3"
Expires: Fri, 11 Mar 2016 11:15:50 GMT
Cache-Control: max-age=345600
Content-Encoding: gzip
52ce.............}k{.G...........H..Y..[...c....Q.z(.e..H..,;...~..(...)...........B.P(..BU....'..hX.jd.....YV.j......=kd.|v9..~./.z...7<...i..}...^.......z.x{pho.......J...S.&.... CA..o....k-.....jD...$............F..K{.....u...u.5.m..z...z.5...M..7..FC.hKX.._."O.U.?.q4....6..d4n..f6..g.,;.].gF!9......KE.....Ou.r.~...4...-..m....{.V.....n.i....={...G......D\7.....NC..&7..QU.@o6....:......d`......0..bh....."..Z'..7...r>.kS.[s.g.Lk.i...g.........5.x...... -........8..<.X.c....j...O5.R.uk..h`.7...;}..u..O...^{....Z..}................q..\...._z.....2of'..74*.W...yV' Fg.f..o.....6.a....t..ca[27\.Gk...........\X.].wk.................}.9J.......m`.>..R...$%......E.B>,$.A.........n..-...........Of.N>..-...........O.. ...!.?..>..BO...._...T....Qb..}|j...].K.|.fv.7.l.=.bl..C...E2.W&F..1.....<.....(gJhD..w}..R.9>....../.....S..7..d.k....r....w......6.:..z..Y.....W....^......F.f...)....M..[..;...S;`.##`.Z.X....r.*td.... .M7.......rz^?P[cX|!.6"..il.So..5....2..........]A..0........u....s..m...F.....,...N..[.z.^.@.].6..H ..(...Yo..ak..Ls.......P......y..{.....h.q_[1_(.U..1...C.#6!..0...?]^.."t<Xa|H~.P...G....M......i.........X..g...?.m]....3Xc!....,.S....a".DT(`c..8....,.1...5..E&.....n..i. 'u........Cb..5.".....}.H.!g...U.x2.'Xs..N.\.j..vW...jY..]......46|.....l..M8.Z.54....z.....gj.0......,...........F;Y.>......s2.db..g..t.f....~g;..o......Z'..............8]....Z.W..C>.........?...f.D!....?5..zW..].<.....7....-.0....P...D....H..t..!.'...w.a..]..,&.utt.~...W..@..rXw..:... ...QS#.E_.}9
<<< skipped >>>
GET /js/api/xdmHelper.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vk.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Last-Modified: Mon, 20 Jul 2015 23:21:19 GMT
Transfer-Encoding: chunked
Connection: keep-alive
ETag: W/"55ad826f-2c65"
Expires: Fri, 11 Mar 2016 11:15:51 GMT
Cache-Control: max-age=345600
Content-Encoding: gzip
e96.............Zkw....._.a..4I.r..e .cK......$-....B...,.$u$....'....4........;..]`8dGoOX..<-8.....YY.....,.g.....p..q.U.9..._...9.N.l:...m.8x......7......]u.....3;......se3cK?g.....xR....~..OG...<..g.hR.<.....L.G.Q.n\..h..[..H<<%.G..x.xD....p.N.g}.#.....?M...2.L.4.z'...E.y....>g..*..!OK.<...=/I....B.,b..........e\V.|a&I..d...?.V..(eG.....t.#...FG.;.vG.ab.N.c2....u...9_.x :..Dn.=G.p..s.dqZ.3......_r....'Y..X....O.....S...lg...3rX...,}!H.[c...J..e..gvp.;^.q..X..#).15..*yQ.!.f.....1)....?......q};:..~"|0.9..?...N.Ey...)loo.9r(.S..nM...7.H%..x.;.#'{...U...^...4.....WP.p...........G.OUv7.....[.Y.....h..O2J...q..._X ..qq..1.T...[.I..Gn...Hc...9..'...$...s."F..0.:...%........v..n%.y.....'.I.1..BS.x.6..8..H....c.dih..Ma.b..t.[...p.....S..J.}.!..m4..g].a......\.~...$......./.....'3..,[. ...r...}.I:.4E..u..VB.bu...g..&/....p.FRgl..e.'uB!..rVc..@V..G..._..T. z..l.....Z...!B..cA...8...Z..1&........J..).Ln..*/....3...}9.I.Fz...`fF.:Ye..u.N]6....)Z...$K*|..`1.C...TNS.X.(V.....s#O....!..[r..,...Ek...j.Z.j..........@........c.N......bU't._,...p]i......s....>..t{.C..*A$Q.37.......*..Ck...z.....q|...yD.....X.$._..jZ.O...~.....O.K..........;.gK%.....).S.....&..-..,......P7*.1.......&..$V}.....ei[k...Q..da.X.c...=x.BAi%...k.sh.Y.mSN#...V..u.a..b1....&.-o..V\T......Pv.# ..`.../M......e...}.f<A...................U.!..<//d..a.4....w.H.J.......%p.O..........T..4a.........G..s.5......E.hGX;...T..Nm..'..qt.[.}....T..}V,p..ET2m-..^2.....h[[..H.Aj.....YAO...l.FC..jJ4....7. ah-.f.rl3.Z....R.....r.hm&2..E....
<<< skipped >>>
GET /downloads/752_55394.ppt HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Server: nginx
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.28
Set-Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04; expires=Wed, 07-Mar-2018 11:15:50 GMT; path=/
Content-Encoding: gzip
e55..............mo...{~.. &..I.vj....M1.H..h?..a...x6.cxG.r..M.bC.vm..........4^..M.....<G..5r..HD.......K..z....}.5.....P...iX .qb`..........(q<.K..F..............i....~.u......Q.........k=l..].N....i..F..F$be.G......]..]V..3.C... N}S:.g....O.......Z6<.".i...H.&D.g.#..X..~qu.~.^Z[........Ab...(..\z,6.=.U.....$.p.. ....<.5f..i[.;"...N...8....c,.A..L$|.U..H......(ej.....C.....J..F.....tM.`R..^.@.6..h....D&..G*..b....u...D...Q?.8..M#n...p...eP..]...`vvjw..p.....:q|*e....s.3...!....p. ..#........ ...?d....1..zG..f....od`...Ci..yQ.L......EM..xPK.;v.6Fi.X .k..>8R......p.'...oI.'....#.Jl..}.........}.......Z:FJ6.i...u..J<..,..M.^......&...8 .q<..R.k&.Q\..|n..a....."...._.a.t.&C...n....L.i.h...I..A..O..A".:..>.6h. .....c5....,#..7.....p.%5.J%Q..^F.1 .M..x..].....V3.1].....'n..|.`.w.%..G...D...1.yj.}.|{.o...18.....o@U....T...)zR..P.......c...9.<v.<..O....P..??`.....%3.Bq...3.....]$|h...a.,..*......K.[Xb.s.......tvJv....1.O...j......LH.`..... ..T..BZ._....}I.....o..u.vc........REM%j5.....h~...........0......dv.i...A ..~.e"..3...qB....<.A_~.(...=.Z..c.g&.A-..-.|......... y..o}..X........g.........8_..,B<.........!...........4- .......V.......T.....^.b.KC.........S...].=..>>c.....2..MXS|...!=A.M....7 ...E4.;.....$gx...3....K..2.wm.'.g.....d....T.XO.~<kbE..[...!..............|....u.~..`..y. .=..3?..O....89.h3AF...x|.&.o....._0.O....:..w.<D..5...;.=m....u.<c'.................F.H].....y..U|.Q..s......../...y.b....(.......d............g..~?..#7 ....."..:E..V.....*.........~.
<<< skipped >>>
GET /style.css HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/css
Last-Modified: Wed, 25 Nov 2015 11:42:28 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Tue, 07 Mar 2017 11:15:50 GMT
Cache-Control: max-age=31536000
Content-Encoding: gzip
5858..............m....0.....`...3>...w.*...s_Rus.l><...E...1%*"u^..._...h.....n..$...h4..t..h...w.|....KU5usNO...(.%..}...........m.....Su.|...M4..d..5....h..<..|........X.Yt9f.9....*...o../...}.qS.7.......!.......?......*.}....|....E..|H....h[...x.G..@.Zd.1...zo`Y.}s(.....w..(??...........z....a.`.i..K.<&q..z.1..R4t.mSe.....\...[zn.m......A.7iQ..]..MOMQ....s>...2N..4..y>W.......1.0...../....5 .S.~~d...rK/YQ....CZ.N........k.2...,..PTX..9Ui9d|x>>n.:......j...eL9We...Aq...z..1f..q_dY~.i...V....-.n../....1..#.S.........p...o..h.9...M..t.Tg....j.....>E..5.n......,...$c...lw....s.?......O.G6<....V#2./..#....$....^o..:?~.3.5....X.../....|]..[..j..OU]..z<..)..AfsLMuz..f.....N.Gc..8< n0......<...<\9.we..Q..M......p..>.....P..q....8>?.q.....:......4-....m &..l2&e..N.'g...cU..m>0..-..U.....8(..K3.N..s..&..>..s.^.0..=....`.0.Jb..}(.bS.....*f([B....z)...O.H..c....^~.i.>.i.7..6J.....W..t.S.~.?.....\3.OU..zV....F...~....WU).w..lT..G1v.j{.......Q..n.d}J...g|..W(.r....l....6.n.S...yhd.L.O...q..6..'F... jX.....x......U.,$.2..z.'...yW.e.n.w]...@P`i...[NDIt6T!...9.....!..;L........"...dRo.B4>...M.....c..._G..9?f.....Nr=/......Wh6I..T.....*..^.....j...!..4:..... 'g.O3.0......:7....1..Vk1.O..c....R.n).:|.`.D6k..QX"R...?............7..7Q.4....!z...j. .(V......7.O.......T5....7..7|.......3.|a.v.Z.!}f..../l.qC.1.P........b........5lMaj&T....O..E...u.xz......Z.O{6...5..>._n..`..RH......@<b..&=...HP.1..........h...F[&&.`........iIfJxH..mT...$x...Q.l.h$.%$3}.......dY.
<<< skipped >>>
GET /fonts/glyphicons-halflings-regular.eot? HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/vnd.ms-fontobject
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Mon, 13 Oct 2014 19:07:31 GMT
ETag: "12840296-4f6f-505529c4862c0"
Content-Encoding: gzip
400a.............{UP.@....98...wwwVVV...]........Cp.. .....n.V.}....o....y...qQ...............[...(.?LQ..?.........s........z.U.,@. .P.(.4.......`......6...\t.:.._...j.p......!..F....x ......O....|....[.......X......`......N.<;......?.?.....z\.Ux...,...y..W.......k..?;.....py....L........:...n._|(....Y28.sw....vK..w.S9...R...J..c..g..6 :...........j....L*...._,cm.....rf..HZ.G.!.....=.n=&..`.W*.T|......[...D$...cv.:1u............ ..FJ...{8`.=:. ...Q.(...-......4..}..1C*...p....._..{._..p,<.7.(.d?t.I-....S...bWr..T.....2{..I..~..m.CY...A7y...W.o2..QR..F......:,.)5..T...{.....C&...$...*L....f.....CS0ne..\8..m].A/4z.......".y.-..{d.....Em{-_{.>.b...e.V.'V.c&rw...<..!.9:.......H.....b......^y....^....R}%....g........!..N.....!.].o...\6ci.-...3.<=..>.N..>...cZU...f..z&..XqE..1.z.`....H.s.^W.`......E.TE......yoa..[....~..!....yH.TR......h}s.1{.[.nu& v....z..*)?:.....`n.ciC..;.6T.?....pEI.r.]:.3..^.....,N ........f].i..G..O(.).......-...>.cY...[S..?.o.LI1PG'...L...QL....o.0E......Q.j....=...A.`.y1....V.*.!....x.H...#"_..O$`Q.g...@.G..-}7..G..0.....W....#...|.>K.&.Ky.&....._..~..2.!.GN...........m.Vt.,Y.`B........J..".Y.l..^1....V.....*..0*....P.5."8P?#.........h..O..!............S.O.P66(.j..)..p.QD..%Q3p.p'..~...b...>n...W....(D&....=..C....l!..S......?...H..@.*.v;..%.......v.mP..?......8.m}...c..56S......rA.b.eH......H....]6.....Fw. ....>._...r.Y3...7S.O..<.'...7...l0.R*......W.x%QQ.5HQ......'.p.`*^.kD.......}.E."Q...p...q...m.Fs..?%Y4....v1g.4..d.....Q.....?...3.....5S.E.T. t^.,u8d
<<< skipped >>>
GET /msdownload/update/v3/static/trustedr/en/authrootseq.txt HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: text/plain
Last-Modified: Thu, 28 Jan 2016 17:51:53 GMT
Accept-Ranges: bytes
ETag: "80823092f459d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 18
Date: Mon, 07 Mar 2016 11:15:52 GMT
Connection: keep-alive
X-CCC: UA
X-CID: 2
1401D159F4929680B9....
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Cache-Control: max-age=604800
Content-Type: application/octet-stream
Last-Modified: Thu, 28 Jan 2016 18:43:43 GMT
Accept-Ranges: bytes
ETag: "80d9e4cffb59d11:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 49661
Date: Mon, 07 Mar 2016 11:15:52 GMT
Connection: keep-alive
X-CCC: UA
X-CID: 2
MSCF............,...................I.......d.........<H.T .authroot.stl. ..-.8..CK...<Tk........./.........Z..e..P..D.&.BRTH...E..E.b.["$qS)....-...[..}.o~g...q...Y...n...........aF\!.lI.4..0..ef.W.....C`....Y..F.D5...Y.A....1.|..c.1...Nc.Y..x..D...NP[FX...O.s@.aN.....'.B......."(~3z-.@~..|}(.......g4.p.........h.n.dQz..t.V.......;.....Q...d/../.pJ...6....E...A.@..]..T9..28..,..p...).....P:}.K...]=.7X.f..9..yB.P....uP$$...Q.u..y..".=......7...........#.X..P.8....>U....v.[.$.e...H.@~..........ea`.3...tLX...].-....<.........v.....M../..z6.t^.....p....M...v(CP%F.......!eX..a...-..G.....S%..l.....Y..(.*.-....C.L0...G.....).rm8...(7.T{.Q...."...B`H.....3..9..-..Vv.5Q.e.W.../...RY.v.P. .........l......8'.&z......3.;:...U4.."....yu... .."....d .e/7.;.XD*tn%$.........];..fY.R...7.....o.=xh...]..4...\.:...v....t..9 .nO.i}.T../(uke..p.&.6.E#.=b...@.R.P...*.s....h......(/.s.%.3g...:*X.].7.IE....E,.w.8......v...r4.qOh}~..E.5t...l...(*..2....`..F..".a:.t....9...W.kO?5..=..HhYrI.Sf..[:...3..2..)DB...;......(...B.......U(...._F./#.k@....9c.Y..G'..]...p..;M_o..~.3?.}.1M.5.f5)._......t _.6...l..K....OsY.0......H...^..\$P;U....8..)...1........J...uE..#n.......h.......17.P=,P.....}z.&..../..a.........p@.|KB..o.E..|..o.mr......m=.(v.:.i....@..I..w>4y....P........F...&... ....r$d..{B...)..A.`..x4E'~`V.."..(..(./G...@_Q`.....O...~`..~...x..KN~....Dko/A{..!...W..G,`)...*...#......q`..H.........%m..G....5..4.....?.......F...{.%..2....l.L....."...Y........ ...].\........... D..Y...!1..*.....M?..G..A.|Ex......~...s.!.=..
