2016-10-21 21:31:29.018549 IP 192.168.1.5.50248 > 192.95.15.211.80: Flags [P.], seq 454:1107, ack 2446, win 16537, length 653: HTTP: GET /index.php?w36KfrmaJR3NA4I=l3SMfPrfJxzFGMSUb-nJDa9GP0XCRQLPh4SGhKrXCJ-ofSih17OIFxzsqAycFUKCqrF4Qu4Fah2h1QWScEZrmYRPFgVIove8hQLfyhSWkpOD9UHfYg5D_5qdFeA_3gykx7lHdJhxxxOB6jBZzL8aQFFT6wkZjuyeV7PC7kpzXlBxFlvbJN0sohfQDmK1JDEqi_W5SDx-1g HTTP/1.1 E…oe@………._…H.P!.n..1.gP.@…..GET /index.php?w36KfrmaJR3NA4I=l3SMfPrfJxzFGMSUb-nJDa9GP0XCRQLPh4SGhKrXCJ-ofSih17OIFxzsqAycFUKCqrF4Qu4Fah2h1QWScEZrmYRPFgVIove8hQLfyhSWkpOD9UHfYg5D_5qdFeA_3gykx7lHdJhxxxOB6jBZzL8aQFFT6wkZjuyeV7PC7kpzXlBxFlvbJN0sohfQDmK1JDEqi_W5SDx-1g HTTP/1.1 Accept: */* Referer: http://gl9q.s57ae8vl3.top/?w36KfrmaJR3NA4I=l3SKfPrfJxzFGMSUb-nJDa9GP0XCRQLPh4SGhKrXCJ-ofSih17OIFxzsqAycFUKCqrF4Qu4Fah2h1QWScEZrmYRPFgVIove8hQLfyhSWkpOD9UHfYg5D_5qdFeA_3gykx7lHdJhxxxOB6jBZzL8aQFFd Accept-Language: en-US User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko Accept-Encoding: gzip, deflate Host: gl9q.s57ae8vl3.top Connection: Keep-Alive 2016-10-21 21:31:29.285255 IP 192.95.15.211.80 > 192.168.1.5.50248: Flags [.], ack 1107, win 1162, length 0 — E..(o.@….3….._…H.P!.q2.2.[P.@B………. 2016-10-21 21:31:31.440263 IP 192.168.1.5.50248 > 192.95.15.211.80: Flags [P.], seq 1107:1540, ack 79746, win 16450, length 433: HTTP: GET /index.php?w36KfrmaJR3NA4I=l3SMfPrfJxzFGMSUb-nJDa9GP0XCRQLPh4SGhKrXCJ-ofSih17OIFxzsqAycFUKCqrF4Qu4Fah2h1QWScEZrmYRPFgVIove8hQLfyhSWkpOD9UHfYg5D_5qdFeA_3gykx7lHdJhxxxOB6jBZzL8aQFFT6wkZjuyeV7PC7kpzXlBvEQ7bJN0sohfQDmK1JDEqi_K8QT98kKM&dfgsdf=2 HTTP/1.1 E…o.@….{….._…H.P!.q2.2.[P.@B.+..GET /index.php?w36KfrmaJR3NA4I=l3SMfPrfJxzFGMSUb-nJDa9GP0XCRQLPh4SGhKrXCJ-ofSih17OIFxzsqAycFUKCqrF4Qu4Fah2h1QWScEZrmYRPFgVIove8hQLfyhSWkpOD9UHfYg5D_5qdFeA_3gykx7lHdJhxxxOB6jBZzL8aQFFT6wkZjuyeV7PC7kpzXlBvEQ7bJN0sohfQDmK1JDEqi_K8QT98kKM&dfgsdf=2 HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko […]