CapTipper

Analysis Info

PCAP File Analysis Time CapTipper Version Traffic Time
/opt/Malware-Project/BigDataset/Scenarios/CTU-Malware-Capture-Botnet-117-1//2015-04-11_capture-win3.pcap 08/27/16 22:00:05 0.2 b10 04/28/75 02:35:28

Flow View


Client Details

IP10.0.2.103
MAC08:00:27:3d:00:32
USER-AGENTMozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)

Conversations

api.bing.com    (195.113.232.88:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
0/qsml.aspx?query=.&maxwidth=296&rowheight=20§ionHeight=400&FORM=IE8SSC&market=en-ustext/htmlqsml.aspx200 OKXML281.0 B04/28/75 02:35:28
1/qsml.aspx?query=.m&maxwidth=296&rowheight=20§ionHeight=400&FORM=IE8SSC&market=en-ustext/htmlqsml.aspx200 OKXML1.3 KB05/06/75 10:48:46
2/qsml.aspx?query=.net&maxwidth=296&rowheight=20§ionHeight=400&FORM=IE8SSC&market=en-ustext/htmlqsml.aspx200 OKXML1.3 KB05/26/75 23:15:54
3/qsml.aspx?query=.net+3&maxwidth=296&rowheight=20§ionHeight=400&FORM=IE8SSC&market=en-ustext/htmlqsml.aspx200 OKXML1.4 KB06/01/75 23:48:58
4/qsml.aspx?query=.net+4&maxwidth=296&rowheight=20§ionHeight=400&FORM=IE8SSC&market=en-ustext/htmlqsml.aspx200 OKXML1.3 KB06/11/75 23:05:54
88/qsml.aspx?query=.met&maxwidth=296&rowheight=20§ionHeight=400&FORM=IE8SSC&market=en-ustext/htmlqsml.aspx200 OK1.3 KB05/13/75 09:40:25

www.bing.com    (204.79.197.200:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
5/sa/simg/sw_mg_l_4d_orange.pngimage/pngsw_mg_l_4d_orange.png200 OKPNG5.7 KB08/19/75 00:33:10
6/fd/ls/l?IG=cd2c42e3145d4cab8970c49b36a67938&Type=Event.CPT&DATA={"pp":{"S":"L","FC":190,"BC":350,"H":360,"BP":481,"CT":491,"IL":1},"ad":[-1,-1,798,391,990,499,10]}&P=SERP&DA=DB4&MN=SERPimage/gifl200 OKGIF42.0 B08/22/75 15:45:43
7/rms/rms%20answers%20Identity%20Blue$BlueIdentityDropdownBootStrap/jc/afd2a963/04592351.jsapplication/x-javascript04592351.js200 OKTEXT1.2 KB08/23/75 12:06:04
8/search?q=.net+4.6+download&src=IE-SearchBox&FORM=IE8SRCtext/htmlsearch200 OKHTML65.5 KB08/14/75 05:35:57
9/rms/Shared.Bundle/jc/37b37add/d66d89c6.js?bu=rms+serp+Shared%24shared_c.source%2cShared%24env_c.source%2cShared%24event.custom_c.source%2cShared%24event.native_c.source%2cShared%24onHTML_c.source%2cShared%24dom_c.source%2cShared%24cookies_c.source%2cShared%24rms_c.source%2cShared%24clientinst_c.source%2cShared%24replay_c.source%2cAnimation_c.source%2cfadeAnimation_c.source%2cShared%24framework_c.sourceapplication/x-javascriptd66d89c6.js200 OKTEXT10.3 KB08/22/75 22:19:45
10/rms/Framework/jc/6669efd0/5f66eff0.js?bu=rms+answers+BoxModel+config%2crules%24rulesBHead2%2ccore%2cmodules%24scroll%2cmodules%24resize%2cmodules%24state%2cmodules%24mutation%2cmodules%24error%2cmodules%24network%2cmodules%24cursor%2cmodules%24keyboardapplication/x-javascript5f66eff0.js200 OKTEXT13.5 KB08/23/75 12:00:56
11/rms/rms%20answers%20Identity%20Blue$BlueIdentityHeader/jc/6874c2cd/37eb3cec.jsapplication/x-javascript37eb3cec.js200 OKTEXT707.0 B08/23/75 12:50:20
12/rms/rms%20answers%20Identity%20SnrWindowsLiveConnectBootstrap/jc/8e462492/c76620da.jsapplication/x-javascriptc76620da.js200 OKTEXT257.0 B08/23/75 12:55:44
13/rms/rms%20serp%20shareWebResults_c.source/jc/14377375/0f4b3475.jsapplication/x-javascript0f4b3475.js200 OKTEXT2.1 KB09/04/75 02:43:16
14/rms/rms%20serp%20blue$WebResultToolbox.source/jc/6a46ec81/bcf861d0.jsapplication/x-javascriptbcf861d0.js200 OKTEXT3.7 KB09/04/75 02:32:54
15/rms/rms%20answers%20Identity%20FacebookConnect/jc/4cfbb990/3114c30f.jsapplication/x-javascript3114c30f.js200 OKTEXT320.0 B09/04/75 02:40:33
16/rms/rms%20answers%20SegmentFilters%20Blue$GenericDropDown/jc/ddfc9752/25ba9f91.jsapplication/x-javascript25ba9f91.js200 OKTEXT5.0 KB09/04/75 02:37:57
17/sa/8_01_1_3872466/UpdateDefaults.jsapplication/x-javascriptUpdateDefaults.js200 OKTEXT656.0 B09/10/75 09:58:57
18/fd/ls/GLinkPing.aspx?IG=cd2c42e3145d4cab8970c49b36a67938&&ID=SERP,5110.1image/gifGLinkPing.aspx200 OKGIF42.0 B10/03/75 22:08:55
19/fd/fb/r?v=9_00_0_3865645&sId=6text/htmlr200 OKHTML5.9 KB09/11/75 01:46:40
89/fd/ls/lsp.aspxlsp.aspx204 No Content0.0 B10/04/75 22:22:13

www.microsoft.com    (23.63.79.162:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
20/library/svy/broker.jsapplication/x-javascriptbroker.js200 OKTEXT13.0 KB10/19/75 00:19:23
22/en-us/download/details.aspx?id=30653text/htmldetails.aspx200 OKTEXT38.5 KB10/06/75 08:00:43
55/library/svy/broker-config_s1.js?1428659018048application/x-javascriptbroker-config_s1.js200 OKTEXT4.0 KB02/03/76 18:07:42
60/favicon.ico?v2image/x-iconfavicon.ico200 OKICO16.8 KB02/14/76 13:25:38
64/en-us/download/confirmation.aspx?id=30653text/htmlconfirmation.aspx200 OKTEXT30.9 KB12/20/78 21:41:21
73/library/svy/broker-config_s1.js?1428659111037application/x-javascriptbroker-config_s1.js200 OKTEXT4.0 KB01/14/79 20:45:34

i.s-microsoft.com    (184.31.86.50:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
21/library/capi/wt_capi.jsapplication/x-javascriptwt_capi.js200 OKTEXT9.5 KB10/19/75 12:37:59
26/fonts/icons/homepage/normal/2.eot?application/octet-stream2.eot200 OKBINARY4.3 KB11/12/75 10:02:13
32/fonts/segoe-ui/west-european/Semibold/latest.eotapplication/octet-streamlatest.eot200 OKBINARY77.1 KB11/12/75 09:17:20
33/fonts/segoe-ui/west-european/normal/latest.eotapplication/octet-streamlatest.eot200 OKBINARY66.4 KB11/12/75 09:10:12
37/fonts/segoe-ui/west-european/light/latest.eotapplication/octet-streamlatest.eot200 OKBINARY73.7 KB11/12/75 06:40:24

c.s-microsoft.com    (184.31.86.50:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
23/en-us/CMSStyles/style.csx?k=eb892833-0e5a-b8c0-2921-57013ef132d9_899796fc-1ab6-ed87-096b-4f10b915033c_e8d8727e-02f3-1a80-54c3-f87750a8c4de_6e5b2ac7-688a-4a18-9695-a31e8139fa0f_8bc2864c-9c85-8adf-1daf-1d75f128bba4_fc29d27f-7342-9cf3-c2b5-a04f30605f03_28863b11-6a1b-a28c-4aab-c36e3deb3375_907fa087-b443-3de8-613e-b445338dad1f_a66bb9d1-7095-dfc6-5a12-849441da475c_1b0ca1a3-6da9-0dbf-9932-198c9f68caeb_ef11258b-15d1-8dab-81d5-8d18bc3234bc_11339d5d-cf04-22ad-4987-06a506090313_74c627f5-7388-88a7-f42f-f6e8b507bad6_8031d0e3-4981-8dbc-2504-bbd5121027b7_3f0c3b77-e132-00a5-3afc-9a2f141e9eae_aebeacd9-6349-54aa-9608-cb67eadc2d17_0cdb912f-7479-061d-e4f3-bea46f10a753_343d1ae8-c6c4-87d3-af9d-4720b6ea8f34_a905814f-2c84-2cd4-839e-5634cc0cc383_190a3885-bf35-9fab-6806-86ce81df76f6_c6e1ad92-2d93-35b0-c0f7-75fa59396549_c8d2e791-3bfb-e9b9-51bc-b274485f0085_04cdd06f-491b-f252-4816-e05dbe3089b4_4d591b90-4f6b-d61a-3fe3-eeabaa54e007_d2a7617d-4fec-e271-3b3c-29c71d1edda1_c54c82ad-9a34-5e14-9f7e-f76e05daa48e_7662fbc3-5b00-dd7a-8c24-6b7bb7bb4b48_2bcd3d2d-6832-7053-3643-75fe6bb53d16_90b9cae5-0156-65e5-3652-a23ad05aa89b_0eea7408-d405-33d1-b3a3-e68154c11931_ba0d0603-e291-f64d-1224-c7179a0128a3_66db1513-3061-60df-c963-21f539556ce2_0f67a2ff-4303-729b-5e92-8c9fdf41f487_edaa7a2f-8af9-ec7d-b92f-7f1d2beb1752_8458a62c-bedc-f933-0122-e66265888317_2bb2f93a-070c-24f3-a072-d242d5ed2dc6_b330fd3d-1e8a-d40d-de4a-4d1c63486b10_60605f77-9b7b-d9fe-129c-c4937ddd200a_234e2194-00bc-d945-f90c-5cb0949c5e6c_c1777bd2-b94a-d4f5-9613-04f778b6d0cd_54a5d793-aac7-b19e-ed26-cc0395a49b4f_2d1729a6-67a8-5390-69d1-3988a55a41c8_31406ffb-4dfc-1e69-997b-05313bbb2db8_30db642a-887e-7424-636a-671576ac660e_3684062b-2b09-fd4e-0f3e-6a149539f0c8_23c3ae93-fc96-f39a-cb7e-0a9eee5d9678_d6bdf6a8-b29b-b551-3bca-52d5615a2c54text/cssstyle.csx200 OKTEXT25.5 KB10/19/75 14:13:50
24/en-us/CMSScripts/script.jsx?k=9ec5cf5a-1af6-fe90-f4cc-1a38d7d1d275_9992692b-e27c-3fdb-ff69-c9e41c46b294_517a7087-9636-e078-8b13-a173049192f5_4c905457-169a-061a-e153-0372577f2998_d3bc9880-cc5f-f076-397b-64222c41edee_525283c5-3d35-4dd2-5a96-acaf933fab61_49488e0d-6ae2-5101-c995-f4d56443b1d8_2ac79f2c-0420-95d2-d38c-1864e2b5b992_38aa9ffb-ddb5-75be-6536-a58628f435f5_e3e65a0a-c133-43e7-571d-2293e03f85e6_4ca0e9dc-a4de-17ba-f0de-d1d346cb99e2_06310cd8-41c6-3b11-4645-b4884789ed70_5c27e8aa-9347-969e-39ac-37a4de428a8d_6c1db848-51f4-78cc-9217-a2f64d1244b2_05287868-6333-1b61-d97a-a7fa0537377a_64c742e2-b29c-b6c1-fdd9-accf33ec40bd_cf2ceca9-3467-a5b3-d095-68958eee6d4c_8c8be2fc-d64f-68b1-c04f-86433b07a6b7_ec5fa2c9-3950-ff57-a5c3-1fa77e0db190_d19f9592-65df-bcc9-e30e-439b875c3381_c12cb3ac-0bcc-88f3-cc76-5974cfd33449_82d3ec86-9d53-519f-c4ce-d79ff9ea8f21_4c06930e-976d-9cb1-9883-35ccc5d4118f_10102c22-b3f8-db84-b802-423fccfef217_0d0bc397-9ed4-1790-c53b-19ef58e50eda_daf547ea-e7e0-5c13-2375-876773f4442e_ed1edc1e-59a4-d30a-33f1-7023ad077a46_31f7b2e8-247c-8192-8a93-02446f7ecb54_b5687080-802a-ed0f-42f6-40dddfa471e8_206c0c39-86a6-7517-32a6-297492d1134e_eb51f80f-943f-3709-b39b-d5334d3a8d75_1c034b1c-7863-2cf2-c847-70db871b2033_587d79f0-4783-6625-8f1a-7749e17b2133_089862b4-a2c6-f637-5ec5-c0548eb22359_c398a8a9-5658-61a7-cff4-0c051e593636_907accee-265d-6812-c262-5ed718394b1f_e9c64221-c07e-6231-da94-5a12c1085418_a00a78f8-b494-2c7c-f132-c399e849b297_5ff685d9-9151-a2ea-217a-568a72fcfe8a_f12ef0bd-63fc-66af-3473-602f62d29b31_d31fe494-9b3b-d04c-d80c-35975eb8372btext/javascriptscript.jsx200 OKTEXT44.4 KB10/19/75 14:10:54
27/en-us/CMSImages/mslogo.png?version=856673f8-e6be-0476-6669-d5bf2300391dimage/pngmslogo.png200 OKPNG1.6 KB11/13/75 11:13:56
28/en-us/CMSImages/search.ltr.png?version=38884e53-76d0-d138-6215-41918aa59c26image/pngsearch.ltr.png200 OKPNG1.5 KB11/13/75 11:18:51
34/en-us/CMSImages/info_tip_16x16.png?version=8dd2a4cb-59c7-14a4-2abf-d78d79c815a3image/pnginfo_tip_16x16.png200 OKPNG430.0 B11/13/75 13:58:27
35/en-us/CMSImages/microsoft_symbol_clr_56x56.png?version=c4eecb84-642d-d95b-b988-919aca21ab9cimage/pngmicrosoft_symbol_clr_56x56.png200 OKPNG3.6 KB11/13/75 13:54:46
36/en-us/CMSImages/microsoft_logo_56x56.png?version=ad0d2fa7-0ee8-4e82-ddbf-8ea5dc9d9c23image/pngmicrosoft_logo_56x56.png200 OKPNG3.6 KB11/13/75 13:51:11
38/en-us/CMSImages/windows_symbol_clr_56x56.png?version=3db565f2-d75c-d989-182d-07edaedef3c8image/pngwindows_symbol_clr_56x56.png200 OKPNG377.0 B11/25/75 03:04:40
39/en-us/CMSImages/ie_symbol_clr_56x56.png?version=73aa5bf1-0743-11e7-8f71-718675c983bfimage/pngie_symbol_clr_56x56.png200 OKPNG630.0 B11/25/75 03:00:54
41/en-us/CMSImages/loading-md.gif?version=cfcaadbb-48cc-ae67-098c-2e657e0aae80image/gifloading-md.gif200 OKGIF981.0 B01/22/76 14:31:37
42/en-us/CMSStyles/CMSImages/accordion_icon_sprite.png?version=17099D97-CD5E-0507-9950-F316C697F104image/pngaccordion_icon_sprite.png200 OKPNG557.0 B01/22/76 14:28:40
43/en-us/CMSImages/microsoft_update_icon.png?version=452f1705-7064-00eb-f7a1-e5b67f54308dimage/pngmicrosoft_update_icon.png200 OKPNG720.0 B01/22/76 16:30:28
50/en-us/CMSImages/icon_arrow.png?version=45068e15-1f21-60f3-d03a-a98d7b2c00b7image/pngicon_arrow.png200 OKPNG729.0 B01/22/76 16:36:05
51/en-us/CMSImages/Ofc365_Evergreen_0811_70x70_EN_US.png?version=4af1b4f1-4571-765e-6aaa-9168e9e6f5e3image/pngOfc365_Evergreen_0811_70x70_EN_US.png200 OKPNG2.2 KB02/03/76 06:17:39
61/CMSImages/Closed_btn_21x21.png?version=3EBBE94B-AC86-4624-1AB4-F214AEC7D4EEimage/pngClosed_btn_21x21.png200 OKPNG570.0 B03/23/76 08:13:07
66/en-us/CMSImages/ie_symbol_clr_70x70.png?version=fdc2d692-7877-38f0-c246-be75d6e1724bimage/pngie_symbol_clr_70x70.png200 OKPNG753.0 B01/07/79 18:17:07

ajax.aspnetcdn.com    (68.232.34.200:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
25/ajax/jQuery/jquery-1.7.2.min.jsapplication/x-javascriptjquery-1.7.2.min.js200 OKTEXT41.7 KB10/19/75 20:14:15

cdn.optimizely.com    (93.184.220.20:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
29/js/222980912.jstext/javascript222980912.js200 OKTEXT230.2 KB10/31/75 06:59:30

222980912.log.optimizely.com    (107.21.127.149:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
30/event?a=222980912&d=222980912&y=false&src=js&s2130980600=true&s2098371093=true&s223040836=search&s244338170=none&s223033821=false&s223082014=ie&n=http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D30653&u=oeu1428659010617r0.08461647052835014&t=1428659010718&f=2434260494,2569840195,2287850098,2408400010,2339690644,2645920436,2651210434,2645750011,2757330690,2561120019,2586480509,2656180613,2693290376,2679321015,2764030409,2615000022,2506470379&g=image/gifevent200 OKGIF35.0 B11/12/75 23:05:10

tags.bkrtx.com    (172.227.124.25:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
31/js/bk-coretag.jsapplication/x-javascriptbk-coretag.js200 OKTEXT13.9 KB11/14/75 03:00:47

222980912.log.optimizely.com    (23.23.154.194:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
40/event?a=222980912&d=222980912&y=false&src=js&s2130980600=true&s2098371093=true&s223040836=search&s244338170=none&s223033821=false&s223082014=ie&n=http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D30653&u=oeu1428659010617r0.08461647052835014&t=1428659016686&f=2434260494,2569840195,2287850098,2408400010,2339690644,2645920436,2651210434,2645750011,2757330690,2561120019,2586480509,2656180613,2693290376,2679321015,2764030409,2615000022,2506470379&g=image/gifevent200 OKGIF35.0 B01/20/76 20:36:40
62/event?a=222980912&d=222980912&y=false&src=js&s2130980600=true&s2098371093=true&s223040836=search&s244338170=none&s223033821=false&s223082014=ie&n=engagement&u=oeu1428659010617r0.08461647052835014&t=1428659022164&f=2434260494,2569840195,2287850098,2408400010,2339690644,2645920436,2651210434,2645750011,2757330690,2561120019,2586480509,2656180613,2693290376,2679321015,2764030409,2615000022,2506470379&g=222978834image/gifevent200 OKGIF35.0 B03/22/76 14:36:58
65/event?a=222980912&d=222980912&y=false&src=js&s2130980600=true&s2098371093=true&s223040836=search&s244338170=none&s223033821=false&s223082014=ie&n=http%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fconfirmation.aspx%3Fid%3D30653&u=oeu1428659010617r0.08461647052835014&t=1428659110286&f=2434260494,2569840195,2287850098,2408400010,2339690644,2645920436,2651210434,2645750011,2757330690,2561120019,2586480509,2656180613,2693290376,2679321015,2764030409,2615000022,2506470379&g=image/gifevent200 OKGIF35.0 B01/07/79 04:10:06
74/event?a=222980912&d=222980912&y=false&src=js&s2130980600=true&s2098371093=true&s223040836=search&s244338170=none&s223033821=false&s223082014=ie&n=engagement&u=oeu1428659010617r0.08461647052835014&t=1428659139758&f=2434260494,2569840195,2287850098,2408400010,2339690644,2645920436,2651210434,2645750011,2757330690,2561120019,2586480509,2656180613,2693290376,2679321015,2764030409,2615000022,2506470379&g=222978834image/gifevent200 OKGIF35.0 B12/13/79 20:41:12

ots.optimize.webtrends.com    (31.186.231.66:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
44/ots/lib/3.2/wt_lib.jstext/javascriptwt_lib.js200 OKTEXT85.5 KB01/23/76 12:38:06
45/ots/ots/js-3.2/311121/WT3pJvY18YA0d1ufkjM5qV02cf1ol00ySJ4n_5_ngvBVqB8JWcvs7XqOlHp6CqUgmQQ9nFgvPGxTmSMMjtOVbWZbZpo2MLlSo7y7Cs4W1gbZiYpOUvutAePRLyfzLQZYGWZXcxreoMmz7k0H-y70jwo86AmvVFYVCEBputIOclNwjTyJAjMI9wj7nOY1XjRJPwe8o4CPJVdMjCSLmRoMdlAk1nnGtayPSJelCKFK1zlILI-0JhAvycjbOGSu_idThBg3fzK-GDi5CkIs74vnFYbkqUkdTXyh4n9xVPNYDb36B3Pwxaejg38x5IDDUsC7u8AwIlIRBxypxLVTMG9g92cacHI1qol0BFSAh5GKJogldgR5UyTORwstqZTx-32yqHo2C7ywCrI9d2Fco4Kdu7upx4wOx9MJrvqEBjUdp7mtbTBlF-BRoNhsIbzgKZoCe4k6mH5kkgxJfuInAoPW8eNt70D8kZwKenOjoODDYPv8nm2g_FlZJBSMHUAi2L1rCSR1WOMqoiKQE5P-1_HIxmI0xXNhvA305BXBy8hxP2PZzgY_XY1GA0KR3-bruRD3o-jUtbfXZEuz1ctpYFxZ8RKqnvfpMceu-T3A0TKbkxGl7Wd7trboC4mhpzzQGEB5xAMQ0uaVQNZULyene6WlIVaTZe7ypmgJiHzEHP5CDVzaWE0SLU-7dwnFuBhwmuCT4q5uqlvieCCvm4aRxfADnKcEUYrPB69-q-o9QocXRIJIm_4Mo97F_DDThxHNhE6lxWlOOBDIZ-OhDAMjuoww7owJekSSzEeDGJW3pAFYU2Lq7HjuZQivxaR4BZIv0Yi2sJBHxEJTXmhJPLDz1KblzvsoirUaX-dGYoyHGnjx5cMqciTeePUmNcTn4lG9BGyk-EOdtJloEALaRTBu_9C_d_uim-7-lZy4WV-5INSxtqfLjuLL7g_6BvgIHr-8mdgAXP77sjB7uNLqch9u_5X8-s7WtN13XWZjcUX0nywjMi73-yHSuo5836VeTzq6cFB2h5B5yY0c4Y0FrIaYelO0vL7eTkD7_GV5UP-Ys6EYzoArUdU5R4ZCUxnRwynSAX3J26fLti4h3ypz0fADx00grF-YueKtmmnmrAbw8ZQbHy75rFmEVTQ5mu7Z9gS2qHM6q6_1Wvq0t_-Q7me3o0a9lcDHj5e8aV9Gcwa7ZVufrXsBdAOLoqz2OjafagEuNR9MAi-aG8Se34WaNXpyiei3R10K5hnklqbuZfZpqCXTg61a7ly3S-y3jJA8UaXJrZJC7xRmyt_TbVnVzPwnYnjmPBz2V_cVxMtLsF0s0EOPLSfcM1MOhyEUIaXppO1bHxxPzLJiXt9N1XOtRkF-xoCPcmc9h7yFSVGvZHh6terJHtyzySN9vCpejiPglCvCPB8GbHpfyo4cVzF17IQW3mV6O4JjntjxWKALUSwuy91O40oTN7ceg3ml1rAyAeXEYZVgiW8aiKQvF3hp-5qTq0RaMCSbvub9MF9vGe66b5PzzLfqAIfI2WnsyvgF0EimBsvh4K6OkgMBWuVb6XKbwHTyp48DLPFlngxiPsXkiu_AVsTKRpnmYVZYPTCp5OFz-KfWtL_tAd6BAudwdTuPw1R9xeyZjqPD8v5w539UAejuI-IXN_qprpC2jxzsxkA4yFBb--x-B7MMvfz0e6JHEVnL_baNuhTvXud6U8Ml0INuoojeFkxL3ZHVvj5pHyBMHKaXk3OD2cqGTdb0YEy7VejZIs9GxBaCWu9YAJy-ZGM6EaimLMJOwi7WPb9X9GgatMhHd2XZC8LdNUkeqKmg-AkKs27qOaStIsz6z3UpWPoG8hR-GFvhLv4pZxF4NLpfC9U_r9e6blCPEdYr1JWpOeN9KsAT4iENBTALH74LtTvXEj6FjyQJD6PyiDgHQR9z-T6QHLIoL2AnlQoGal5ZJQsIUG8YDaSzMMLUE_R0mXenPn805ZB-ih8Ead6OCVlJTzbF/1428659017187-928/0/2text/javascript2200 OKTEXT157.0 B01/24/76 13:15:41
48/ots/ots/js-3.2/311121/lH1R_zJcbeK2lQL3WSdv2nABOiSX213dYVcfiSHa8kCjRaG57N-h1pM4Yte0F7vS4YX-dTJVV78kLdFwDdVH22OpEyTn0bsWpqBYxzAsJIbvMPMrT8yXCuux_5PnGqsfm8XXbLu7nr5pSFRCccl-dFyhg6Yb9HJi8M6NKxvhBwoz2IQ9YKIi8U31R8T8r9n06Ickkn9ACbAjACn-Mb_AQ-kJMcvMm2EpcUe7YGx8s23PsFNsxJtrqZhnaQV2JMt7Fc5iUjPDkVJu633bY1E8bCm6SJtcMZc6d67tvDJJkjp0BSl3tpboPh2OGUuFpTXz2oDzjCvHaO2YU1ahFrOMMukv4Yz-kn4G0rmfXhXAWHJf8_2gP-YcQ2XNnSBT4SZ9nEOkY_GloUl4gt-QWVlMY9RlJKay57h4ywzMIdPSd_ekQnuPL23vZkylSFGHVE_jGJEHqpZzfYuiB2DHYx3ZtH5Z3R8sVnqHFw9Hj_7_r2uyrd-Mcz9ulBFahsV-z3OhzH8z-I09HYWuQvEHQnM2xRClYAfNQRhd68CUeEciSis4pQlcUDZqDq2c2IxwIkQbpyefoSN-jqT_ggJ5Ho6W4M9CJw9Z6ObRcPp3chR9vA7QqkeSB1tPQJvKB7_lgB9stdNrcs2Xml3v2xFfGJc93UH2ACmQDANGun4oLVime9YAtM6BS104Arqg_dCV3399YfD7IIkE2PNZn487lY2SWHWtkY13FF-koxU33RWfSzADdu_RRJv_IXDc83_W1T976WVEu05kcAnTdR0GNWJUIbVhwrURn6on7bJFg63JJR2ZmYhQ-j522y1RXX7ZQLI2rruDe1diFUfhRks1laH4B_Ey4_JRAJp3vm9qbfC1wCvrfCG3Mg51R00po2iXQQAvj2x867SLOunbl48kUkl3D7MJtoxtilefLeIGxQa98z7miJCH2sL6BWXvhvMK22mp_kL6Vwv5kL0bjNCOy3y_bTu2C4RPH8Dj442Qv9YVKsI5jwQ3-RfyMI7X_c1X1UW7noPyDI1N20FngoW4Xhj6z7aFZ-EG-VK_oKrXNeSS9eljOnWVPSZmZR4c8aHmkoAlkYbCDdqT6mNlr_HZvlxm6Dzcyh8ErC5Aw8g0_b9wuHHBAEd5yEqk7o1WQR0PKkW8krUxjqwcre-YH3PAXwP6rb_lxVYHoLC8WH2st2zaGEmjPiWdl83IY58am_Ml2KxRZBavPivwxNJaOnm2ceh2b8YSvxpQva_yylS98u5rWS9AaG2I7xV5vsLGk3LCYVGKQUJy2Mt4nFSPQSu-SQ8mNHzxvssBXJ7I7n2GQ0WMczVowe-2M6h-whpJ_BpsLIEQotPzrl7OuaZt-FM1-GQvrJ7yRBDxoJrAXms2vgxSsqxvvEUl0dAcPOIXI7nwzQ1cAXQHTMjUeJCv_zKGm0EhjucyBB7l9PFAHtjY_0Kl09MA2pc4Ow-0bKiFZD9xDmRA7msN2VD2n9N1VE~/1428659017187-928/1/2text/javascript2200 OKTEXT487.0 B01/25/76 00:26:16
67/ots/ots/js-3.2/311121/WT3NSDL0Xsv_5C4op8DEU7u4-y2tI2TEOIBDJDINOXDnmYFUBk4qdPp_nIR5USykINEGxaOZ0WcHun5SxlRH91QgBs4KZfRZ4qeAV9V_c1B0zTzBuSVG8ygW8egMbiV0jTwuTqBW1CZNC0byfsIKQPpP5Gp05hXaoHkjY8XOxHp5mkXKXjsTpkZ5UDqq4I784kMRcTT-SEPHM1bNY4rQGCavCloH05AawfNSHahugdMaYrnCMJ7_OAwX5KCIM3pF6zX6jRgx-3rNVYYtBc-8ZPJzxuKTKh_Z_0IUhkwhngXa7W7ZIzslvgOHibZDCYdhHuVn5zAZHt3tAR6uZ5mkYNV7ydDvXb2u8fazM7UZZORMWZekIbekWe2TcS2JO2q2Koy8y5ZzOJZILthrIk8u25KlMrTYd5Pe04Pd3atSjgS0adWkaHCHa1ypNPWV-cc4ZA1iBrs6DotjZegFhjsvUkJBgIo6RlQnB5ny8XFg73Q5TL_Po3jbSPI-It6wR17wU8fswmoPof3g6F0VZzMCLz9sBa1Rrpu-ikwu2UfO7dA80S9oMFacyzxm6Duud4aH6XtZr76EZK7lhLpVr2Alji5DImvLlzhCEOyY5croGapnGPwYGb11tzAA-HAvHx9qZjJbF4s50zct9EWMO3S5xGFoVdBdFy8Bh50EzUQtuxMnt6UHPfBvKaQcP-zO3XsTOdNgJQoO92OfknwVrJ9caGtkyF96UUPJq7qs7ZY5IvzhPcQJ3ChCmbnKcSo2-o1PFVCO7QqIKDoSQxissvIk10qLpyEovtPF9F0gDjpxDyA4JKmAbKqXhlpHytWypneLQ3dil7BdQkn_gEt59IoY3KIurDj2R0AcX4UGfnBgKiL78XDITHWHcYCV10YgAJerI_bwSEC7Ji-6SnVdXIqyrrZIVgP58PXaqubrgAsCx1u-8cLeST1in-WtVnflS4nBqRH8_LnrqgYPB7bx4EwJ3vhbP7FfnxnsjDKK5L7Ks_jSFiXOC8QqPkiLSAI5jbZgDhXxNsD9Ak7MuHQWV9a3hQzzNMpRBl7hoxXLedAbQTqCjs1VBy9tqJOmYnkVDbQ1CN82iMkHwOLfGQa62F1WfyctUFhDfLq5c4MyRU_wvGX4JWg5Txrut6o5zpt_Jf4IOQFytLQREyuqwuzcaucRQToivbfQVEt2y2AplANzVhHitR4JssSwXa67I8jPgEDZw2tbjU8zHl6TYGDJa_usiG3cEHSBlUeemb1FyIS2mlGjfpo8Y9MduGgfl_jd0UGzIwAIYzYRMFuoRO1iymQ0IuUZHgl7INlDo_r2djF2rB1bhu7w_wqLgjp4WJIk4mr2J8F_LTN6ltudvnEksckoV-Fnarl3h6GW479jSrmlCh6WEizCwxCrWjdi6lQ5hZrPtVRfPcH1GAXjP6d1IENiGzzL0r4jLuCG6MSGEAP3_KPGGUH2Y4DyjQgZ7MhllT9p8XIoTkeKTGK-5PSLslZyg7B1HUO37ps_kwABWOSCbe37VGyRDPygI_C5IUOLuUgDyER0RxppM-IU_m5vvccWqpMKwULjgPMkwHTESNsZaUAzrerA8HkxM1OQ1gsmo_lQX_oLi868bwiPES8_GhA3bD_P73UhwgGx_WzvniTMdGbutegKcVdboDlhi9wirRd355Kf9yXdOtDtWXY_eyY_XLO4krQpuuSvHsuR2wUd3BtqTzY1Vadq9uIQgRO3A_43_V9UNToXvacm_LE7Y98j9jthacdn45E55iyjl9XBHhDjzrw3uaeXFeWcAhr62PiOmFoYrCVcCbWXAA3T8RbGNy8S8a0iEdQni6stVuMOvQaGijePaTKil69EqjDXk4eCrq2RmGsj3C_IYIa6m3qEueChy59zg_NUhum6hjENcxHyoNjxcjUZy-e1RftMpnEzTRrlu3cw_dpC1FshYXRbaz2z27xBgrLeDNK7KDe7QfF58KnKNRrwIxe79kdkF4tn/1428659110546-533/0/2text/javascript2200 OKTEXT157.0 B01/09/79 06:58:46
68/ots/ots/js-3.2/311121/hxBxxXPGtODtTSQ4VjAhArCyfUzoSOh8aerrsmRLPofMfU6wqk7GyWG2b2u5n8JRxfvmRM0gZmkZtNSnqv6R1p8zKA9GYfTl1KDzNwRiDSD64Vmsz37PO3Gtr3w1DfKkr4AMhxM8TIq_1MZbw9FlWHtia5-Ian1q9a-zRxILNPwpDRoaZ7kW5PrbroqQvNViVG-y-OPgtULre3kKX6GC4ruw-wgPXgnWA9ru9lR_OhFbxwmBhie8iXRh3c6ITeVYJX_rBg0nCDAm38s1pqlHKnvM8vQbPf6qKMcYgnwCvpBwD8D5ARq3dgUudCv7tYagsCn2jEDGEWo7TDPEKh2usKWj1bGlfVEcML-RjN0-7A47sqe19Yid08TPVoIEiYHhdjtgIq7BQB4YrNSzm_2keZZ1uHF1KvdIP7wEY8WPIGCvdL3sLmDuqTMgP05DZhe8Ed4kQMgQCg9RMwXKbeUnb4UdrHvV4NnvwZiUPzYMPWs9o2fHl89IbMTYKgQCOQEr4zY0RGsDsZFi5UAiV4ckHLs1hTDcm36_qDJ7gZTTXxVvn95vazhxWJiNL-msta30XUpUeGkPXOvTH2RaQGgzKZo8I1Yi36qn01N2H78qs0RW2I5h5RC7169xk4wPaPrdDeVrn62SLE5q9JA95RbIFlq3GfkiJzIiAC_WCUxmzKfmPdGUQ7D4qx5ZN44sPwG4tEbNiS2dOEaW9_G01W2MdeueiDf5akNiM8VBhaNxHxYfVWtetl-EKnS49gzmQftXcQErE6ZmnAGryAEPQvSkzgJo750Ut5HkQZUPeYd74_NPK7w1LdNlrox1jCZXIpmjOWCtb7wFhkAk5UZeYPR-PPPuXRaIHyKS8AVk5hjugGRr2QTSl8JgyoheE2b4ZOmVg7sVYzwmxZRshGBqiDUvH_ItE-eRvTzGyCChtDtpHtJoW0z5PJI5JsjLyXV1aUtGHb9mQKqczPWFdRj7R8wgp62fkDs4IKZH8SPAKY3sxf3Vwma4bS7ucF5Q8_-RryOugVPRZsu96LZT6XsUA2vPZLNHV95NN3c7uCTDUpn4x7HSJnl1pzKWStmmyfJ28GZekqqZoockNy9kg3OMor8HaKOdHDTL7T0xz9g_mbXTfopdO2JCaB0eDhRkF_uM7wuVrQsHH43fU3Vd7s_mew70Be6mo6C6DcA51mXCT6MLkLTL1NwrURcQ3-_zsjQZfIeU6RHLZTA6su5GLWxG3n5HI9RQkB6BrWsiDgv_EelgW1lzPSRnPG_O-mp9GSVdIlN-8HRkAb5rj_qqtcTRCPx1hCuzxEby-C3-OCwjr3zTL7NhrPTg-HyjQd8BiUY-TuICWXJi4XgckJtq_ugkehOsIzltPN9sedgntob09hhoIESRGSeoS4pSrFlLU9E7QNca6zAMOwMLvwAe_ldqCk9uDo82I9K90a55s04LhVhYi34PsA~/1428659110546-533/1/2text/javascript2200 OKTEXT1.8 KB01/09/79 14:58:26

tags.bluekai.com    (173.192.220.64:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
46/site/15815?ret=jstext/javascript15815200 OKTEXT41.0 B01/22/76 23:05:51
52/site/14095?dt=0&r=1444252863&sig=772461942&bkca=KJhNEXLmQM9xdJo0L6Wvb/VeintoaIIAxQAB4jY0ocbIiNaeEWytmpmcZ57NWGGKM/fsUkAGpvhSy33l3rFfD9w30QVg7VCJWo2PT2lAmAOmnbzq9F4Y0meXQe0ksKfmmTByfEgPvvadqvr6GfxQdqorynolfona0FX2gayqBHofQJsy96ATEQiOZAX+qjSnrnuqKDJLF04yPGJxK3JisCIWX54dn1TpaZkkaOHo8/LXtIftuz3KCE8QQQ==text/html14095200 OKHTML606.0 B02/05/76 18:02:14
56/site/14095?ret=html&phint=muid%3D&phint=__bk_t%3DDownload%20Microsoft%20.NET%20Framework%204.5%20from%20Official%20Microsoft%20Download%20Center&phint=__bk_k%3D.NET%204.5%3B%20.NET%20Framework%204.5%3B&phint=__bk_l%3Dhttp%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D30653&limit=4&r=65178243text/html14095302 Found0.0 B02/04/76 12:43:57
59/site/3085?id=6638070103791715376&BK_SWAP_DEST=3085image/gif3085200 OKGIF62.0 B02/07/76 23:44:08
69/site/14095?ret=html&phint=muid%3D&phint=__bk_t%3DDownload%20Microsoft%20.NET%20Framework%204.5%20from%20Official%20Microsoft%20Download%20Center&phint=__bk_k%3Ddownload%2C%20software%2C%20update%2C%20Microsoft%2C%20product%2C%20computer%2C%20PC%2C%20Windows%2C%20Office%2C%20server%2C%20MSN%2C%20Live%2C%20game%2C%20Xbox%2C%20security%2C%20driver%2C%20install%2C%20trial%2C%20preview%2C%20demo%2C%20popular&phint=__bk_l%3Dhttp%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fconfirmation.aspx%3Fid%3D30653&limit=4&r=33528859text/html14095200 OKHTML257.0 B01/09/79 18:58:36

i.microsoft.com    (184.31.86.50:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
47/global/ImageStore/PublishingImages/icons/search-button-blue.pngimage/pngsearch-button-blue.png200 OKPNG428.0 B01/27/76 07:49:35
49/global/ImageStore/PublishingImages/icons/list-blue.pngimage/pnglist-blue.png200 OKPNG224.0 B01/27/76 07:54:42

googleads.g.doubleclick.net    (173.194.122.25:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
53/pagead/viewthroughconversion/956565568/?value=1.00¤cy_code=USD&label=GJo0CLqbnFkQwJCQyAM&guid=ON&script=0image/gif53.html302 FoundGIF42.0 B02/07/76 02:33:12
70/pagead/viewthroughconversion/1038632207/?value=1.00&label=b4o6CJ7w5lYQj4qh7wM&guid=ON&script=0image/gif70.html302 FoundGIF42.0 B01/13/79 05:02:04

ib.adnxs.com    (37.252.170.4:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
54/getuid?http%3A%2F%2Ftags.bluekai.com%2Fsite%2F3085%3Fid%3D%24UID%26BK_SWAP_DEST%3D3085text/htmlgetuid302 Found0.0 B02/07/76 07:56:53
63/bounce?%2Fgetuid%3Fhttp%253A%252F%252Ftags.bluekai.com%252Fsite%252F3085%253Fid%253D%2524UID%2526BK_SWAP_DEST%253D3085text/htmlbounce302 Found0.0 B02/07/76 17:52:38

www.google.com    (173.194.122.19:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
57/ads/user-lists/956565568/?label=GJo0CLqbnFkQwJCQyAM&script=0&random=4142602493text/html57.html302 FoundHTML314.0 B02/07/76 21:27:25
71/ads/user-lists/1038632207/?label=b4o6CJ7w5lYQj4qh7wM&script=0&random=781909385text/html71.html302 FoundHTML314.0 B01/13/79 16:02:03

www.google.cz    (173.194.122.15:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
58/ads/user-lists/956565568/?label=GJo0CLqbnFkQwJCQyAM&script=0&random=4142602493&ipr=yimage/gif58.html200 OKGIF42.0 B02/08/76 12:04:36
72/ads/user-lists/1038632207/?label=b4o6CJ7w5lYQj4qh7wM&script=0&random=781909385&ipr=yimage/gif72.html200 OKGIF42.0 B01/14/79 01:47:51

download.microsoft.com    (195.113.232.96:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
75/download/B/A/4/BA4A7E71-2906-4B2D-A0E1-80CF16844F5F/dotNetFx45_Full_setup.exeapplication/octet-streamdotNetFx45_Full_setup.exe200 OKEXE982.0 KB12/14/79 15:23:05
80/download/1/E/3/1E3220BD-1D17-4EE7-8D7F-333422D1BA4B/enu_netfx/x86/windows6.1-kb958488-v6001-x86.msuapplication/octet-streamwindows6.1-kb958488-v6001-x86.msu200 OK0.0 B09/09/81 10:50:47
84/download/1/A/F/1AF0211E-69A7-4B58-8189-8BA9014AE03A/enu_netfx/x86/netfx_fullcab.exeapplication/octet-streamnetfx_fullcab.exe200 OK0.0 B10/12/81 23:13:15
86/download/1/E/3/1E3220BD-1D17-4EE7-8D7F-333422D1BA4B/enu_netfx/x86/netfx_full_x86.msiapplication/octet-streamnetfx_full_x86.msi200 OK0.0 B10/12/83 01:41:30

crl.microsoft.com    (195.113.232.75:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
76/pki/crl/products/microsoftrootcert.crlapplication/pkix-crlmicrosoftrootcert.crl200 OKBINARY813.0 B02/14/81 07:23:40
77/pki/crl/products/MicCodSigPCA_08-31-2010.crlapplication/pkix-crlMicCodSigPCA_08-31-2010.crl200 OKBINARY554.0 B02/15/81 05:05:27

crl.microsoft.com    (195.113.232.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
78/pki/crl/products/MicrosoftTimeStampPCA.crlapplication/pkix-crlMicrosoftTimeStampPCA.crl200 OKBINARY550.0 B07/14/81 07:42:11
81/pki/crl/products/CSPCA.crlapplication/pkix-crlCSPCA.crl200 OKBINARY506.0 B10/07/81 11:40:24
82/pki/crl/products/tspca.crlapplication/pkix-crltspca.crl200 OKBINARY521.0 B10/08/81 00:33:30

go.microsoft.com    (64.4.11.25:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
79/fwlink/?LinkId=249117&clcid=0x409text/html79.html302 Found0.0 B09/05/81 03:20:11
83/fwlink/?LinkId=249121&clcid=0x409text/html83.html302 Found0.0 B10/11/81 01:25:09
85/fwlink/?LinkId=249119&clcid=0x409text/html85.html302 Found0.0 B10/09/83 17:14:00

www.msftncsi.com    (195.113.232.90:80)
IDURIRESPONSE TYPEFILENAMERESPONSE CODEMAGICSIZETIME
87/ncsi.txttext/plainncsi.txt200 OKTEXT14.0 B07/11/92 18:35:40