<<< skipped >>>
GET /font-awesome/4.1.0/css/font-awesome.min.css HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: maxcdn.bootstrapcdn.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:50 GMT
Content-Type: text/css
Content-Length: 20766
Connection: keep-alive
Last-Modified: Wed, 14 May 2014 20:41:32 GMT
ETag: "bbfef9385083d307ad2692c0cf99f611"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:50 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman theheader@maxcdn.com or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes
/*!. * Font Awesome 4.1.0 by @davegandy - hXXp://fontawesome.io - @fontawesome. * License - hXXp://fontawesome.io/license (Font: SIL OFL 1.1, CSS: MIT License). */@font-face{font-family:'FontAwesome';src:url('../fonts/fontawesome-webfont.eot?v=4.1.0');src:url('../fonts/fontawesome-webfont.eot?#iefix&v=4.1.0') format('embedded-opentype'),url('../fonts/fontawesome-webfont.woff?v=4.1.0') format('woff'),url('../fonts/fontawesome-webfont.ttf?v=4.1.0') format('truetype'),url('../fonts/fontawesome-webfont.svg?v=4.1.0#fontawesomeregular') format('svg');font-weight:normal;font-style:normal}.fa{display:inline-block;font-family:FontAwesome;font-style:normal;font-weight:normal;line-height:1;-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale}.fa-lg{font-size:1.33333333em;line-height:.75em;vertical-align:-15%}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-fw{width:1.28571429em;text-align:center}.fa-ul{padding-left:0;margin-left:2.14285714em;list-style-type:none}.fa-ul>li{position:relative}.fa-li{position:absolute;left:-2.14285714em;width:2.14285714em;top:.14285714em;text-align:center}.fa-li.fa-lg{left:-1.85714286em}.fa-border{padding:.2em .25em .15em;border:solid .08em #eee;border-radius:.1em}.pull-right{float:right}.pull-left{float:left}.fa.pull-left{margin-right:.3em}.fa.pull-right{margin-left:.3em}.fa-spin{-webkit-animation:spin 2s infinite linear;-moz-animation:spin 2s infinite linear;-o-animation:spin 2s infinite linear;animation:spin 2s infinite linear}@-m
<<< skipped >>>
GET /font-awesome/4.1.0/fonts/fontawesome-webfont.eot? HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: maxcdn.bootstrapcdn.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/vnd.ms-fontobject
Content-Length: 72449
Connection: keep-alive
Last-Modified: Wed, 14 May 2014 20:41:33 GMT
ETag: "90186830c9c50a0fed932494581761d9"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:51 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman theheader@maxcdn.com or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes
..................................LP........................!H......................F.o.n.t.A.w.e.s.o.m.e.....R.e.g.u.l.a.r...$.V.e.r.s.i.o.n. .4...1...0. .2.0.1.3...&.F.o.n.t.A.w.e.s.o.m.e. .R.e.g.u.l.a.r.....BSGP..................X.........B.....`.g.iSyR..&U:.47.4......mj...1......I.PJQ......X*i.Y.!G.....0.*.-.a.....Xn..$.X...2......RL....RD......p...f..."..p.vU;..k..2.6IQ.}-T.y..I....z....E'....T.....`.D....].Y...G......&.E.7e..%...:Mt~..l......U.@....t.......y.....X.)lI....FW.'&.....X#............J.G.~.........e.0.sZ.. <.. ...p]..e...C.....h.......[.....e}j.I.pr..n..#A".P...'!A..~B........mtv-.,....)2..YQI....o......YA@&&....<c.(?........!....B.\K$.D........Ke.4p. S........>.P..z..T...#............[.h...Q......mi.lJbI.J@.....K.tK..e'.<..OY......pB:..x..p.....)..A.gd.P....t.....6...P..{.b....Z..l......ka.tV..Y.Q2U.,...l.'k.uW...A......}....~.m!.x..=&.%...V#....|;L.......[...".k.eT.B..}....r|...O......}.4...=bC. .L..... .d......O.2E......G....8..%...!.'H6..0..t...rO!Q..y.E..DP!..O....,..4....3...\...S$..............%$...a...........;...df#DwFC..6b.f1...Y.F:CE......../.<.`...v..^...-..>......q$.........&...5s4.0.9...v.....!.WQ.J..n...L..8;q.O....w..m........1>.1..e?...,I.c^e.D.-SP.....5......`."a....U.........a..>..\.....t'..|.3.1HZ1....8..4...1.*..1....!@.2..[]..!9..U`......`.T.?.....X#......W.........vz.uK9.5]"X.u...oR\B.....XX..Q9....lWJ.d..s.@.XY...........x ...... ...n...........:{.M..?..*.=..:.z..x}z..p........._.`S.G..%")v..f....F.Y._.u...*AG...4\.@.t.S.._.5Al.t.o....{L..._!.8.n.
<<< skipped >>>
GET /share/share.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: yandex.st
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.8.1
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: application/x-javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Tue, 26 Jan 2016 15:03:14 GMT
ETag: W/"56a78ab2-d3bd"
Expires: Thu, 10 Mar 2016 11:13:29 GMT
Cache-Control: max-age=259200
Cache-Control: public
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Content-Encoding: gzip
3580.............}k...q.w....<....y.,.....o......;.g...n.4v0..@.c.;..u.rHa.z.%Y2-Q...C$-R........Y...._....Pxv...2.....BUVVfVVVVV...........*..[..M..7..........N..w.].1Oj...[..,._.>~....n.%...o(.*I..b.Y..g.9DW..fh..l6......G.t...../A?P....K5....9.....O.........S..}-nBX.....yS.-..B.J*.D...j...d.X.c.......5k_.e........e....M..M'|...J..v&....R..5....m.?0.^.......s...%].{J.h.*......lh.... .....r...M.7...Ms.......H.&...aOL}.#....A.z.|.3.........M..d0..B[.0.Y.M=.L(.-.......0.SVz.'.[..98.Be.... .<>i...V.<5.Pn:m..g...,m~........s......>-.....M..[\t..e(.>.l......ZTZ...wv9[...{.....tvQ.U..$t1.-.f.c.[@8.oN ...pBQ]}.9h.c.j.s...8....i.rF...i_Y.......<7..v.1.\{....k....v.;.....3.@......x.5.d.j...........N......o......g......Z:mo..8. &.B.......Qq.. ...7.F#...i.:.\?4..,Pc.*..;.R}.`.j.$t.D^a&.6.....V`.,...4.E.-..z.9..1..?.;.9'n....... ....vd.,.f.v.pF5.7.M.<...W..........'.y...jc.gg..........=.. . .....{....$....-Y..bm.H....p...5....0l......R..F......y ...m3'z....#D.dKk..P;0..............,.q.<yB...(c'.:.Q.....G.-.2l50..........Vg=%U...4....(J..C.%...0....i...C.'...:f^\.......'~...s-'4..L....=D.<-V.,Z.z../\.t.Vo......Q..O.w"%....U...|s..41Wf.:..5G0.[..X.^SK.A...RDu..9G..l...=..&.9.....{c..]g..Y.....^.#..r..<......H.1..<....?/...W......c..Y`}ns._.....3.........>WK.;.U..K..... <..\.D.....,P....o0."..kN!@.i.... ."....V..S......D..>....f=5I.d..(.&.......Z...zb.....VL..T`.p.."Y&!.Z.`.|B.E.p .k.....i......c(.2....2O=.N...sT82,'[A.........4.g...0.e...<y,sp.P_.L.|.y....>..{e.......Hk
<<< skipped >>>
GET /images/logo.png HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: presentaci.ru
Connection: Keep-Alive
Cookie: ci_session=a:5:{s:10:"session_id";s:32:"da878a1ea1093fc64e82507fb0d5fbad";s:10:"ip_address";s:14:"194.242.96.218";s:10:"user_agent";s:120:"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; ";s:13:"last_activity";i:1457349350;s:9:"user_data";s:0:"";}55041aa335cdb69d5ff17e6b51652862574edb04
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Mar 2016 11:15:51 GMT
Content-Type: image/png
Content-Length: 1928
Last-Modified: Mon, 13 Oct 2014 18:58:38 GMT
Connection: keep-alive
Expires: Tue, 07 Mar 2017 11:15:51 GMT
Cache-Control: max-age=31536000
Accept-Ranges: bytes
