2017-03-24 21:33:08.433085 IP 192.168.1.102.52862 > 47.90.205.113.80: Flags [P.], seq 0:296, ack 1, win 256, length 296: HTTP: GET /user.php?f=2.gif HTTP/1.1 E..P.F@…+….f/Z.q.~.P…….gP…7K..GET /user.php?f=2.gif HTTP/1.1 Accept: application/x-shockwave-flash, image/gif, image/jpeg, image/pjpeg, */* Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Accept-Encoding: gzip, deflate Host: voperforseanx.top Connection: Keep-Alive   2017-03-24 21:34:18.965418 IP 192.168.1.102.52879 > 204.79.197.213.443: Flags [.], ack 84798, win 32768, length 0 E..(2.@…s….f.O……1.B…b^P…R……… 2017-03-24 21:34:18.965823 IP 192.168.1.102.52879 > 204.79.197.213.443: Flags [.], ack 86258, win 32768, length 0 E..(2.@…s….f.O……1.B…h.P…M……… 2017-03-24 21:34:18.966006 IP 192.168.1.102.52879 > 204.79.197.213.443: Flags [.], ack 87718, win 32768, length 0 E..(2.@…s….f.O……1.B…m.P…GM…….. 2017-03-24 21:34:18.969465 IP 192.168.1.102.52879 > 204.79.197.213.443: Flags […]