.PNG........IHDR..............qr0...(PLTE.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................feB....tRNS.............................. !"%&'()* ,-./013679;=?@@ACDEFHIKLNPQSWX\]_`abcdeimoppqrswxy{|~.........................................................................................wg....YIDATX......5..3.Z...(j..... ..@9,rU..#.sA..E.`9e)..5.e.*....li.@..{.%3..L......~.~.&3/..&....!.......Q#AP.b...JW.l..KO...-..it....I.g&l6..c.........a......)G..3.a....$.!..5./n.s.....|...r.N..F...tG.......o....w<.h..#O@r........@........w.._7.G0...y@.F....U.c..S..7....Xi..{.Nm..b ..c.1.D.8D.l.....0...2......._.``...;?o.&n.uR9.D|Lk.(z.yZN>e".pD..8Y.?V&.....{:.p`.4.}M.0.2...1...[.....?.4...u4.#...6.$...vrz..i.r........... .a..K.....?Gc..6...B.s"....6..a&.aY.K....b..9ac....p..F...S".S.t.F...b3.....8..wi.eA5.{.....L......0..`.*..8`..6(.wA...r. ..D....sH..]....!`.$Y.c.`.]-H. ....'.....-J. .v'.aT.?7!....^.1......*.`...^...!..6...b...aXiW...w.".c5]..............U.T$x.R6R!$"P<^...x.\T.RjB.`.CW1j{.(.M......v....$\....b8....6.<..c
<<< skipped >>>
GET /bootstrap/3.1.1/js/bootstrap.min.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: netdna.bootstrapcdn.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 07 Mar 2016 11:15:52 GMT
Content-Type: application/javascript
Content-Length: 29110
Connection: keep-alive
Last-Modified: Tue, 01 Dec 2015 17:30:27 GMT
ETag: "ba847811448ef90d98d272aeccef2a95"
Server: NetDNA-cache/2.2
Expires: Thu, 02 Mar 2017 11:15:52 GMT
Cache-Control: max-age=31104000
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
X-Hello-Human: You should work for us! Email: jdorfman theheader@maxcdn.com or @MaxCDNDeveloper on Twitter
X-Cache: HIT
Accept-Ranges: bytes
/*!. * Bootstrap v3.1.1 (hXXp://getbootstrap.com). * Copyright 2011-2014 Twitter, Inc.. * Licensed under MIT (hXXps://github.com/twbs/bootstrap/blob/master/LICENSE). */.if("undefined"==typeof jQuery)throw new Error("Bootstrap's JavaScript requires jQuery"); function(a){"use strict";function b(){var a=document.createElement("bootstrap"),b={WebkitTransition:"webkitTransitionEnd",MozTransition:"transitionend",OTransition:"oTransitionEnd otransitionend",transition:"transitionend"};for(var c in b)if(void 0!==a.style[c])return{end:b[c]};return!1}a.fn.emulateTransitionEnd=function(b){var c=!1,d=this;a(this).one(a.support.transition.end,function(){c=!0});var e=function(){c||a(d).trigger(a.support.transition.end)};return setTimeout(e,b),this},a(function(){a.support.transition=b()})}(jQuery), function(a){"use strict";var b='[data-dismiss="alert"]',c=function(c){a(c).on("click",b,this.close)};c.prototype.close=function(b){function c(){f.trigger("closed.bs.alert").remove()}var d=a(this),e=d.attr("data-target");e||(e=d.attr("href"),e=e&&e.replace(/.*(?=#[^\s]*$)/,""));var f=a(e);b&&b.preventDefault(),f.length||(f=d.hasClass("alert")?d:d.parent()),f.trigger(b=a.Event("close.bs.alert")),b.isDefaultPrevented()||(f.removeClass("in"),a.support.transition&&f.hasClass("fade")?f.one(a.support.transition.end,c).emulateTransitionEnd(150):c())};var d=a.fn.alert;a.fn.alert=function(b){return this.each(function(){var d=a(this),e=d.data("bs.alert");e||d.data("bs.alert",e=new c(this)),"string"==typeof b&&e[b].call(d)})},a.fn.alert.Constru
<<< skipped >>>
GET /metrika/watch.js HTTP/1.1
Accept: */*
Referer: hXXp://presentaci.ru/downloads/752_55394.ppt
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: mc.yandex.ru
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx/1.8.0
Date: Mon, 07 Mar 2016 11:15:52 GMT
Content-Type: text/html
Content-Length: 184
Connection: keep-alive
Location: hXXps://mc.yandex.ru/metrika/watch.js
<html>..<head><title>301 Moved Permanently</title></head>..<body bgcolor="white">..<center><h1>301 Moved Permanently</h1></center>..<hr><center>nginx/1.8.0</center>..</body>..</html>..HTTP/1.1 301 Moved Permanently..Server: nginx/1.8.0..Date: Mon, 07 Mar 2016 11:15:52 GMT..Content-Type: text/html..Content-Length: 184..Connection: keep-alive..Location: hXXps://mc.yandex.ru/metrika/watch.js..<html>..<head><title>301 Moved Permanently</title></head>..<body bgcolor="white">..<center><h1>301 Moved Permanently</h1></center>..<hr><center>nginx/1.8.0</center>..</body>..</html>....
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
iexplore.exe_1940:
%?9-*09,*19}*09
%?9-*09,*19}*09
.text
.text
`.data
`.data
.rsrc
.rsrc
msvcrt.dll
msvcrt.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
USER32.dll
USER32.dll
SHLWAPI.dll
SHLWAPI.dll
SHDOCVW.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
IE-X-X
rsabase.dll
rsabase.dll
System\CurrentControlSet\Control\Windows
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
dw15 -x -s %u
watson.microsoft.com
watson.microsoft.com
IEWatsonURL
IEWatsonURL
%s -h %u
%s -h %u
iedw.exe
iedw.exe
Iexplore.XPExceptionFilter
Iexplore.XPExceptionFilter
jscript.DLL
jscript.DLL
mshtml.dll
mshtml.dll
mlang.dll
mlang.dll
urlmon.dll
urlmon.dll
wininet.dll
wininet.dll
shdocvw.DLL
shdocvw.DLL
browseui.DLL
browseui.DLL
comctl32.DLL
comctl32.DLL
IEXPLORE.EXE
IEXPLORE.EXE
iexplore.pdb
iexplore.pdb
ADVAPI32.dll
ADVAPI32.dll
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
IExplorer.EXE
IExplorer.EXE
IIIIIB(II<.fg>
IIIIIB(II<.fg>
7?_____ZZSSH%
7?_____ZZSSH%
)z.UUUUUUUU
)z.UUUUUUUU
,....Qym
,....Qym
````2```
````2```
{.QLQIIIKGKGKGKGKGKG
{.QLQIIIKGKGKGKGKGKG
;33;33;0
;33;33;0
8888880
8888880
8887080
8887080
browseui.dll
browseui.dll
shdocvw.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
6.00.2900.5512 (xpsp.080413-2105)
Windows
Windows
Operating System
Operating System
6.00.2900.5512
6.00.2900.5512